> Markdown version of [/jobs/ext/3103695-senior-auditor-it-compliance](https://www.wearedevelopers.com/jobs/ext/3103695-senior-auditor-it-compliance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Auditor IT Compliance - **Company:** Simon Group - **Location:** Berlin, Germany (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Data Analysis, Cyber Security, Information Security Management, Tisax, Information Technology - **Published:** September 27, 2026 - **Apply:** https://www.adzuna.de/details/5899922309 ## About the Role * Education: University degree or formal education in informatics, business informatics, IT security, or a related field. Professional background: at least four to five years of experience in a similar role within an international organization and global corporate environment. * Audit Qualifications: Relevant education, training, or professional development as an Auditor or Senior Auditor in Information Security, IT Security, or Cyber Security. * Audit Standards Expertise: Practical experience auditing against ISO 2700x standards, BSI Grundschutz, SOC 2 Type II, TISAX or similar Information Security and Information Security Management frameworks. * Audit Certifications: Certifications related to Information Security Auditing are considered a plus. * Audit Planning & Execution: Experience in planning audits, defining audit scopes, selecting appropriate audit methodologies, leading auditees through the audit process, and estimating the effort required for audit preparation, execution, documentation, and reporting. * Risk Management: Experience in risk management and familiarity with risk management terminology and methodologies. * Communication & Stakeholder Management: Very good communication skills and the ability to guide stakeholders through the audit process in a clear and timely manner. * Languages: Advanced proficiency in German and English (B1 level or higher). * Organization & Self-Management: Strong initiative, self-starter mentality, analytical thinking, and solid organizational, time management, and result-driven working skills to operate effectively in a global environment. * Professional Ethics: High ethical standards in auditing, including maintaining confidentiality, avoiding conflicts of interest, and conducting audits and reporting objectively and independently. ## Description * Audit Planning & Documentation: Plan audits by analyzing Information Security standards, including ISO 27001:2022 and TISAX, defining audit scope, maintaining relevant audit catalogues, and drafting audit plans within the assigned area of responsibility. * IT, Security & Service Provider Audits: Perform audits in accordance with approved audit plans covering internal Simon-Kucher processes and assets, external service providers, IT systems, infrastructure, processes, and Information Security Management activities. * Physical Security Audits: Conduct on-site or virtual audits of physical security controls, including occasional travel to Simon-Kucher offices worldwide. * Audit Findings & Risk Management: Document and classify audit findings, enabling process owners, asset owners, and decision-makers to develop mitigation measures and implementation plans, while contributing to Simon-Kucher's risk register and collaborating with IT Compliance colleagues and risk owners. * Reporting & Stakeholder Collaboration: Report to the Director of the IT Compliance Group, contribute to audit reporting for the CTO, and collaborate with IT Compliance colleagues and relevant stakeholders throughout the audit process, including involvement in certification audits. ## Related Videos - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [Data Analyst Salary Germany](https://www.wearedevelopers.com/magazine/277-data-analyst-salary-germany) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Finding IT & Technology English-speaking Jobs in Germany ](https://www.wearedevelopers.com/magazine/446-finding-it-technology-english-speaking-jobs-in-germany) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)