未来职位:网站安全审计员:洛杉矶都会区 远程
Future Opening: Site Security Auditor: Los Angeles Metro REMOTE
我们预计未来需要招聘一名站点安全审计员。
ISE的站点安全审计员将协助我们媒体和娱乐供应商审计计划的发展。我们理想的站点安全审计员候选人必须具备GRC工具、入侵预防与检测的实际技术经验,以及直接的安全审计经验。
你在ISE的工作内容包括:
- 对在实体场所执行工作流程的服务设施进行站点评估,包括商业和住宅场景。
- 通过了解安全协议并展示负责任的网络安全实践,包括风险管理、控制实施、ISMS实施和业务连续性管理等主题,来推动客户的安全,从而增强整体安全态势。
- 与客户及其供应商员工进行会议,同时处理供应商的安全政策、工作流程、物理和数字安全参数。
- 制定审计计划以测试关键控制措施并验证合规性。评估已识别弱点的严重性及涉及的风险影响。
- 根据电影协会(MPA)最佳实践及其他最佳实践和标准机构,识别安全差距,理解其根本原因或相关影响,并了解如何解决。
- 记录并向内部和外部利益相关者汇报审计发现、观察结果和结论。
- 评估并提出建议,以确保供应商符合行业最佳实践。
- 与领导层合作,制定对现有政策和实践的调整,以解决业务流程和审计流程中的缺口。
- 确保在约定的工作量和时间范围内完成项目。
必备条件:
- 近四年内有媒体和娱乐行业审计经验,至少一年。
- 居住在加利福尼亚州洛杉矶都会区
- 熟悉安全审计框架、实践、工具和技术。
- 审计人员应具备分析和技术知识,同时具备访谈、人际交往和演示技能。
- 具有电影协会(MPA)最佳实践的经验,并了解这些实践在供应商场所中的整合方式。
- 至少两年的IT审计经验,涵盖内容安全、网络安全、信息安全和/或信息系统。
- 至少有一项活跃的信息
查看英文原文
We are anticipating the need to hire a Site Security Auditor in the future.
The Site Security Auditor at ISE will assist in the growth of our media and entertainment vendor audit program. Our ideal candidate for the Site Security Auditor must have hands-on technical expertise with GRC tools, intrusion prevention & detection and direct experience with security audits.
What you’ll do at ISE:
- Perform site assessments of services facilities, which conduct workflows at physical premises, including commercial and residential scenarios.
- Drive client security through knowledge of security protocols and demonstrating responsible cybersecurity practices, including risk management, control implementation, ISMS implementation, and business continuity management, among other topics, to build a stronger overall security posture.
- Conduct meetings with clients and clients’ vendors’ employees, while addressing the vendors’ security policies, workflow, physical, and digital security parameters.
- Create audit plans to test key controls and verify compliance. Assess the severity of identified weakness and the impact of the risk involved.
- Identify security gaps based on Motion Pictures Association (MPA) Best Practices and other best practice and standard bodies, understand any underlining causes or related impact, and how to address them.
- Document and present audit findings, observations, and conclusions to internal and external stakeholders.
- Evaluate and develop recommendations to ensure vendors compliance with industry best practices.
- Collaborate with leadership to develop adjustments to existing policies and practices in order to address gaps within business processes and within the audit process.
- Ensure completion of the project within the agreed-upon level of effort and time frame.
Must Haves:
- One year of experience within the last four years in Media & Entertainment industry audit experience.
- Reside in Los Angeles, California metro area
- Knowledge of security audit frameworks, practices, tools, and techniques.
- Auditors should possess analytical and technical knowledge together with interviewing, interpersonal and presentation skills.
- Experience with Motion Picture Association (MPA) Best Practices and how they are integrated in vendor locations.
- Minimum of two years of experience conducting IT audits covering Content Security, Cyber Security, Information Security, and/or Information Systems.
- At least one active information security, cybersecurity, and/or IT audit certification below.
- CompTIA
- Security+
- CASP+
- PenTest+
- EC-Council
- CEH
- GIAC
- GSEC
- GISF
- GWAPT
- GISP
- ISACA
- CISA
- CISM
- CRISC
- CGEIT
- CDPSE
- CSX-P
- ISC2
- CISSP
- PECB
- ISO 27001 Certified Auditor
What you bring to the table:
- Experience reading and illustrating architecture and network diagrams.
- Understanding of the principals of information security policies, business continuity plans, and industry control requirements as they pertain to the security of the content.
- Ability to identify gaps and develop recommendations around operations, policy management, and physical and digital security.
- Knowledge of compensating controls or alternatives due to restraints such a budget, employment, nature of content, etc.
- Strong writing, communication, logistics/time management, professionalism.
- Ability to travel internationally.
Salary:
Associate to Mid Level: $70K-$90K
Senior Level: $90K-$110K
If you don't meet all the criteria above but are still interested in the job, please apply. Nobody checks every box, and we're looking for someone excited to join the team.
What we bring to the table:
- Check out joinise.io for full details
- Work that matters; projects that impact people’s everyday life and wellbeing
- Quality, integrity, dedication, and education: our core values.
- Life balance: flexible schedule, work from home option, and unlimited vacation
- $0 health premium plan option, including spouse and family.
- Opportunities to research and publish, speak at major security events and conferences.
- Leadership and peers that support and mentor you: your growth is our growth, your success is our success.
- Relaxed and fun environment: ditch the suit and tie, sit or stand at your desk or find a sofa.
How you’ll learn at ISE:
Everyone has a mentor, or two or three sometimes. We hold you and ourselves accountable for your advancement. You’ll learn directly from your mentor, your colleagues, resources vetted by the team, and at regular firetalk lunches by your peers. You also have access to paid training, workshops, university courses, certification courses, and we’ll pay for the certs too. Want to learn a new skill that you aren’t currently using but want to? Great! Innovation is key–new technology is important.
About ISE:
ISE is an independent security consulting and software firm headquartered in Baltimore, Maryland dedicated to securing high value assets for global enterprises and performing groundbreaking security research. Using an adversary-centric perspective driven by our elite team of analysts and developers, we improve our clients’ overall security posture, protect digital assets, harden existing technologies, secure infrastructures, and work with development teams to ensure product security prior to deployment. Our team enjoys working in a creative, educational, and comfortable environment where they can thrive professionally.
Building a Better Community:
We value different viewpoints and fresh perspectives. We embrace people who challenge our thinking and question the status quo. We are opposed to narrow minded, exclusionary, and discriminatory viewpoints or practices that inherently undermine our creative process, hinder growth, and impede innovation.
Need more info?
Be sure you spend some time at . Make sure you look through all the perks on the Careers page, then check out our Research and Blog, our events page for the IoT Village, and About page. Follow us on Twitter @ISEsecurity and @IoTvillage
Originally posted on Himalayas