أبلاي إيدج ابدأ البحث عن عمل

Senior Auditor - IT & Cybersecurity Audit

KLN Logistics Group · Kwai Tsing District, Hong Kong SAR

قدّم وتابع مع أبلاي إيدج
ResponsibilitiesExecuting audits in areas such as Information Risk Management, Technology Governance, Cybersecurity, Network Security, Identity and Access Management, Data Center Security, Cloud Security, Architecture Reviews, and Business Continuity/ Disaster Recovery.Assist in developing and maintaining the IT & Cybersecurity internal audit programs, test plans, and request lists, etc.Plan and execute audit projects and perform ad hoc reviews or investigations to understand the information technology control environment to assess and evaluate the effectiveness and efficiency of internal controls and operating practices;Perform walkthrough, data analysis, and audit testing to identify key risks, assess controls, and develop recommendations on solving or mitigating risks and control issues during audits; ensure all audit work done is properly and timely documented in accordance with the required standards. Contribute and assist in the production of meaningful internal audit reports that clearly articulate the position on risks and related issues, clearly communicate potential issues, evaluate corrective action plans, track management’s remediation progress, and perform follow-up reviews to ensure the audited units properly and timely implement audit recommendations. Assist the engagement leader in managing audit projects and provide guidance/ coaching to the junior team members. Support multiple simultaneous audit projects to meet time and quality objectives.Assist with various internal team/department initiatives.Engage in continuous knowledge development of the audit techniques and performance standards, relevant rules and regulations, best practices, and audit tools.RequirementsUniversity degree in information systems or other relevant degree, with 3-5 years of experience in a technology audit/risk management role.Experience analyzing complex data sets.CISA, CISSP, and/or CISM designations are preferred.Strong understanding and experience with testing of IT General Controls.Good understanding of IT governance, risk management, and control frameworks, i.e., COBIT, ISO27001/ ISO27002, NIST CSF, CIS Controls, ITIL, etc., with the ability to assess the effectiveness of governance structures, risk management processes, and internal controls.Good knowledge of cybersecurity controls and technical security practices, including network security, vulnerability assessment and penetration testing, operating system and application hardening, identity and access management (IAM/PAM), security monitoring and logging, data protection, intrusion detection/prevention systems, and incident response.Good knowledge of IT resilience and operational controls, including backup and recovery processes, disaster recovery and business continuity planning (DR/BCP), capacity management, patch management, configuration management, and infrastructure monitoring.Good understanding of technology project delivery governance and software development practices, including SDLC and DevSecOps processes, secure coding standards, CI/CD controls, environment segregation, release management, and management of third-party software componentsGood knowledge of cloud technologies and security controls across IaaS, PaaS, SaaS, Microsoft 365, Azure, AWS, and hybrid environments, including cloud identity management, security monitoring, and configuration management.Demonstrates a risk-based audit mindset, with the ability to assess technology and cybersecurity issues from business, operational, governance, and management perspectives.Ability to quickly comprehend business processes, identify risk implications, analyze complex situations, reach appropriate conclusions, and make value-added and practical recommendations.Results-oriented with a keen focus on quality and delivering value; ability to balance multiple priorities and projects; strong attention to detail while retaining focus on the big picture and top risks; flexible and organized with the ability to oversee multiple projects concurrentlyAble to travel up to 30% regionally internationally.If you have the energy and qualifications to add to our velocity, Please visit KLN Company Webpage to apply or send your CV with your present and expected salary to Human Resources & Administration Department by clicking Quick Apply.(We are an equal opportunity employer and welcomes applications from all qualified candidates. All personal data will be kept in the strictest confidence and will be used for recruitment purpose only. All applicants maybe considered for other suitable positions in KLN. All personal data of unsuccessful candidates will be destroyed.)