Senior Cyber Security Internal Auditor

Sita
Madrid, Spain
12 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Cloud Computing Security Control Objectives for Information and Related Technology (COBIT) Cyber Security Identity and Access Management Log Analysis Systems Development Life Cycle Privacy Controls IT General Controls (ITGC) Software Security Data Analytics Workday Vulnerability Analysis

Job description

Overview WELCOME TO SITA At SITA, we keep airports moving, airlines flying smoothly, and borders open.Our technology and communication innovations power the success of the global air travel industry.You’ll find us in 95% of international airports, working closely with over 2,500 transportation and government clients.Each partnership brings unique challenges, and we thrive on delivering fresh solutions and cutting-edge tech to keep operations running like clockwork.We don’t just move the world forward-we’re proud to be recognized as aGreat Place to Work ® by 79% of our employees and certified in most of our growing locations.Here, we feel empowered, supported, and inspired to grow.Are you ready to love your job?The adventure begins right here, with you, at SITA.PURPOSE The purpose of this role is to perform Cyber Security, IT and Privacy audits of SITA corporate procedures processes and sites throughout the world and to prepare factual audit reports and communications informing management and stakeholders of risk areas and issues.Key Responsibilities Perform independent cyber security, IT and Privacy audits in accordance with the audit schedule approved by the Audit and Risk Management Committee and hence prepare for independent cyber security, IT and Privacy audits and field work with the purpose of evaluating (but not limited to):Cyber Security, IT and Privacy Policies, Standards and ProceduresCyber, IT and Privacy governance and operating modelCyber Security, IT and Privacy risk managementIdentity & access management (IAM)Network and infrastructure securityCloud securityApplication security and SDLCData protection and privacy controlsIncident response and cyber resilienceIn order to perform the above, the candidate must demonstrate ability to:Perform end-to-end audit activities: planning, fieldwork, testing, documentation, and reportingApply data-driven and technical audit techniques (configuration reviews, log analysis, vulnerability assessment review, etc.)Assess the design, implementation and and operating effectiveness of cybersecurity, IT anmd Privacy controlsEvaluate alignment with recognized frameworks and standards (e.g. NIST CSF, ISO **, CIS, COBIT, NIS2, GDPR)Identify control gaps, weaknesses, and root causesAssess management’s remediation plans for adequacy, sustainability, and timelinessAssess compliance with Internal policies, Regulatory and contractual cyber requirementsProvide assurance over third-party and supply-chain cyber, IT and Privacy risk managementPresent audit results to senior management and EMTTrack and validate remediation actions, including follow-up testing where requiredQualifications EXPERIENCE3 years of experience in external/internal cyber, IT, and privacy auditingExperience performing end-to-end audits independentlyStrong understanding of cybersecurity and IT controlsExperience with technical audit techniques (not only policy-level reviews)Familiarity with frameworks such as ISO **, NIST, CIS, COBIT, GDPR, NIS2Background in an audit environment (e.g. audit firm or internal audit team)Ability to communicate effectively with senior stakeholders, including leadership levelNice To HaveISO *** Lead Auditor or similar certification (e.g. CISM)Exposure to privacy topics alongside cybersecurityWhat We Offer We’re all about diversity.We operate in 200 countries and speak 60 different languages and cultures.We’re really proud of our inclusive environment.Our offices are comfortable and fun places to work, and we make sure you get to work from home too.Find out what it’s like to join our team and take a step closer to your best life ever.Flex Week:Work from home up to 2 days/week (depending on your team’s needs)Flex Day:Make your workday suit your life and plans.Flex-Location:Take up to 30 days a year to work from any location in the world.Employee Wellbeing:We have got you covered with our Employee Assistance Program (EAP), for you and your dependents 24/7, 365 days/year.We also offer Champion Health - a personalized platform that supports a range of wellbeing needs.Professional Development:At SITA, we believe growth fuels innovation.Our learning ecosystem offers access to world-class platforms and programs designed to help you thrive.FromLinkedIn Learning, Microsoft’s Enterprise Skills Initiative,andAirport Council International-available to all employees-to specialized solutions likePluralsightfor technology upskilling,Harvard Business Publishingfor people leadership,Stanfordfor strategic development and many others, we align learning opportunities with your Development Plan and our business priorities.Your development journey is supported every step of the way.Competitive Benefits:Competitive benefits that make sense with both your local market and employment status.SITA is an Equal Opportunity Employer.We value a diverse workforce.In support of our Employment Equity Program, we encourage women, aboriginal people, members of visible minorities, and/or persons with disabilities to apply and self-identify in the application process.#J-***-Ljbffr

Requirements

3 years of experience in external/internal cyber, IT, and privacy auditing Experience performing end-to-end audits independently Strong understanding of cybersecurity and IT controls Experience with technical audit techniques (not only policy-level reviews) Familiarity with frameworks such as ISO **, NIST, CIS, COBIT, GDPR, NIS2 Background in an audit environment (e.g. audit firm or internal audit team) Ability to communicate effectively with senior stakeholders, including leadership level Nice To Have ISO ** Lead Auditor or similar certification (e.g. CISM) Exposure to privacy topics alongside cybersecurity

About the company

We operate in 200 countries and speak 60 different languages and cultures. We’re really proud of our inclusive environment. Our offices are comfortable and fun places to work, and we make sure you get to work from home too. Find out what it’s like to join our team and take a step closer to your best life ever. Flex Week: Work from home up to 2 days/week (depending on your team’s needs) Flex Day: Make your workday suit your life and plans. Flex-Location: Take up to 30 days a year to work from any location in the world. Employee Wellbeing: We have got you covered with our Employee Assistance Program (EAP), for you and your dependents 24/7, 365 days/year. We also offer Champion Health - a personalized platform that supports a range of wellbeing needs. Professional Development: At SITA, we believe growth fuels innovation. Our learning ecosystem offers access to world-class platforms and programs designed to help you thrive. From LinkedIn Learning, Microsoft’s Enterprise Skills Initiative, and Airport Council International -available to all employees-to specialized solutions like Pluralsight for technology upskilling, Harvard Business Publishing for people leadership, Stanford for strategic development and many others, we align learning opportunities with your Development Plan and our business priorities. Your development journey is supported every step of the way. Competitive Benefits: Competitive benefits that make sense with both your local market and employment status. SITA is an Equal Opportunity Employer. We value a diverse workforce. In support of our Employment Equity Program, we encourage women, aboriginal people, members of visible minorities, and/or persons with disabilities to apply and self-identify in the application process. #J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:13 min

Audience Q&A on maturity assessments and external consultants

Mathias Tausig · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

11:18 min

Addressing audience questions on security and microservice architectures

Reinhard Kugler · LIVE

6:22 min

Eliminating HR bureaucracy and trusting employees

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:48 min

Leveraging multi-agent systems for autonomous software testing

Ondřej Gróf Ondřej Gróf · World Congress 2026 Europe

Videos

See all

Related articles

See all