DNEG logo
DNEGPosted 2 weeks ago

Information Security Audit Lead

On-siteBengaluru, Karnataka, India

Part TimeSenior LevelLarge

Job Summary

Lead and personally execute DNEG Group's internal Information Security audit program, covering ISO 27001 and ISO 42001 certifications, physical site security audits, and technical assessments of business-critical systems, applications, and cloud environments. Conduct risk-based audits from scoping through fieldwork, testing security controls, and verifying remediation while leveraging AI, automation, and analytics to improve efficiency. Produce defensible audit reports, identify material control deficiencies, and collaborate with global stakeholders to mature the audit program's methodology and standards.

Required Qualifications

  • Approximately 5–10+ years of relevant professional experience across Information Security audit, technology audit, cybersecurity audit, security assurance, technical security assessment, or closely related disciplines
  • Demonstrable experience leading or materially contributing to an enterprise Information Security or technology internal audit program
  • Demonstrable ability to both lead an audit program and personally execute complex audits
  • Practical experience developing risk-based audit plans, audit programs, engagement scopes, testing procedures, sampling approaches, working papers, findings, and formal audit reports
  • Strong knowledge of internal audit principles, control design and operating-effectiveness testing, objective evidence, audit sampling, documentation, findings development, and follow-up verification
  • Demonstrable experience conducting ISO 27001 internal audits and strong working knowledge of applicable ISO 27001 requirements and controls
  • Knowledge or experience of ISO 42001, SOC 2, TPN, and other relevant security and assurance frameworks
  • Practical experience auditing against recognized Information Security standards, frameworks, or control environments
  • Experience conducting physical or site-based security audits within complex organizational environments
  • Strong technical knowledge across multiple Information Security domains, which may include: Identity and Access Management and privileged access
  • Strong technical knowledge across multiple Information Security domains, which may include: Network and infrastructure security
  • Strong technical knowledge across multiple Information Security domains, which may include: Cloud security
  • Strong technical knowledge across multiple Information Security domains, which may include: Application and product security
  • Strong technical knowledge across multiple Information Security domains, which may include: Vulnerability and exposure management
  • Strong technical knowledge across multiple Information Security domains, which may include: Security monitoring and logging
  • Strong technical knowledge across multiple Information Security domains, which may include: Security operations and incident-response controls
  • Strong technical knowledge across multiple Information Security domains, which may include: Endpoint and platform security
  • Strong technical knowledge across multiple Information Security domains, which may include: Data security and protection controls
  • Strong technical knowledge across multiple Information Security domains, which may include: Secure configuration and change management
  • Strong technical knowledge across multiple Information Security domains, which may include: Software development and supporting technology processes
  • Ability to understand complex technology environments, interrogate technical evidence, ask incisive questions, challenge control assertions constructively, and reach independent, well-supported conclusions
  • Demonstrable experience evaluating both the design and operating effectiveness of Information Security controls
  • Ability to identify material control deficiencies and clearly articulate the associated security exposure and business implications
  • Strong written communication skills and experience producing professional audit reports suitable for technical stakeholders, senior management, and executive leadership
  • Strong stakeholder-management skills and the confidence to constructively challenge control owners while maintaining effective professional relationships
  • Demonstrable ability to manage multiple audit engagements and deliver high-quality work against defined schedules
  • Experience working within complex, distributed, or global technology environments
  • Demonstrable practical experience using AI, automation, analytics, scripting, or technology-assisted audit techniques to improve audit efficiency, coverage, evidence analysis, testing, or reporting
  • A continuous-improvement mindset with the ability to challenge unnecessarily manual or time-consuming audit processes and develop more efficient approaches without compromising audit quality or professional standards
  • Demonstrable experience developing, leading, operating, and continuously improving a risk-based Information Security or technology internal audit program
  • Demonstrable experience personally planning, leading, and executing Information Security audits from initial scoping through fieldwork, reporting, and follow-up
  • Strong working knowledge of recognized audit methodologies and the principles of independence, objectivity, professional judgment, evidence-based assessment, sampling, control testing, audit documentation, and reporting
  • Demonstrable experience conducting internal audits supporting ISO 27001 and ISO 42001 certification requirements
  • Experience conducting physical or site security audits against established security standards, control frameworks, or certification requirements
  • Strong technical Information Security knowledge and experience conducting audits or control assessments of complex systems, applications, infrastructure, cloud environments, networks, identity and access environments, security technologies, or other business-critical technology
  • Ability to distinguish material security and control weaknesses from lower-value procedural or administrative observations and reach defensible, evidence-supported conclusions
  • Excellent analytical, investigative, interviewing, documentation, reporting, and stakeholder-management skills
  • Ability to communicate complex audit findings and technical control deficiencies clearly to both technical and non-technical stakeholders
  • Ability to operate independently while collaborating effectively with the Global CISO Office, technology teams, business stakeholders, Facilities, Shared Services, and other control owners
  • Demonstrable ability to manage multiple concurrent audits, priorities, dependencies, and reporting requirements across a global organization
  • Strong commitment to continuously improving audit quality, efficiency, consistency, and scalability
  • Demonstrable ability and willingness to leverage AI, automation, data analytics, and modern audit technologies to improve audit planning, evidence analysis, testing, documentation, reporting, and overall audit execution
  • Must be capable of developing and operating a mature, scalable internal security audit program
  • Must be capable of independently evaluating technical environments, examining objective evidence, testing security controls, identifying material control deficiencies, and reaching clear and well-supported audit conclusions
  • Must be able to effectively lead and coach others
  • Must be available for weekend shifts

Desired Qualifications

  • Experience auditing organizations operating across multiple countries, business units, or geographically distributed locations
  • Experience conducting audits within film, visual effects, media, entertainment, technology, or other environments handling highly confidential intellectual property and client information
  • Working knowledge of the Trusted Partner Network (TPN) or comparable content-security requirements
  • Experience working with unified or common control frameworks that map organizational controls across multiple standards, regulatory requirements, or customer assurance frameworks
  • Experience conducting audits of cloud-native or hybrid technology environments
  • Experience auditing business-critical applications, internally developed systems, SaaS platforms, production technology, or complex technology services
  • Experience using GRC, audit-management, data-analysis, automation, or evidence-management platforms to support audit execution

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce