
Mid-level Auditor – Technology & Information Security
Omni Conectado
full-time
Posted on:
Location Type: Hybrid
Location: São Paulo • Brazil
Visit company websiteExplore more
About the role
- Execute the Technology and Information Security audit plan based on risk and regulatory compliance;
- Manage audit projects from planning through execution, reporting and follow-up;
- Maintain continuous interaction with Technology and Information Security teams to identify and map risks and key controls of audited processes;
- Review frameworks and regulations, verifying alignment with internal guidelines and industry best practices (COBIT, ITIL, ISO, NIST, CIS Controls, Central Bank, SEC/CVM, etc.);
- Define and design the work program and tests to be performed across Technology and Information Security topics;
- Prepare documentation of tests conducted during audits, and draft recommendations and reports;
- Analyze the organization’s technology and security solutions, tools, devices and mechanisms;
- Prepare audit reports including risk assessment and recommendations to mitigate identified risks;
- Present and discuss audit findings with the audited areas;
- Periodically monitor the implementation of action plans established for risks related to recommendations issued by Internal Audit.
Requirements
- Previous experience auditing Information Security, Cybersecurity, LGPD (data protection law), CLOUD, IT Risk Management, Business Continuity Management, Governance, IT Service Management, Data Storage, Security Assets, Servers, Network and Connectivity Assets, Infrastructure Management, APIs, and IT Architecture;
- Experience interacting with Technology and Information Security teams;
- Prior experience in IT audit or IT consulting projects;
- Knowledge of agile methodologies;
- Bachelor’s degree in Information Technology, Computer Science, Information Systems, Information Security, Computer Engineering, or a related field;
- Preferred: Postgraduate degree and/or specialization in Information Security, Networking, Databases and/or Technology and Data Protection topics;
- Advantage: knowledge and use of data analysis tools (Alteryx, ACL, SQL, PYTHON and/or similar);
- Knowledge of applying frameworks (COBIT, ITIL, COSO, CIS CONTROLS, NIST, ISO, etc.);
- Familiarity with defining security architectures and solutions for environments, systems and applications.
Benefits
- 👶 Childcare allowance for children up to 6 years and 11 months
- 🏋️ TotalPass for your physical health
- 🏠 Hybrid work model 3x2 (on-site and remote)
- 🍴 Flexible meal and food allowance card
- 🚌 Commuter transportation allowance
- 🩺 Medical and dental coverage (SulAmérica, apartment plan)
- 🛡️ Life insurance
- 🏃 Wellness program (running and more)
- 🎂 Day off on your birthday
- 💻 Conexa Saúde – online consultations with no co-pay
- 💰 Profit sharing
- 👕 No dress code – be yourself!
- ⏰ Flexible working hours
- 🎓 Corporate University
- ✨ And much more for you!
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
Information Security auditingCybersecurityIT Risk ManagementBusiness Continuity ManagementGovernanceIT Service ManagementData StorageInfrastructure ManagementData analysis (Alteryx, ACL, SQL, PYTHON)Security architecture
Soft skills
Project managementCommunicationInterpersonal skillsAnalytical skillsPresentation skills