Job Description
The Information Security Auditor is responsible for evaluating and ensuring the effectiveness of an organization’s information security policies, controls, and procedures. The role involves conducting audits, assessing risks, ensuring compliance with industry standards (e.g., ISO 27001, NIST, PCI-DSS), and recommending improvements to strengthen the company’s security posture.
Plan, execute, and report on internal and third-party information security audits.
Evaluate IT and cybersecurity controls across systems, networks, and applications.
Identify vulnerabilities, compliance issues, and control gaps.
Ensure compliance with standards such as ISO 27001, NIST CSF, HIPAA, GDPR, or PCI-DSS.
Review and assess organizational policies and procedures related to information security.
Work with departments to create remediation plans for audit findings.
Develop audit documentation including risk assessments, findings, and recommendations.
Assist with incident investigations and forensic analysis if necessary.
Maintain up-to-date knowledge of regulatory and industry developments.
Provide training or guidance on audit and compliance best practices.
Job Requirements
Education & Experience:
Bachelor’s degree in Information Technology, Cybersecurity, or a related field.
3–5 years of experience in IT auditing, information security, or risk management.
Experience with security frameworks and audit methodologies (e.g., COBIT, ISO 27001, SOC 2).
Certifications (Preferred):
Certified Information Systems Auditor (CISA)
Certified Information Security Manager (CISM)
Certified Information Systems Security Professional (CISSP)
ISO 27001 Lead Auditor or Lead Implementer
Skills:
Strong understanding of IT infrastructure, cybersecurity concepts, and risk management.
Familiarity with SIEM, vulnerability management tools, and access control systems.
Excellent analytical, problem-solving, and organizational skills.
Ability to clearly communicate technical issues to non-technical audiences.
High level of integrity and attention to detail.