IT Risk and Cybersecurity Auditor
This job was originally posted in Spanish and automatically translated to English. You'll most likely need Spanish to apply.
Job Description
Your mission will be to analyze and evaluate the technological infrastructure and the associated control framework, with the aim of ensuring that processes and systems are executed securely, reliably, and efficiently, in compliance with current regulations.
We will count on you to...
- Develop and execute audit programs, in line with the multi-year Internal Audit plan and business objectives.
- Collaborate in the definition of the audit plan, considering business needs and associated risks.
- Evaluate controls, analyze risks, and identify weaknesses during audits, proposing improvements and communicating them to the involved areas.
- Prepare audit reports according to established methodology and procedures.
- Participate in special projects: investigations, incident reviews, organizational analyses, ad hoc IT processes, and regulatory requirements.
- Perform follow-ups on the implementation of agreed corrective measures.
We need you to bring
- Degree or qualification in Computer Science, Information Technology Engineering, or related fields.
- Minimum of 2 years of experience in risk-based ICT auditing.
- Knowledge of information systems auditing and IT General Controls (CISA certification or similar is valued).
- Knowledge of internal auditing.
- Knowledge of cybersecurity, systems, network infrastructures, and communications.
- Familiarity with control frameworks in security, privacy, and business continuity (NIST, ISO 2700X, ISO 22301, etc.).
- Knowledge of IT and cybersecurity regulations (DORA, NIS2, PCI DSS, GDPR, among others).
- Experience in risk management and internal control (COSO, MAGERIT, ISO 27005, etc.) is valued.
WHAT DO WE OFFER?
A different way of working, growing professionally and personally, so that you can unleash your full potential in a sustainable and inclusive way. To achieve this:
• We promote teamwork, mutual support, and participation.
• We personalize training to develop people's skills throughout their entire professional life.
• We offer the flexibility you need to ensure a good balance between professional and private life.
• We bet on internal talent, and therefore you will have multiple opportunities to face new challenges and assume new roles.
• We will take care of you through Zainduz, our health program, through which you can enjoy: workshops on healthy habits and emotional well-being, digital Physiotherapy service, and incentives for walking or cycling to work.
• We will facilitate access to the Lagun Aro medical network for you and your family, as well as special banking and insurance conditions.
In short, we offer inclusive and respectful work environments, guaranteeing equal opportunities between men and women in work dynamics and professional careers, working to be a benchmark in equality.
View original advert (Spanish)
Tu misión será analizar y evaluar la infraestructura tecnológica y el marco de control asociado, con el objetivo de asegurar que los procesos y sistemas se ejecutan de forma segura, fiable y eficiente, en cumplimiento con la normativa vigente.
Contaremos contigo para...
- Elaborar y ejecutar programas de auditoría, en línea con el plan plurianual de Auditoría Interna y los objetivos del negocio.
- Colaborar en la definición del plan de auditoría, considerando las necesidades del negocio y los riesgos asociados.
- Evaluar controles, analizar riesgos e identificar debilidades durante las auditorías, proponiendo mejoras y trasladándolas a las áreas implicadas.
- Elaborar informes de auditoría conforme a la metodología y procedimientos establecidos.
- Participar en proyectos especiales: investigaciones, revisiones de incidentes, análisis organizativos, procesos ad hoc de TI y requerimientos regulatorios.
- Realizar el seguimiento de la implantación de medidas correctoras acordadas.
Necesitamos que aportes
- Grado o titulación en Informática, Ingeniería en Tecnologías de la Información o afines.
- Experiencia mínima de 2 años en auditoría de TIC basada en riesgos.
- Conocimientos de auditoría de sistemas de información y Controles Generales de TI (valorable certificación CISA o similar).
- Conocimientos de auditoría interna.
- Conocimientos en ciberseguridad, sistemas, infraestructuras de red y comunicaciones.
- Familiaridad con marcos de control en seguridad, privacidad y continuidad de negocio (NIST, ISO 2700X, ISO 22301, etc.).
- Conocimiento de normativa en TI y ciberseguridad (DORA, NIS2, PCI DSS, RGPD, entre otras).
- Valorable experiencia en gestión de riesgos y control interno (COSO, MAGERIT, ISO 27005, etc.).
¿QUÉ OFRECEMOS?
Otra forma de trabajar, creciendo profesional y personalmente, para que puedas poner en marcha todo tu potencial de forma sostenible e inclusiva. Para ello:
• Promovemos el trabajo en equipo, el apoyo mutuo y la participación.
• Personalizamos la formación para desarrollar la capacitación de las personas a la largo de toda su vida profesional.
• Ofrecemos la flexibilidad que necesitas para que exista un buen equilibrio entre la vida profesional y privada.
• Apostamos por el talento interno, y por ello tendrás múltiples oportunidades de enfrentarte a nuevos retos y asumir nuevos roles.
• Cuidaremos de ti a través de Zainduz, nuestro programa de salud, a través del cual podrás disfrutar de: talleres sobre hábitos saludables y bienestar emocional, servicio de Fisioterapia digital, incentivos por venir andando o en bici a trabajar.
• Te facilitaremos el acceso al cuadro médico de Lagun Aro para ti y tu familia, además de condiciones especiales bancarias y de seguros.
En definitiva, ofrecemos entornos de trabajo inclusivos y respetuosos, garantizamos igualdad de oportunidades entre hombres y mujeres en las dinámicas de trabajo y en las carreras profesionales, trabajando para ser una referencia en materia de igualdad.