Associate Security Auditor, Security Auditor, Security Auditor II, Senior Security Auditor

 

Recruiter:

Option Consultancy Services

Job Ref:

GLI001

Date posted:

Tuesday, December 28, 2021

Location:

Johannesburg, South Africa

Salary:

TCTC


SUMMARY:
Associate Security Auditor, Security Auditor, Security Auditor II, Senior Security Auditor

POSITION INFO:

Associate Security Auditor, Security Auditor, Security Auditor II,

Senior Security Auditor 

FLSA Classification (US only)

  • Associate level is Non-Exempt
  • Security Auditors I, II & Senior are Exempt


Travel                                           

  • Must have the ability to travel up to 75%
The Security Auditor is responsible for probing the safety and effectiveness of computer systems and their related security components, i.e., IT Procedures and an information security management system. This position is also responsible for delivering detailed reports to clients on

the overall effectiveness of the system, explaining any security issues and suggesting changes and improvements.

Essential Functions (Duties & Responsibilities):                                                                

The Associate Security Auditor, under direct supervision, is responsible for: 
  • Executing and/or administering security audits that are planned by more experience staff including inspecting and evaluating financial and information systems, management procedures and security controls
  • Administering risk-focused exams for IT systems
  • Properly documenting the audit process on a variety of computing environment and
  • applications
  • Providing a written and verbal report of audit findings
  • Coordinating and working together with colleagues in other lines of services insupport of client needs for Information Security Services
  • Delivering excellent client service
  • Following, maintaining and improving standard operation procedures (SOP)
  • Achieve and maintain any required professional certification
  • Performs other duties as assigned

Security Auditor I is responsible for all the duties listed under the Associate Security

Auditor level and the following:

  • Executing security audits independently that are planned by more senior staff including inspecting and evaluating financial and information systems, management procedures and security controls; may be planning some fewer complex audits independently
  • Accurately interprets audit results against defined criteria for less complex audits
  • Working with clients to develop appropriate remediation plans
  • Supporting senior members in the sale of security auditing services
  • Performs other duties as assigned

Security Auditor II is responsible for all the duties listed under the Associate Security

Auditor and Security Auditor I and the following:

  • Planning and executing security increasingly more complex audits independently including inspecting and evaluating financial and information systems, management procedures and security controls
  • Assessing the exposures resulting from ineffective or missing control practices
  • Working with management to ensure security recommendations comply with

Company procedures

  • Supporting team technical development, through service development or research, and contributes to company technical processes overall
  • Performs other duties as assigned 
 
Senior Security Auditor is responsible for:
  • All duties listed under the Associate Security Auditor level and the following:
  • Handling the most complex assignments
  • Working as a senior subject matter expert (SME) in their field
  • Performing peer reviews on reports
  • Leading the technical development of a team, training junior members and assisting on improvements to penetration testing services
  • Managing complex security testing projects
  • Managing other team members assigned to projects
  • Performs other duties as assigned

 Required Education and Other Credentials:

  • Bachelor’s Degree in Computer Science, Information Systems, Engineering or related major from an accredited University or equivalent; or
  • Certification, formal training, experience or demonstrated competency may be evaluated and considered in lieu of the educational requirements                                                      

 One or more of the following certifications are required:

  1. Associate Security Auditor): None
  2. Security Auditor: one among ISO 27001 Lead Auditor, PCI Qualified Security Auditor (QSA), Certified Information Security Professional (CISP), Certified Information Security Auditor (CISA) or equivalent
  3. Security Auditor II: Two among ISO 27001 Lead Auditor, PCI Qualified Security Auditor (QSA), Certified Information Security Professional (CISP), Certified Information Security Auditor (CISA) or equivalent
  4. Senior Security Auditor: Certified in Risk and Information Systems Control (CRISC) plus any mandatory for level II

Required Skills/Experience:                                                                             

