Security Auditor (m/f/d)
Berufserfahrener
The Berner Group
Region: Cologne or Künzelsau (mobile work is possible)
Bereich: IT Security
Jetzt bewerbenREADY FOR BERNER?
The BERNER Group is a European trading company for professionals in the mobility, construction and industry sectors. We are the leading B2B specialist and innovative manufacturer of chemical products. Our purpose is: "We are pushing the limits of the possible for the shapers of a better tomorrow". This means that our strong brands BERNER, BTI by BERNER and CCS help our customers to keep their business successful and running.
YOUR TASKS
- Conducting audits of security controls, risk management processes, and compliance within IT environments, ensuring adherence to relevant frameworks and regulatory standards.
- Collaborating with internal teams to evaluate security practices and identify gaps or weaknesses in controls.
- Advising on remediation actions to address audit findings and improve the security posture.
- Providing support in preparing for audits from external parties or regulatory bodies, ensuring compliance documentation is complete and accurate.
- Performing risk assessments and assisting in the development of risk mitigation strategies.
- Ensuring continuous improvement of internal audit processes and security compliance practices.
- Communicating audit findings clearly to stakeholders, including senior management, and providing recommendations for risk reduction and improved governance.
- Monitoring and reporting on the effectiveness of security policies and controls, helping to drive adherence to industry best practices.
YOUR PROFILE
- Completed a degree in IT Security, Information Systems, Business Administration, or a similar field.
- Strong knowledge of security frameworks and standards, such as NIS2, ISO 27001, NIST, SOC 2, and other relevant regulations and industry best practices.
- Extensive experience in conducting IT security audits, vulnerability assessments, and compliance reviews.
- Ability to assess and audit security controls, risk management processes, and policies, identifying areas for improvement and ensuring compliance with regulatory requirements.
- Technical expertise to audit and assess complex technical systems, not just processes, ensuring a thorough understanding of both the technical and operational aspects of the systems being reviewed.
- Strong analytical skills with the ability to evaluate complex security data and develop actionable insights.
- Excellent stakeholder management skills, with the ability to work effectively with internal and external stakeholders at all levels, driving necessary changes in processes and systems.
- Strong interpersonal skills to guide and influence change management initiatives within the organization.
- Fluency in English (both written and spoken).
- Additionally Desired Qualifications:
- German language skills are helpful but not required.
- Broad experience across various domains of security.
- Proven experience in auditing and governance, risk, and compliance (GRC), preferably with a background in a Big Four auditing firm or a similar organization.
WHY BERNER?
- permanent contract
- mobile work is possible
- structured onboarding
- state-of-the-art workplace
- Künzelsau: canteen with daily, freshly prepared dishes
- Cologne: Pluxee meal vouchers
- allowance for transportation costs
- bike leasing (Jobrad)
- Wellpass with more than 5.000 sport and fitness offers
- company pension scheme and employee purchase with attractive conditions
- many training and development opportunities within our future-oriented company
Are you ready to tread new paths with us?
Then waste no time and apply now. By using our very short online form you ensure a prompt process of your application. Please also submit your salary requirements and possible start date.
If you have any questions, you can reach Francesca Talamo:
+49 (0) 7940 121-641
We are looking forward to your application!
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Audits Compliance Governance ISO 27001 Monitoring NIS2 NIST Risk assessment Risk management SOC SOC 2
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.