Share profiles along with Job ID number
Certifications: At least one relevant certification (CISA, CISSP, CRISC, or ISO 27001 Lead Auditor) – Certificate copy is mandatory
Government/Regulated Industry Experience: Preferred background in auditing technology vendors serving courts
Review vendor contracts, SLAs, and cybersecurity obligations to confirm compliance with requirements.
Evaluate the design and implementation of vendor cybersecurity controls against contractual and industry standards.
Collect and analyze evidence (e.g., security policies, system configurations, logs, access records).
Conduct interviews with vendor personnel to assess governance and security practices.
Perform control testing and sampling to validate effectiveness of safeguards.
Identify gaps, deficiencies, or non-compliance in vendor controls and assess risks.
Prepare audit reports summarizing findings, risks, and recommended corrective actions.
Track remediation efforts and validate closure of audit findings.
Coordinate with internal stakeholders to ensure vendor risks are communicated and addressed.
| Years | Requirement | Description |
|---|---|---|
| 5 | Cybersecurity frameworks & compliance | Proven experience auditing against NIST, ISO 27001, PCI-DSS, or SOC 2; knowledge of data protection laws, regulatory compliance, and third-party risk management. |
| 5 | Technical IT auditing | Strong ability to evaluate controls such as network protection, IAM, endpoint security, and incident response across IT environments. |
| 5 | Communication & reporting | Skilled in drafting reports, presenting findings to executives/legal teams, and engaging vendors constructively. |
| 5 | Analytical & investigative thinking | Ability to identify security gaps, assess risks, and provide evidence-based recommendations. |
| 4 | Third-party/vendor risk auditing | Hands-on experience conducting cybersecurity audits of external vendors, including due diligence, compliance, and risk assessments. |
| 3 | Policy & documentation review | Skilled at reviewing/validating security documentation, procedures, and control implementations. |
| 3 (Preferred) | Cloud cybersecurity auditing | Experience auditing AWS, Azure, or GCP environments, including shared responsibility models. |
| 3 (Preferred) | Incident response & breach assessment | Familiarity with analyzing vendor IR plans, reviewing breaches, and assessing remediation practices. |
| 3 (Preferred) | Contract & SLA compliance | Ability to interpret and validate technical/legal obligations in vendor contracts. |
| 2 (Preferred) | Government/regulated industry experience | Background auditing vendors serving courts or similar regulated industries. |
| 2 (Preferred) | Executive presentation | Experience summarizing technical findings for non-technical stakeholders (C-suite, legal counsel). |
| 1 (Preferred) | Certifications | CISA, CISSP, CRISC, or ISO 27001 Lead Auditor. |
--
Thanks & Regards
Hangouts: sek...@tekwings.com / usekh...@gmail.com
Tekwings Requirements Email group : https://groups.google.com/d/forum/tekwings_requrements_group1
LinkedIn Group: https://www.linkedin.com/groups/10421204/
LinkedIn: https://www.linkedin.com/in/sekhar-u-27b11a166/