Aptean is seeking a highly motivated and experienced Lead Audit and Compliance Specialist to join our growing team. As a Subject Matter Expert (SME), you'll play a key role in maintaining our robust compliance posture with industry standards like SOC 2 and ISO 27001 , focusing specifically on cloud infrastructure from a Governance, Risk, and Compliance (GRC) perspective.
Principal Duties and Responsibilities
- Conduct internal audits of security controls and processes related to SOC 2 and ISO 27001 compliance.
- Assist with the development, implementation, and maintenance of security policies and procedures.
- Analyze and evaluate the effectiveness of existing security controls and identify areas for improvement.
- Participate in the design and execution of penetration testing and vulnerability assessments.
- Work collaboratively with various teams (Security, IT Operations, Cloud Engineering) to remediate identified security risks and control gaps.
- Maintain and update GRC documentation related to security controls and compliance requirements.
- Stay up-to-date on industry best practices and regulatory changes related to cloud security and compliance.
- Assist with the preparation and execution of SOC 2 and ISO 27001 audits.
- Support the development and implementation of a cloud security GRC program.
Qualifications
Education : Bachelor's degree (Required). Master's degree (Preferred).Work Experience : 4-6 years of experience in a similar role within a security-conscious organization.Certifications : CISA, CRISC, or other relevant security certifications are a plus.Knowledge, Skills and Abilities
Experience conducting internal audits of security controls and processes.Strong understanding of SOC 2 and ISO 27001 compliance requirements.Working knowledge of cloud security concepts and best practices (e.g., AWS Security, Azure Security, GCP Security).Proficiency in GRC frameworks and methodologies (e.g., COBIT, COSO).Excellent analytical and problem-solving skills.Strong communication and interpersonal skills , with the ability to collaborate effectively across different teams.Ability to prioritize tasks, manage multiple deadlines, and work independently.Experience with GRC tools (e.g., MetricStream, RSA Archer) is a plus.Strong understanding of internal security audit and policy review processes.Skills Required
Internal Audit, Iso 27001, Cloud Security, Interpersonal Skills