> Markdown version of [/jobs/ext/2040007-cyber-security-internal-auditor](https://www.wearedevelopers.com/jobs/ext/2040007-cyber-security-internal-auditor). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Internal Auditor - **Company:** Sita Bekijk Alle Vacatures - **Location:** Rotterdam, Netherlands (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Identity and Access Management, Log Analysis, Systems Development Life Cycle, Privacy Controls, IT General Controls (ITGC), Software Security, Data Analytics, Vulnerability Analysis - **Published:** August 13, 2026 - **Apply:** https://www.careerjet.nl/job/nlc4f9a8ba96ffb00408095c2467aab4d0/eaa ## About the Role * 3 years of experience in external/internal cyber, IT, and privacy auditing * Experience performing end-to-end audits independently * Strong understanding of cybersecurity and IT controls * Experience with technical audit techniques (not only policy-level reviews) * Familiarity with frameworks such as ISO 27001, NIST, CIS, COBIT, GDPR, NIS2 * Background in an audit environment (e.g. audit firm or internal audit team) * Ability to communicate effectively with senior stakeholders, including leadership level Nice to have: * ISO 27001 Lead Auditor or similar certification (e.g. CISM) * Exposure to privacy topics alongside cybersecurity ## Description At SITA, we keep airports moving, airlines flying smoothly, and borders open. Our technology and communication innovations power the success of the global air travel industry. You'll find us in 95% of international airports, working closely with over 2,500 transportation and government clients. Each partnership brings unique challenges, and we thrive on delivering fresh solutions and cutting-edge tech to keep operations running like clockwork. We don't just move the world forward-we're proud to be recognized as a Great Place to Work® by 79% of our employees and certified in most of our growing locations. Here, we feel empowered, supported, and inspired to grow. Are you ready to love your job? The adventure begins right here, with you, at SITA. PURPOSE The purpose of this role is to perform Cyber Security, IT and Privacy audits of SITA corporate procedures processes and sites throughout the world and to prepare factual audit reports and communications informing management and stakeholders of risk areas and issues., Perform independent cyber security, IT and Privacy audits in accordance with the audit schedule approved by the Audit and Risk Management Committee and hence prepare for independent cyber security, IT and Privacy audits and field work with the purpose of evaluating (but not limited to): * Cyber Security, IT and Privacy Policies, Standards and Procedures * Cyber, IT and Privacy governance and operating model * Cyber Security, IT and Privacy risk management * Identity & access management (IAM) * Network and infrastructure security * Cloud security * Application security and SDLC * Data protection and privacy controls * Incident response and cyber resilience In order to perform the above, the candidate must demonstrate ability to: * Perform end-to-end audit activities: planning, fieldwork, testing, documentation, and reporting * Apply data-driven and technical audit techniques (configuration reviews, log analysis, vulnerability assessment review, etc.) * Assess the design, implementation and and operating effectiveness of cybersecurity, IT anmd Privacy controls * Evaluate alignment with recognized frameworks and standards (e.g. NIST CSF, ISO 27001, CIS, COBIT, NIS2, GDPR) * Identify control gaps, weaknesses, and root causes * Assess management's remediation plans for adequacy, sustainability, and timeliness * Assess compliance with Internal policies, Regulatory and contractual cyber requirements * Provide assurance over third-party and supply-chain cyber, IT and Privacy risk management * Present audit results to senior management and EMT * Track and validate remediation actions, including follow-up testing where required ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [PySpark - Combining Machine Learning & Big Data](https://www.wearedevelopers.com/videos/44-pyspark-combining-machine-learning-big-data) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Best Companies in the Netherlands: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/193-best-companies-in-the-netherlands-top-25-companies-in-2023) - [How to Find Tech Jobs in Amsterdam](https://www.wearedevelopers.com/magazine/279-how-to-find-tech-jobs-in-amsterdam) - [Software Developer Salary in The Netherlands [2023]](https://www.wearedevelopers.com/magazine/217-software-developer-salary-in-the-netherlands-2023) - [How to land a developer job in Amsterdam](https://www.wearedevelopers.com/magazine/36-how-to-land-a-developer-job-in-amsterdam) - [The Netherlands – Europe’s powerhouse for software development?](https://www.wearedevelopers.com/magazine/31-the-netherlands-europe-s-powerhouse-for-software-development) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)