GitLab3 дня назад

Senior Security Assurance Engineer

Зарплата не указана
РЫНОК
10 833медиана по профессии
Security Engineer · 5 вакансий с указанной зарплатой
8 417половина предложений: 8 500–15 00016 667
Работодатель не указал зарплату — сравните с рынком сами.
Remote

Обязанности

  • 01Design, document, and maintain IT General Controls and security controls across the in-scope estate
  • 02Test controls for design and operating effectiveness against regulatory, contractual, and corporate policy requirements
  • 03Map shared controls once and test them to serve multiple obligations at the same time
  • 04Serve as the compliance point of contact and liaison for IT, Corporate Security, Engineering, and Finance teams
  • 05Help set standards and control expectations for the governed use of AI across corporate and business systems
  • 06Partner with Security Governance on corporate security policy work
  • 07Run recurring compliance monitoring on monthly, quarterly, and annual cadences
  • 08Assess system implementations, migrations, and significant changes for control readiness ahead of go-live
  • 09Manage SOX ITGC testing and certification requests from internal and external auditors
  • 10Identify, track, and lead remediation of control deficiencies and risks

Требования

  • 015+ years in IT compliance, security compliance, IT audit, information security, or information technology
  • 02BA/BS in a business or technology field or equivalent experience
  • 03Big 4 or external audit experience is a plus
  • 04Demonstrated experience testing controls against frameworks such as COSO, COBIT, NIST CSF, ISO 27001, SOC 2, and SOX ITGC
  • 05Experience working directly with internal or external auditors
  • 06Experience assessing controls in SaaS and cloud-native application stacks
  • 07Working knowledge of identity and access management — SSO, SCIM, RBAC, privileged access, and joiner/mover/leaver processes
  • 08Familiarity with AI governance concepts and control questions raised by AI tools
  • 09Experience contributing to security policies and standards