Cybersecurity Auditor - Lisbon/Porto

Descrição do trabalho

We are recruiting a Cybersecurity Auditor to join an international IT Risk Management, Cybersecurity & Digital Fraud team, operating in a highly regulated financial environment with strong exposure to international entities.

This role is ideal for experienced professionals with a background in cybersecurity audit, IT risk and compliance, looking to work in a structured, demanding environment with direct impact on information security and risk management.

About the role

As a Cybersecurity Auditor, you will be responsible for assessing the effectiveness of security controls and compliance with internal policies, standards and regulatory requirements, across both internal entities and third parties.

  • Key responsibilities
  • Conducting cybersecurity audits across internal entities and third parties (Third Party Audits);
  • Assessing security risks, vulnerabilities and control weaknesses within information systems;
  • Auditing security controls based on internal policies, frameworks and industry best practices;
  • Contributing to SOC, ITGC and IT Risk audits;
  • Preparing clear and structured audit reports, including findings and actionable recommendations;
  • Following up on remediation plans and closure of audit findings;
  • Working closely with technical, risk and business teams;
  • Participating in both remote and on-site audits, with occasional international travel.
  • Technical requirements
  • Higher education in Computer Science, Information Systems, Cybersecurity or a related field;
  • Minimum 5 years of experience in IT and/or Cybersecurity Audit, ideally within financial services or other regulated environments;
  • Experience in Cybersecurity Audit, IT Risk or Third Party Risk Management;
  • Strong knowledge of frameworks and standards such as:
  • ISO 27001 / 27005
  • NIST Cybersecurity Framework
  • COBIT
  • Experience with SOC (SOC 1 / SOC 2) and/or SOX audits is a strong plus;
  • Strong analytical and risk-oriented mindset;
  • Excellent written and verbal communication skills, including with non-technical stakeholders.
  • Languages
  • Fluent English
  • Fluent French
  • Soft Skills
  • Ability to synthesize and structure information clearly;
  • Critical thinking and autonomy;
  • Comfort working with defined governance and methodologies;
  • Ability to operate in international and multicultural environments;
  • Availability for occasional travel.