What are the responsibilities and job description for the Security Audit Analyst position at IBM?
At IBM, work is more than a job - it's a calling: To build. To design. To code. To consult. To think along with clients and sell. To make markets. To invent. To collaborate. Not just to do something better, but to attempt things you've never thought possible. Are you ready to lead in this new era of technology and solve some of the world's most challenging problems? If so, lets talk.
Your Role and Responsibilities
Who You Are:
Security Audit Analyst provides guidance to key company stakeholders to mitigate information technology (IT) risk and enhance IT internal controls.
Leverage data visualization tools in the planning, execution and reporting phases to drive efficiencies and effectiveness.
Participate in planning activities to develop audit scopes.
Design audit programs and test plans to determine the adequacy and effectiveness of internal controls and compliance.
Interview select personnel and documenting and assessing business processes and information systems to determine the adequacy of the control environment.
Test information technology application and system processes and controls.
Understand financial, operational and compliance risks which impact information systems.
Identify value-added recommendations and aligning with management on corrective actions to address identified risks.
Present audit results to management.
Prepare audit reports detailing recommendations to strengthen and improve the control environment.
Required Technical and Professional Expertise
3 years of experience with security assessment of the SLAC environment including:
- Controls (NIST, etc.) NIST 800-53
- Self-assessment
- Cloud assessments
- System security plans
- Expert control
- Define roles and responsibilities of different roles
- Splunk or SIEM alternative
- Threat hunting (Splunk or SIEM alternative)
- Advisory to SLAC stakeholders
- Advisory on writing dashboards capturing SLAC-mandated security metrics
3 years of experience issuing written reports outlining findings and recommendations based on audit results.
3 years of experience assisting with the development and implementation of data analytics and ad-hoc data analysis to improve audit efficiency.
3 years of experience providing guidance and direction regarding security control elements in policies throughout the organization.
3 years of experience documenting relevant business processes and their implications on information security.
Preferred Technical and Professional Expertise
CISA, CISSP, CRISC, CISM