远程工作雷达

SOC2 与 CMMC 内部审计联络员

SOC2 & CMMC Internal Auditor Liaison

开发工程职能支持限定地区(需当地身份)
公司Victory
薪资未公开
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

你将与我们的工程师、支持代表和外部审计师合作,负责:

  • 执行复杂的高级审计和咨询工作,以制定针对SOC2和国防部(DOD)网络安全成熟度模型认证(CMMC)/FedRAMP的新审计计划和流程。
  • 进行研究、基准测试、审查记录和财务报表。
  • 执行数据分析和风险分析,识别适当的控制措施,评估业务流程,并评估管理流程。
  • 管理适当的审计范围的制定、外部审计师的选择以及每年审计的顺利完成。
  • 持续收集运营文档和数据样本,以关闭流程差距或在差距成为发现项之前记录已接受的风险。
  • 与外部审计师保持良好关系,预判审计重点的变化,并为组织做好准备。
  • 向组织普及审计要求、风险分析和控制措施,并协助我们将最佳实践整合到现有的操作框架中。
  • 根据审计报告识别并记录需要采取的纠正措施。
  • 回应客户对我们流程和审计报告的文档请求。
  • 理解并遵循来自合作伙伴和供应商的CUECs变化。

要求

你有以下经验:

  • 按照通用审计准则和基于风险的内部审计进行审计。
  • 云环境中的基本信息技术控制。
  • 分析、解释和总结数据、政策和程序,以有效执行审计工作。
  • 与内部和外部利益相关者建立和维护基于信任的关系。

你需要...

  • 具备高级写作和沟通能力。
  • 愿意将你的技能应用到我们小型组织的各个方面,从基层(例如编写流程文档)到高层(例如制定组织审计计划)。
  • 帮助我们维护组织的文化和价值观。

如果你有以下经历会是加分项:

  • 一些与DOD网络安全要求和合同的经验,例如NIST 800-171。
  • 一些与FedRAMP要求的经验。

最初发布于喜马拉雅山

查看英文原文

You will work with our engineers, support representatives, and external auditors to:

  • Perform complex, senior-level auditing and advisory work to develop a new audit program and processes for SOC2 and Department of Defense (DOD) Cybersecurity Maturity Model Certification (CMMC) / FedRAMP.
  • Conduct research, benchmarking, examining and reviewing records & financial statements.
  • Perform data & risk analyses, identify appropriate controls, assess business processes, and evaluate management processes.
  • Manage the development of an appropriate audit scope, selection of an external auditor, and successful completion of audits annually.
  • Continuously collect operational documentation and data samples in order to close process gaps or to document accepted risk before a gap becomes a finding.
  • Maintain relationships with our external auditors to anticipate changes to audit focuses and prepare the organization for them.
  • Educate the organization about audit requirements, risk analysis and controls, and assist us with integrating best practices into our existing operational framework.
  • Identify and document corrective actions that need to be taken based on audit reports.
  • Respond to client requests for documentation of our processes and audit reports.
  • Understand and follow changes to CUECs from our partners and vendors.

Requirements

You have experience with:

  • Auditing in accordance with generally accepted auditing standards and risk-based internal auditing.
  • Basic information technology controls in a cloud environment.
  • Analyzing, interpreting, and summarizing data, policies, and procedures for effective performance of audit work.
  • Establishing and maintaining trust-based relationships with internal and external stakeholders.

You should...

  • Have advanced writing and communication skills.
  • Be willing to apply your skills across our small organization, from the low level (e.g. writing process documentation) to high level (e.g. developing organizational audit plans).
  • Help us maintain the culture and values of our organization.

It would be a plus if you have...

  • Some experience with DOD cybersecurity requirements and contracts, e.g. NIST 800-171.
  • Some experience with FedRAMP requirements.

Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

← 返回全部职位