IT Auditor
The IT Auditor will be responsible for auditing the processes, procedures and controls integrated within the ITA infrastructure, reviewing metrics and reporting on the state of compliance with corporate policies, industry regulations and customer requirements. This position will manage relationships with external auditors and ITA customers and will maintain expertise in regulations and standards such as Payment Card Industry, ISO17799, Sarbanes Oxley and state, federal and international laws. This position reports to the Manager of Information Security.
Responsibilities: • Performs audit procedures, including identifying and defining issues, developing criteria, reviewing and analyzing evidence, and documenting internal processes and procedures.
• Review new regulations, guidance, policies and customer initiatives and develop programs to address any new compliance requirements.
• Conducts data extraction, analysis, and security reviews utilizing software tools.
• Manage relationships with external auditors and customers to assure compliance with standards such as PCI, ISO17799, Sarbanes-Oxley, Safe Harbor and government regulations.
• Works with legal counsel to ensure the company has and maintains appropriate privacy processes and policies reflecting current legal practices and requirements.
• Interface with internal management to communicate the state of compliance.
• Work with internal groups to communicate how to resolve non-compliance with laws, policies, and procedures.
• Build business relationships and act as an essential interface between IT and the business on IT compliance matters.
Participate in 24/7 on-call rotation.
Qualifications: • B.S. or equivalent experience in Computer Science or a related discipline.
• Three or more years experience with security audit and assessment methodologies.
• Demonstrated experience conducting risk assessments.
• Substantial experience with current legal and regulatory requirements around information security and privacy, including PCI, SOX, ISO7799, GLBA, etc
Special Knowledge/Skills Required: • Strong understanding of network security (firewalls, IDS, routers, crypto, PKI, VPN, anti-virus software, Internet services).
• Strong understanding of system security (Microsoft NT/2000/AD/XP, LDAP, Linux, workstation platforms, mail servers)
• Fundamental understanding of security attack profiles.
• Excellent communication and presentation skills.
• Proven ability to perform complex analysis, and prepare documentation which establishes business objectives, problems, options, and recommendations.
• Superior organizational and time management skills.
• CISSP or CISA is a plus.
How to Apply
If you are interested in this position, please send your resume to us via this link.
An ITA Software recruiter will review your qualifications and contact you if there is a fit with our needs.
Don't see the perfect job for you? Sign up for our RSS feed.
|