Senior Security Auditor 0926
We are seeking a Senior Security Auditor to join our cybersecurity assurance team and take ownership of complex, high-impact audits across cloud infrastructure, software development, identity and access management, and enterprise technology environments.
This is a highly technical audit role for someone who can go beyond reviewing documentation and actually evaluate how security controls operate within modern technology environments. You will lead audit engagements from planning through final reporting, work directly with technical control owners, and provide an independent perspective on security risks and control effectiveness.
The ideal candidate is comfortable operating at the intersection of cybersecurity, technology, compliance, and risk. You will partner closely with engineering, infrastructure, security, and compliance teams while maintaining the independence and professional skepticism expected of an internal audit function.
You will also have the opportunity to mentor less-experienced auditors and help improve the team's overall audit methodology, automation, and continuous monitoring capabilities.
What You'll Do
- Lead complex security and technology audits spanning cloud environments, on-premises infrastructure, application development, identity and access management, and third-party technology platforms.
- Develop audit scopes, risk assessments, testing strategies, sampling methodologies, and detailed audit procedures based on applicable security and regulatory requirements.
- Evaluate the design and operating effectiveness of security controls through technical walkthroughs, configuration reviews, log analysis, access reviews, and examination of supporting evidence.
- Assess cloud security configurations, identity controls, change management processes, vulnerability management practices, and software development security controls.
- Translate security frameworks and regulatory requirements into practical, technology-focused testing procedures.
- Identify control deficiencies and develop clear audit findings that articulate the underlying risk, root cause, business impact, and recommended remediation.
- Participate in organizational security maturity assessments and help identify gaps between current capabilities and desired control maturity.
- Coordinate with external auditors and assessors during security assessments, customer reviews, and regulatory examinations.
- Serve as a key point of contact for evidence collection, walkthroughs, testing requests, and follow-up questions throughout external assessments.
- Monitor remediation activities and perform follow-up testing to determine whether identified issues have been appropriately addressed.
- Provide constructive challenge to control owners when proposed remediation does not adequately mitigate the underlying risk.
- Mentor junior and mid-level auditors on audit methodology, testing techniques, evidence standards, documentation, and professional judgment.
- Help improve audit processes through better workpaper standards, testing automation, data analytics, and continuous monitoring.
- Communicate audit results effectively to both technical stakeholders and leadership.
What We're Looking For
- 8+ years of progressive experience in security audit, IT audit, cybersecurity, technology risk, or a related discipline.
- Demonstrated experience independently leading security or technology audits from planning through reporting and remediation follow-up.
- Strong technical understanding of cloud security, with significant experience in AWS environments.
- Ability to evaluate cloud architecture, identity and access controls, security configurations, logging/monitoring, encryption, network controls, and infrastructure-as-code.
- Strong knowledge of commonly used cybersecurity and compliance frameworks, including NIST CSF, NIST SP 800-53, PCI DSS, and applicable data/security regulations.
- Experience evaluating software development and application security controls, including SDLC processes, code review, source-control protections, secrets management, CI/CD security, and vulnerability management.
- Experience auditing identity and access management platforms and controls, including SSO, MFA, user lifecycle management, privileged access, and access reviews.
- Strong analytical and written communication skills, with the ability to turn complex technical observations into concise, business-focused audit findings.
- Ability to work independently, exercise sound professional judgment, and manage multiple audit activities with limited day-to-day oversight.
- Demonstrated ability to coach and develop less-experienced auditors.
- Strong interpersonal skills and the ability to build productive relationships with engineering, security, infrastructure, and compliance teams while maintaining audit independence.
- Relevant certifications such as CISA, CISSP, CCSP, AWS Security Specialty, or QSA are highly preferred.
- Experience working within highly regulated, security-sensitive, or technology-intensive industries is a plus.
Why This Role
This is an opportunity to have meaningful influence over an organization's security posture while working directly with technical teams and leadership. The role combines hands-on technical auditing with ownership of complex engagements, making it a strong fit for an experienced auditor who wants to operate at a senior level and help shape the organization's broader security assurance program.
Required Skills
Required Languages
🇬🇧 English