Thomson Reuters

Senior Cyber Compliance & Audit Analyst

Posted: 1 days ago

Job Description

DescriptionLooking forward to advancing your career in IT Audit? We are growing and we are hiring, come join us.Location: Toronto, Canada (Hybrid)About the Role :In this opportunity as Senior Cyber Compliance & Audit analyst, you will assess, challenge, and test the design and operational effectiveness of controls using TR's control framework and ISO 27001 controls by working collaboratively with control owners and stakeholders to improve the control testing process, including defining re-test cycles and evidence expected.Execute a testing plan by communicating requirements to control owners, reviewing evidence submitted, agreeing on deficiencies found and finalizing the next steps in meeting control requirements.Complete test papers including the results of testing and storing relevant artifacts.Oversee and act as a liaison for both external and internal audits.Identify procedures and practices that are not compliant with industry FrameworksRecommend and support stakeholders making changes to address non-compliance issues.Compile reports on audit results and present them to managers & supervisors.Propose efficiencies and automation where possible to optimize workflow.Work closely with other teams like ERM, Finance, business and application owners, third party or contractors supporting processes to report and track remediation plans for any control deficiencies identified.Ensure awareness about security risks, best practices and policy/standard requirements are essential to ensure compliance.Work independently, act decisively and ensure personal deadlines and team requirements are met.Willingness and drive to learn continuously and approach change with openness.About YouYou're a fit for the role of Senior Cyber Compliance & Audit analyst if your background includes:Bachelor's degree in IT, Accounting, Finance or equivalent education and experience (preferable).At least 4+ years of relevant work experience in ISO 27001:2022, ITGC, SOC, PCI within Audit, Big 5, consulting firms or as line 1a or line 1b completing IT-ISControl testing or working within a Governance or Compliance function across Financial Services organizations.One of these certifications in order of preference is essential ISO, CISA, CISSP, CCAK, CISM, or CRISC .Strong ethical principles and understanding of business and IS ethics.Awareness about common security vulnerabilities of web and cloud applications and operating techniques from sources such as SANS, OWASP Top10 and Cloud Security Alliance (CSA).Experience in testing Cloud controls and related technologies will be an asset.Excellent oral and written communication skills in English. Additional expertise in French, Spanish or another language will be an asset.Knowledge about GRC platforms like Vanta, ServiceNow, Process Unity, RSA Archer, MetricStream and the like.All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.The pay range that the employer in good faith reasonably expects to pay for this position is $40-$48/hr CAD.Our optional benefits can include medical, dental, vision and retirement benefits.Applications will be accepted on an ongoing basis.Tundra Technical Solutions (the operator of this Talent Community) is a global leader of contingent talent services. Our success and our clients’ success are built on a foundation of service excellence. We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic. Qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable law, including the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Unincorporated LA County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: client provided property, including hardware (both of which may include data) entrusted to you from theft, loss or damage; return all portable client computer hardware in your possession (including the data contained therein) upon completion of the assignment, and; maintain the confidentiality of client proprietary, confidential, or non-public information. In addition, job duties require access to secure and protected client information technology systems and related data security obligations.

Job Application Tips

  • Tailor your resume to highlight relevant experience for this position
  • Write a compelling cover letter that addresses the specific requirements
  • Research the company culture and values before applying
  • Prepare examples of your work that demonstrate your skills
  • Follow up on your application after a reasonable time period

Related Jobs