Cybersecurity Auditor
Accountabilities: Execute risk-based cybersecurity and IT audits by defining audit objectives, evaluating processes and associated risks, designing and performing control testing, assessing control effectiveness, and documenting conclusions for identified risks.
Review IT controls, security configurations, and technology processes across areas such as change management, incident management, access management, patching, APIs, asset inventory, vulnerability management, operations, databases, risk management, authentication, authorization, and data protection.
Assess cybersecurity governance and technical practices, including secure system and application configuration, security assessments, business continuity, disaster recovery, audit logging, segregation of duties, physical security, cloud environments, and third-party risk.
Communicate identified issues, risks, technical findings, and potential impacts clearly and professionally to both technical and non-technical audiences, while developing actionable recommendations.
Prepare comprehensive audit documentation and final reports that clearly communicate the effectiveness of controls and the organization's ability to mitigate identified risks.
Lead teams of IT auditors during assigned engagements, providing direction and maintaining effective coordination throughout the audit lifecycle.
Apply recognized security, risk, internal control, and audit frameworks—including ISO 27000, COSO, NIST, COBIT, IPPF, and ITIL—to support consistent and effective audit activities.
Maintain strong time management and professional judgment while managing multiple audit activities, stakeholders, priorities, and deadlines.
Requirements
Bring at least 5 years of professional experience in Information Technology, Cybersecurity, Information Security, Technology Risk, IT Operations, Application Development, Cloud Technologies, or a related technical field; 7+ years is preferred for more advanced profiles.
Have experience in cybersecurity, IT auditing, risk management, SOX, IT compliance, or related technology assurance functions, ideally within a large or global organization.
Demonstrate strong knowledge of cybersecurity laws, regulations, standards, and security practices, with familiarity with frameworks such as COBIT, ISO 27001/27002, NIST, and COSO.
Possess broad knowledge of cybersecurity processes, including incident response, secure software development, security governance, cloud computing, SDLC, third-party risk management, penetration testing, vulnerability management, disaster recovery, IAM, access management, configuration management, audit logging, and physical security.
Be capable of independently executing risk-based audits, from defining objectives and assessing risks through control testing, impact analysis, recommendations, and final reporting.
Communicate complex technical information, audit findings, and risks clearly and professionally in English to both technical and non-technical stakeholders.
Demonstrate excellent analytical, critical-thinking, organizational, and time-management skills, with the ability to manage competing priorities and deliver audit engagements effectively.
A bachelor's or master's degree in Information Security, Information Systems, Computer Science, or a related field is preferred.
Hold at least one relevant professional certification, such as CISA, CISM, CISSP, PCIP, Security+, CC, or an equivalent credential.
Benefits
Fully remote position based in Brazil.
Full-time Monday-to-Friday schedule, from 8:00 AM to 5:00 PM.
Opportunity to work on impactful cybersecurity, technology risk, and audit initiatives across complex technology environments.
Access to professional development opportunities, including certifications, coaching, continuous feedback, and hands-on learning experiences.
Exposure to learning opportunities involving technologies and certifications from providers such as Microsoft, Google, and Amazon.
Supportive and inclusive work environment focused on employee well-being, belonging, professional growth, and continuous learning.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1