SOC2 与 CMMC 内部审计联络员
SOC2 & CMMC Internal Auditor Liaison
开发工程职能支持限定地区(需当地身份)
公司Victory
薪资未公开
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
你将与我们的工程师、支持代表和外部审计师合作,负责:
- 执行复杂的高级审计和咨询工作,以制定针对SOC2和国防部(DOD)网络安全成熟度模型认证(CMMC)/FedRAMP的新审计计划和流程。
- 进行研究、基准测试、审查记录和财务报表。
- 执行数据分析和风险分析,识别适当的控制措施,评估业务流程,并评估管理流程。
- 管理适当的审计范围的制定、外部审计师的选择以及每年审计的顺利完成。
- 持续收集运营文档和数据样本,以关闭流程差距或在差距成为发现项之前记录已接受的风险。
- 与外部审计师保持良好关系,预判审计重点的变化,并为组织做好准备。
- 向组织普及审计要求、风险分析和控制措施,并协助我们将最佳实践整合到现有的操作框架中。
- 根据审计报告识别并记录需要采取的纠正措施。
- 回应客户对我们流程和审计报告的文档请求。
- 理解并遵循来自合作伙伴和供应商的CUECs变化。
要求
你有以下经验:
- 按照通用审计准则和基于风险的内部审计进行审计。
- 云环境中的基本信息技术控制。
- 分析、解释和总结数据、政策和程序,以有效执行审计工作。
- 与内部和外部利益相关者建立和维护基于信任的关系。
你需要...
- 具备高级写作和沟通能力。
- 愿意将你的技能应用到我们小型组织的各个方面,从基层(例如编写流程文档)到高层(例如制定组织审计计划)。
- 帮助我们维护组织的文化和价值观。
如果你有以下经历会是加分项:
- 一些与DOD网络安全要求和合同的经验,例如NIST 800-171。
- 一些与FedRAMP要求的经验。
最初发布于喜马拉雅山
查看英文原文
You will work with our engineers, support representatives, and external auditors to:
- Perform complex, senior-level auditing and advisory work to develop a new audit program and processes for SOC2 and Department of Defense (DOD) Cybersecurity Maturity Model Certification (CMMC) / FedRAMP.
- Conduct research, benchmarking, examining and reviewing records & financial statements.
- Perform data & risk analyses, identify appropriate controls, assess business processes, and evaluate management processes.
- Manage the development of an appropriate audit scope, selection of an external auditor, and successful completion of audits annually.
- Continuously collect operational documentation and data samples in order to close process gaps or to document accepted risk before a gap becomes a finding.
- Maintain relationships with our external auditors to anticipate changes to audit focuses and prepare the organization for them.
- Educate the organization about audit requirements, risk analysis and controls, and assist us with integrating best practices into our existing operational framework.
- Identify and document corrective actions that need to be taken based on audit reports.
- Respond to client requests for documentation of our processes and audit reports.
- Understand and follow changes to CUECs from our partners and vendors.
Requirements
You have experience with:
- Auditing in accordance with generally accepted auditing standards and risk-based internal auditing.
- Basic information technology controls in a cloud environment.
- Analyzing, interpreting, and summarizing data, policies, and procedures for effective performance of audit work.
- Establishing and maintaining trust-based relationships with internal and external stakeholders.
You should...
- Have advanced writing and communication skills.
- Be willing to apply your skills across our small organization, from the low level (e.g. writing process documentation) to high level (e.g. developing organizational audit plans).
- Help us maintain the culture and values of our organization.
It would be a plus if you have...
- Some experience with DOD cybersecurity requirements and contracts, e.g. NIST 800-171.
- Some experience with FedRAMP requirements.
Originally posted on Himalayas
本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。
本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。