Required Skills / Qualifications:
- Bachelor's degree in management information system or computer science or engineering
- Minimum 5 years' experience in technical information security/privacy
- Minimum 5 years' experience in Big 4 or regulatory compliance consulting experience applying risk and threat assessment methodologies with experience across IT, security, privacy and business
Preferred Skills / Qualifications:
- One existing certification from each of the following categories, which must be currently maintained and valid.
- General Audit Certification:
- Certified Information Systems Auditor (CISA)
- Certified Internal Auditor (CIA)
- Certified Fraud Examiner (CFE)
- Information Technology Infrastructure Library (ITIL)
- Certified Information Systems Auditor (CISA)
- Certified in Risk and Information System Control (CRISC)
- Certified in Risk Management Assurance (CRMA)
- Certified in Governance of Enterprise IT (CGEIT)
- Cisco Certified Network Associate/Professional (CCNA, CCNP)
- IT Security/Privacy Certification:
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Quality Security Assessor (QSA)
- Payment Card Industry Professional (PCIP)
- Certified Ethical Hacker (CEH)
- Microsoft Certified Professional/Security Engineer (MCP, MCSE)
- Advanced knowledge of security principles and technologies with hands-on experience in information technology systems and security assessments, or security by design testing, or a variety of security and privacy technology solution implementations
- General auditing standards such as IIA, PCAOB, GAAP, GAAS, IPPF or equivalent.
- General information technology processes of Contract Management, Change Management, Recovery Management, Operations Management, Configuration Management, and Risk Management and testing of ITAC/ITGC controls.
- Automated audit control testing environments such as SAP/ERP, ServiceNow, PeopleSoft or equivalent.
- Finance regulatory compliance testing such as NAIC/MAR, SOX, EHNCA, ICFR or equivalent.
- Information technology compliance testing such as ISO27001/2013, COSO, AICPA/SOC(I,II,III) or equivalent.
- Information security compliance testing such as CMS ARS, CIS, CSA or equivalent.
- Information privacy compliance testing such as HIPAA (45 CFR), GDPR, CCPA, NYCRR or equivalent.
- GRC frameworks such as NIST (800-36), ISO (27k series), COBIT, ITIL, GAAS or equivalent.
- Compliance crosswalk methodologies and models such as SCF, CCF, UCF, RMF, HITRUST or equivalent.
- Proven ability to effectively communicate complex technical information to both technical and non-technical audiences at all levels of the organization.
- Proven ability to multitask various audits and projects throughout all audit phases.
- Proven ability to effectively prioritize tasks in a deadline-driven environment.
- Clean credit history as reported by credit report
Additional Information:
- Upon offer of employment, the individual will be subject to a background check and a drug screen.
Aleron companies (Acara Solutions, Aleron Shared Resources, Broadleaf Results, Lume Strategies, TalentRise, Viaduct, and Aleron's strategic partner, SDI) are Equal Employment Opportunity and Affirmative Action Employers. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender identity, sexual orientation, national origin, genetic information, sex, age, disability, veteran status, or any other legally protected basis. The Aleron companies welcome and encourage applications from diverse candidates, including people with disabilities. Accommodations are available upon request for applicants taking part in all aspects of the selection process.
Applicants for this position must be legally authorized to work in the United States. This position does not meet the employment requirements for individuals with F-1 OPT STEM work authorization status.