Information Security Auditor

Descrição do trabalho

We're fast learners, hard workers, natural collaborators... and we Make Modern Happen!

Our ambition is to unlock the potential of our digital world so that organisations everywhere can innovate and thrive securely.

We aim to achieve this goal by bringing together the world’s most talented people and the most powerful technologies, combining them to address our customers' challenges and to build something stronger together.

If you share our vision, join us!

Right now, we are looking for an Information Security Auditor to integrate our internal team, based in Lisbon.

  • Your responsibilities include:
  • Support the Quality Department in preparing the Annual Internal Audit Plan, specifically for the Information Security domain (internal and supplier audits).
  • Participate in the preparation of individual audit programs, identifying practices and requirements that must be assessed.
  • Conduct information security audits to evaluate whether current practices and procedures comply with applicable standards and regulations, including ISO 27001, ISO 27701, ISO 22301, GDPR, DORA Regulation, NIS 2 Directive, among others.
  • Document critical control points, deviations, and non-conformities identified during audits.
  • Follow up on corrective and improvement action plans, ensuring timely and effective implementation.
  • Support the management team in preparing regular reports for senior leadership and relevant stakeholders on the status and outcomes of auditing activities.
  • You must have:
  • Bachelor’s degree in Audit, Management, Engineering, or a related field.
  • Minimum of 3 years of experience in auditing, preferably in IT or Information Security;
  • Strong knowledge of information security standards and frameworks, audit methodologies, and relevant regulations, such as ISO 27001, ISO 27002, ISO 27701, GDPR, DORA Regulation, and the NIS 2 Directive;
  • Information Security Auditor certifications (e.g., CISA, ISO 27001 Lead Auditor, or equivalent) are highly valued;
  • Solid understanding of cybersecurity principles;
  • Experience with security tools and technologies (e.g., SIEM) and risk management systems (e.g., GRC, TPRM);
  • Good command of the English language, both written and spoken;
  • Excellent communication, interpersonal, and analytical skills;
  • Ability to work independently and manage multiple tasks and priorities efficiently.
  • We offer:
  • Regular professional development;
  • Certification paths resources;
  • Regular teambuilding programs;
  • Friendly workplace.

Workplace: Lisbon (Hybrid)

Claranet: Make Modern Happen!