Purpose of Job:
Lead and conduct risk based IT audits following to the bank's audit methodology.
- Plan and lead collaborative risk-based Cyber Securityaudits of moderate to high complexity and conclude whether risks are appropriately managed through the existence of effective control or other techniques.
- For those audits where the auditor assumes a supervisory role, the auditor is expected to develop a comprehensive audit plan clearly outlining the objective, scope, deliverables, approach, resourcing and schedule.
- Follow the Audit Standard Guidelines of the Bank and specific application, project and operations audit methodologies.
- Ensure that audit conclusions and recommendations are properly supported by an orderly accumulation and analysis of documented audit evidence, and that the auditreport content is clear, concise and supported by the audit work completed.
- Perform accountabilities with minimal supervision and provide audit management and audit client with regular status updates of the assignment. The incumbent is expected to seek and obtain direction, perspective and resources as required in order to complete the assigned audit on time and within budget.
- Prepare and deliver effective presentations to clients at audit opening and closing meetings as a means of communicating and gaining their agreement and understanding of audit plans and audit results.
- When required, prepare and present effective presentations on various audit and technology related matters as a means to share information and demonstrate expertise.
- Prepare and discuss audit findings with client senior management; identifying significant issues in a business context, working with audit clients to identify and recommend feasible solutions.
- Establish and maintain positive relationship management with audit clients.
- Maintain information security competency through ongoing professional development and staying abreast of technical matters in the industry.
Skills & Experience:
- 5 years of information securityexperience.
- Excellent written and verbal communication skills.
- Experience in the assessment of threats and risks over IT processes and assets.
- Knowledge and experience with security assessment tools (exploit tools, vulnerability assessment) and Security Operations Centre software (IDS, IPS, SIEM, etc).
- Kowledgeable in areas such as networksecurityarchitecture, penetration testing, Red Team testing, vulnerability asssessments, Data Loss Prevention, web application security, secure coding assessment, cloud security, DDoS protection, encryption and malware protection.
- Working knowledge of primary Bank business areas (e.g. retailbanking, wealth management) would be an asset.
Education & Other Requirements:
Bachelor's degree in Information Technology, Computer Science or equivalent required.
One or more of the following certifications: CISA, CISM, CRISC, CRMA, CISSP, GCIA, CEH, OSCP, OSCE is required.
Some travel may be required within Canada and international bank locations.
Fluency in Spanish would be an asset.
Requisition ID: 21756