IT and Cybersecurity Risk Auditor
IT and Cybersecurity Risk Auditor
IT and Cybersecurity Risk Auditor
Need a visa? The advert says visa sponsorship isn't available for this role.
About the role
Your mission will be to analyze and evaluate the technological infrastructure and the associated control framework, with the aim of ensuring that processes and systems run securely, reliably, and efficiently, in compliance with current regulations.
What you'll do
- Develop and execute audit programs, in line with the multi-year Internal Audit plan and business objectives.
- Collaborate in defining the audit plan, considering business needs and associated risks.
- Evaluate controls, analyze risks, and identify weaknesses during audits, proposing improvements and communicating them to the relevant areas.
- Prepare audit reports in accordance with established methodology and procedures.
- Participate in special projects: investigations, incident reviews, organizational analyses, ad hoc IT processes, and regulatory requirements.
- Follow up on the implementation of agreed corrective measures.
What we're looking for
- A degree in Computer Science, Information Technology Engineering, or related fields.
- At least 2 years of experience in risk-based IT auditing.
- Knowledge of information systems auditing and general IT controls (CISA certification or similar is a plus).
- Knowledge of internal auditing.
- Knowledge of cybersecurity, systems, network infrastructures, and communications.
- Familiarity with control frameworks for security, privacy, and business continuity (NIST, ISO 2700X, ISO 22301, etc.).
- Knowledge of IT and cybersecurity regulations (DORA, NIS2, PCI DSS, GDPR, among others).
Nice to have
- Experience in risk management and internal control is a plus (COSO, MAGERIT, ISO 27005, etc.).
What you'll get
WHAT DO WE OFFER?
A different way of working, growing professionally and personally, so you can unleash your full potential in a sustainable and inclusive manner. To achieve this:
• We promote teamwork, mutual support, and participation.
• We personalize training to develop people's skills throughout their professional careers.
• We offer the flexibility you need for a healthy work-life balance.
• We invest in internal talent, giving you multiple opportunities to take on new challenges and roles.
• We take care of you through Zainduz, our health program, which includes workshops on healthy habits and emotional well-being, digital physiotherapy services, and incentives for walking or cycling to work.
• We provide access to the Lagun Aro medical plan for you and your family, along with special banking and insurance conditions.
Additional information
In short, we offer inclusive and respectful work environments, guarantee equal opportunities for men and women in our workplace dynamics and career paths, and strive to be a benchmark in equality.
About the role
Tu misión será analizar y evaluar la infraestructura tecnológica y el marco de control asociado, con el objetivo de asegurar que los procesos y sistemas se ejecutan de forma segura, fiable y eficiente, en cumplimiento con la normativa vigente.
What you'll do
- Elaborar y ejecutar programas de auditoría, en línea con el plan plurianual de Auditoría Interna y los objetivos del negocio.
- Colaborar en la definición del plan de auditoría, considerando las necesidades del negocio y los riesgos asociados.
- Evaluar controles, analizar riesgos e identificar debilidades durante las auditorías, proponiendo mejoras y trasladándolas a las áreas implicadas.
- Elaborar informes de auditoría conforme a la metodología y procedimientos establecidos.
- Participar en proyectos especiales: investigaciones, revisiones de incidentes, análisis organizativos, procesos ad hoc de TI y requerimientos regulatorios.
- Realizar el seguimiento de la implantación de medidas correctoras acordadas.
What we're looking for
- Grado o titulación en Informática, Ingeniería en Tecnologías de la Información o afines.
- Experiencia mínima de 2 años en auditoría de TIC basada en riesgos.
- Conocimientos de auditoría de sistemas de información y Controles Generales de TI (valorable certificación CISA o similar).
- Conocimientos de auditoría interna.
- Conocimientos en ciberseguridad, sistemas, infraestructuras de red y comunicaciones.
- Familiaridad con marcos de control en seguridad, privacidad y continuidad de negocio (NIST, ISO 2700X, ISO 22301, etc.).
- Conocimiento de normativa en TI y ciberseguridad (DORA, NIS2, PCI DSS, RGPD, entre otras).
Nice to have
- Valorable experiencia en gestión de riesgos y control interno (COSO, MAGERIT, ISO 27005, etc.).
What you'll get
¿QUÉ OFRECEMOS?
Otra forma de trabajar, creciendo profesional y personalmente, para que puedas poner en marcha todo tu potencial de forma sostenible e inclusiva. Para ello:
• Promovemos el trabajo en equipo, el apoyo mutuo y la participación.
• Personalizamos la formación para desarrollar la capacitación de las personas a la largo de toda su vida profesional.
• Ofrecemos la flexibilidad que necesitas para que exista un buen equilibrio entre la vida profesional y privada.
• Apostamos por el talento interno, y por ello tendrás múltiples oportunidades de enfrentarte a nuevos retos y asumir nuevos roles.
• Cuidaremos de ti a través de Zainduz, nuestro programa de salud, a través del cual podrás disfrutar de: talleres sobre hábitos saludables y bienestar emocional, servicio de Fisioterapia digital, incentivos por venir andando o en bici a trabajar.
• Te facilitaremos el acceso al cuadro médico de Lagun Aro para ti y tu familia, además de condiciones especiales bancarias y de seguros.
Additional information
En definitiva, ofrecemos entornos de trabajo inclusivos y respetuosos, garantizamos igualdad de oportunidades entre hombres y mujeres en las dinámicas de trabajo y en las carreras profesionales, trabajando para ser una referencia en materia de igualdad.
You'll most likely need Spanish to apply.This job was automatically translated to English, .