Security Compliance and Assurance SME
Your day to Day
You will be responsible for ensuring that the policies, procedures and internal controls objectives in scope for Vodafone CIoud and Infrastructure (VCI) workstreams are fulfilled.
You will ensures that the policies, standards, processes and control activities are designed and operated to meet external regulations, financial audit requirements, internal audits, such as: Sarbanes-Oxley (SOx), PCI-DSS and ISAE 3402 requirements. The role acts as main point of contact during audits (internal or external audits.), assumes control coordination and operation, as needed.
You will ensures the efficient operation of assigned audit processes throughout the VCI organization, covering On-Premises and both Private/Public Cloud Infrastructure.
You will be responsible to coordinate VCI compliance activities with Security Departments, Local Markets and other VCI internal departments. This role oversees the implementation of new services and technologies at VCI, focusing on transitioning services from an On-Premises datacenter to a private/public cloud.
With these activities you will have a great impact on our business
•You will manage the assigned controls, from design, documentation, implementation, and execution.
•You will coordinate the audit session for the assigned area/controls from planning, evidence delivery and resolution.
•You will coordinate the communication between Central/Group Teams with VCI management and external/internal auditors.
•You will anticipate risks/gaps and takes pro-active action to address them without impacting the processes operation and audit cycles.
•You will ensure the efficient remediation of deficiencies identified by the auditors; implements controls and new activities as required by the auditors.
•You will be responsible with the continuous improvement of the processes and controls to obtain simple, efficient and error free processes.
•You will build control documentation and templates for new services together with service/product owners.
•Effectiveness of assigned controls
•Updated and efficient control processes
•Control enablement documentation
With these skills you are a great candidate
•You have a very good knowledge of SOX IT General Controls (Access management, Computer Operations: Back Up and Recovery, Change Management, Information Security Policies, Program Development, SOC Reports Review).
•You have a good knowledge of PCI-DSS; ISAE 3402 (and similar).
•You have experience in internal and external audits, in implementation of compliance requirements in cloud environments.
•You have a understanding of IT-Service Management ISO 20000)/ ISO 27001 / 9000 (optional GDPR requirements).
•Good knowledge of Data Centre technologies (on premise vs cloud).
•Customer focus and communication skills.
•Good project management and coordination skills.
•Strong analytical skills.
•Experience in coordinating virtual teams
•You have minimum 5 years of experience in IT internal/ external audit (e.g. ICOFR/SOX audits)
•Good to have: CIA/ CISA/ CRISC/COMPTIA or similar.
•Fluent in English
Sounds like the perfect job? We’ve got even more to offer:
- Hybrid way of working: 2 days per week/ 8 per month
- Medical and dental services
- Life and hospitalization insurance
- Dedicated employee phone subscription
- Take control of your benefits and choose any of the below options: MEAL TICKETS/ PRIVATE PENSION/ VACATION VOUCHERS/ CULTURAL VOUCHERS within the budget.
- Special discounts for gyms and retailers
- Annual Company Bonus
- Ongoing Education – we continuously invest in you to ensure you have everything needed to excel on the job and enhance your skills
- You get to work with tried and trusted web-technology
- We let you write your own story by planning vacations: go for a trip, experience new things, have fun and enjoy your 23 days off.
- Special Paternal Program - 4 months of paid paternity leave
We recognize and celebrate the importance of diversity and inclusivity in our workplace so that we are as diverse as the customers and communities we serve. We do not tolerate any form of discrimination especially related to but not limited to race, color, age, veteran status, gender identification, sexual orientation, pregnancy, ethnicity, disability, religion, political affiliation, trade union membership, nationality, indigenous status, medical condition, HIV status, social origin, cultural background, social or marital status.
Worried that you don’t meet all the desired criteria exactly? We are passionate about Inclusion for All and creating a workplace where everyone can thrive, whatever their personal or professional background. So, if you’re excited about this role but your experience doesn’t align exactly with every part of the job advert, we encourage you to apply as you may be just the right candidate for this role or another role, and our recruitment team can help see how your skills fit in.
#_VOIS