Information Security Auditor (CISA / CISSP / CIA)

$$$$

V-Spot Ltd is a cybersecurity firm working with regulated organisations across Switzerland and Europe. We are looking for an experienced Information Security Auditor to lead security audits and assessments for clients handling highly sensitive personal data.
 

What you'll do

  • Plan and run information security and data protection audits, including on-site audits at client organisations (interviews, document reviews, sampling, process checks, physical security and access control inspections)
  • Assess the effectiveness of security controls: access and role management, incident management, change and patch management, backup and recovery, monitoring and endpoint protection
  • Scope, coordinate and review penetration tests of web applications, APIs and infrastructure, and turn technical findings into audit conclusions
  • Carry out risk analyses and protection-needs assessments, and document residual risks
  • Review and help develop ISMS and data protection concepts, security policies, minimum standards and business continuity / disaster recovery plans (BCM)
  • Review annual security reports and follow up on remediation of audit and pentest findings, including re-audits
  • Support data protection impact assessments (DPIA) and incident response, including lessons learned
  • Advise clients on information security and data protection, and present findings clearly to management and technical teams
  • Write audit reports and documentation in English
     

Must have

  • A valid CISA, CISSP or CIA certification (mandatory)
  • At least 5 years of experience in IT/information security auditing, IT risk management or security assessment
  • Proven track record of planning and executing security audits in large, complex organisations
  • Solid knowledge of ISO/IEC 27001/27002, NIST CSF or comparable frameworks, and of data protection requirements (Swiss FADP / GDPR)
  • Good understanding of penetration testing methodologies (e.g. OWASP) and of common vulnerabilities in web applications and APIs
  • Professional working proficiency in English, spoken and written; German is a plus
  • Ability to travel to Switzerland on request for on-site audits and client meetings (a few times per year)

     

Nice to have

  • Knowledge of structured project methods (e.g. PRINCE2, SAFe)
  • Additional certifications such as ISO 27001 Lead Auditor, CISM or CRISC
  • French language skills
     

What we offer

  • Part-time employment (approx. 20โ€“30%), long-term from January 2027, with potential to grow
  • Varied audit and advisory work for highly renowned organisations
    Fully remote work, with occasional on-site assignments in Switzerland
  • A small, senior and technically strong team
     

Required skills

Information Security (InfoSec), CISSP, CISA

Required languages

English C1 - Advanced
German B2 - Upper Intermediate
Published 8 October
22 views
ยท
3 applications
To apply for this and other jobs on Djinni login or signup.
Loading...