  •  Knowledge and/or experience with sales, scoping and client/project management
  • Working knowledge of regulatory and industry data security standards, i.e., FFIEC, HIPPA, PCI, NERC, SOX, NIST, etc.
  • Must have experience with ISO 27001/27002, ITIL and COBIT frameworks
  • Must understand Linux, Windows and UNIX operating systems, as well as MSSQL and Oracle databases
  • Knowledge of ACL, IDEA and/or similar software programs for data analysis is preferred
  • Working knowledge of Fidelis, ArcSight, Niksun, Websense, Proofpoint, BlueCoat and/or similar auditing and network defense tools is required
  • Must have a solid understanding of firewall and intrusion detection/prevention protocols and know how to employ virtualization techniques
  • Must have the ability to communicate effectively, both orally and written, with other members of the team and clients/prospective clients
  • Proficiency in Microsoft Word, PowerPoint, Excel, and Outlook
  • Must be able to deliver quality reports on time
  • Must have the ability to work both independently and as part of a team
  • Must have the ability to understand source code in C/C++, VB.NET, ASP, PHP, or Java
  • Must demonstrate a high degree of attention to quality, details, and correctness
Associate Security Auditor has no experience requirements

Security Auditor I must have:
  • At least 2 years of experience working on security audits that includes inspecting and evaluating financial and information systems, management procedures and security controls

Security Auditor II must have:

  • At least 3 years of experience in planning, executing and leading security audits across an organization
  • At least 3 years previous experience as technical leader of a team of Security Auditors

Senior Security Auditor must have:

  • At least 5 years of experience in planning, executing and leading security audits across an organization
  • At least 5 years previous experience as technical leader of a team of Security Auditors
 Physical Requirements and Working Conditions:                                     
  • Must have the ability to work at a computer for extensive periods of time
  • Must have the ability to read (both paper and computer screen) for extensive periods of time
  • Must have the ability to listen and speak with internal external parties on the telephone for extended periods of time
  • Must have sufficient hand, arm and finger dexterity to operate a computer keyboard and other Company equipment

 



 

NB! This job is now closed. You can apply for other jobs by uploading your CV.



 

 

 

Similar jobs you might be interested in:

Senior ICT Infrastructure Manager
Location: Johannesburg
Salary:
Ou client is seeking a highly skilled and experienced senior ICT Infrastructure Manager to lead and manage the ICT network and infrastructure across our organization. This key role involves overseeing the installation, maintenance, and security of hardware and software, ensuring the availability, integrity, and resilience of their IT systems. You will play a vital role in shaping the direction of ...
10 days ago


Senior Infrastructure Engineer
Location: Centurion
Salary: 90000.00 Monthly
Are you an experienced IT infrastructure professional looking for your next challenge? Our client is seeking a senior Infrastructure Engineer to join their team and take the lead in managing and enhancing their IT infrastructure.
10 days ago


PostgreSQL Database Administrator (DBA)
Location: Johannesburg
Salary: market related Monthly
Role OverviewThe PostgreSQL DBA is responsible for the performance, integrity, and security of PostgreSQL databases hosted on Azure. This role also involves leveraging Azure DevOps for continuous integration and continuous deployment (CI/CD) processes. Key Responsibilities:Database Management: Install, configure, and maintain PostgreSQL databases on Azure.Performance Tuning: Optimize database...
10 days ago


IT Support Engineer - Johannesburg
Location: Pretoria
Salary:
12 days ago


Data Engineer
Location: Johannesburg
Salary:
Data Engineers with SAP experience - we are looking for you!
29 days ago


Senior Solutions Architect – Microsoft Azure
Location: Midrand
Salary: Annually
Are you ready to shape the future of enterprise IT on a global stage? We are looking for a visionary senior Solutions Architect with a deep expertise in Microsoft Azure to lead and innovate within our cloud transformation journey. This role is not just about architecture—it's about architecting the future of digital transformation.
5 days ago


AWS Data Engineer
Location: Johannesburg
Salary:
72 days ago


Create a free job alert for Associate Security Auditor, Security Auditor, Security Auditor II, Senior Security Auditor in Johannesburg

Enter your email address below and we will email you similar jobs when they become available:

You can cancel at any time. We will not spam you.
By giving us your email address your agree to our Terms and Conditions