About this role
ascio is hiring a Technology Auditor to support our technology, cybersecurity, information security and digital assurance work.
This role will conduct and support audits and assessments across technology environments, management systems and cybersecurity controls. The Technology Auditor will review documented requirements, assess implementation, gather objective evidence and prepare clear findings and reports.
Responsibilities
- Plan and conduct technology, cybersecurity and information security audits and assessments.
- Review policies, procedures, risk assessments, controls and supporting technical evidence.
- Conduct remote and onsite audit activities, including interviews, walkthroughs and evidence review.
- Assess the design and implementation of technical and organizational controls.
- Review areas such as identity and access management, cloud security, vulnerability management, backup and recovery, incident management, logging and monitoring.
- Evaluate management-system processes and supporting operational controls.
- Identify gaps and nonconformities and document findings supported by objective evidence.
- Prepare clear audit reports, working papers and assessment records.
- Present findings to technical teams, management and other stakeholders.
- Support follow-up and verification of corrective actions where required.
- Maintain appropriate professional development, confidentiality and impartiality requirements.
Required Skills and Experience
- Practical professional experience in information technology, cybersecurity, information security, technology assurance or a related field.
- Experience conducting audits, assessments, control reviews or assurance activities.
- Strong understanding of technology and cybersecurity controls.
- Experience reviewing technical evidence and determining whether controls have been implemented effectively.
- Knowledge of risk assessment, control assessment and audit principles.
- Experience with cloud services, identity and access management, security operations or other modern technology environments.
- Strong evidence gathering and documentation skills.
- Ability to communicate effectively with both technical and non-technical stakeholders.
- Clear, evidence-based report writing.
Standards and Framework Knowledge
Experience with one or more recognized standards or frameworks is required. Relevant experience may include:
- ISO/IEC 27001 and ISO/IEC 27002.
- ISO/IEC 42001.
- ISO 19011.
- NIST cybersecurity frameworks.
- CyberSecure Canada or comparable cybersecurity baseline controls.
- Other recognized technology, cybersecurity, privacy or management-system frameworks.
Qualifications
- Degree, diploma or equivalent professional education in information technology, cybersecurity, information systems, computer science or a related field, or equivalent professional experience.
- Relevant current auditing, cybersecurity, information security or technology certifications.
- Applicants must be able to provide certification status and expiry or renewal dates, where applicable.
Relevant certifications or training may include:
- ISO/IEC 27001 Lead Auditor or Auditor.
- ISO/IEC 42001 Lead Auditor or Auditor.
- CISA.
- CISSP.
- CISM.
- CCSP.
- CRISC.
- Other recognized technology, cybersecurity or audit certifications.
Preferred Experience
- Management-system certification audits.
- Information security or cybersecurity assessments.
- AI governance or Artificial Intelligence management systems.
- Cloud service environments.
- Microsoft 365, Google Workspace, Azure or AWS.
- Small and medium-sized business technology environments.
- Experience across multiple industries or regulated sectors.
- Experience supporting or working with accredited certification or assurance organizations.
- Cybersecurity baseline or maturity assessments.
Location and Work Arrangement
- Remote within Canada.
- Some assignments may require occasional onsite work or travel within Canada.
- Applicants must be based in Canada and legally entitled to work in Canada.
- A criminal record check may be required before access to sensitive systems, information or environments.
Compensation Details
$90.00/hour
Ready to apply?
Pay shown up front. Free for job seekers, always.