D

Information Security Audit Lead

DNEG · State of Mahārāshtra, India

8–16 yrs experiencePosted 1w ago

Job description

Information Security Audit Lead 1.1 Overview DNEG’s expanding global Information Security program requires an experienced Information Security Audit Lead to lead, operate, and continuously mature the Information Security internal audit program across DNEG Group. The Information Security Audit Lead forms part of the Security Audit & Assurance function within the Global CISO Office and is responsible for providing structured, objective, risk-based assurance over DNEG locations, business-critical systems and applications, and security control environments. The role will lead and personally execute DNEG’s internal Information Security audit program across three primary areas: - Internal audits required to support applicable ISO certification and assurance requirements. - Physical and site security audits against the DNEG Unified Security Control Framework, including applicable mappings to ISO, TPN, and other relevant security requirements. - Technical security audits of business-critical systems, applications, platforms, infrastructure, and supporting technology environments. This is both a program leadership and hands-on audit role. The successful candidate must be capable of developing and operating a mature, scalable internal security audit program while personally planning, leading, executing, documenting, and reporting complex audits. The role requires a combination of formal audit expertise and strong Information Security technical knowledge. The Information Security Audit Lead must be capable of independently evaluating technical environments, examining objective evidence, testing security controls, identifying material control deficiencies, and reaching clear and well-supported audit conclusions. The Information Security Audit Lead will work collaboratively across the Global CISO Office and with business, technology, engineering, facilities, and control owners while maintaining the independence and objectivity required of the Security Audit & Assurance function. 1.2 Mandatory Requirements and Expectations An experienced Information Security audit professional who works in a methodical, objective, technically rigorous, and efficient manner is required to lead the DNEG Group Information Security internal audit program. - Demonstrable experience developing, leading, operating, and continuously improving a risk-based Information Security or technology internal audit program. - Demonstrable experience personally planning, leading, and executing Information Security audits from initial scoping through fieldwork, reporting, and follow-up. - Strong working knowledge of recognized audit methodologies and the principles of independence, objectivity, professional judgment, evidence-based assessment, sampling, control testing, audit documentation, and reporting. - Demonstrable experience conducting internal audits supporting ISO 27001 and ISO 42001 certification requirements, including the ability to conduct complete internal audits in accordance with applicable internal audit requirements and established audit criteria. - Experience conducting physical or site security audits against established security standards, control frameworks, or certification requirements. - Strong technical Information Security knowledge and experience conducting audits or control assessments of complex systems, applications, infrastructure, cloud environments, networks, identity and access environments, security technologies, or other business-critical technology. - Ability to distinguish material security and control weaknesses from lower-value procedural or administrative observations and reach defensible, evidence-supported conclusions. - Excellent analytical, investigative, interviewing, documentation, reporting, and stakeholder-management skills. - Ability to communicate complex audit findings and technical control deficiencies clearly to both technical and non-technical stakeholders. - Ability to operate independently while collaborating effectively with the Global CISO Office, technology teams, business stakeholders, Facilities, Shared Services, and other control owners. - Demonstrable ability to manage multiple concurrent audits, priorities, dependencies, and reporting requirements across a global organization. - Strong commitment to continuously improving audit quality, efficiency, consistency, and scalability. - Demonstrable ability and willingness to leverage AI, automation, data analytics, and modern audit technologies to improve audit planning, evidence analysis, testing, documentation, reporting, and overall audit execution2. Duties and Operational Responsibilities - Lead, manage, and continuously mature the DNEG Group Information Security internal audit program, including the risk-based audit plan, methodology, schedule, standards, and reporting. - Personally lead and conduct Information Security audits across DNEG Group, applying consistent audit methodology from planning and scoping through testing, reporting, and follow-up. - Lead and conduct required ISO Information Security internal audits, including ISO 27001 and ISO 42001, supporting certification and assurance requirements. - Conduct physical and site security audits across DNEG Group locations against the DNEG Unified Security Control Framework, including applicable mappings to ISO, TPN, SOC, and other relevant security requirements. - Conduct risk-based technical security audits of business-critical systems, applications, platforms, infrastructure, cloud environments, and supporting technology services. - Evaluate the design, implementation, and operating effectiveness of security controls through appropriate evidence review, sampling, technical analysis, interviews, and control testing. - Apply sufficient technical depth to independently evaluate technical environments, challenge control assertions, identify material control weaknesses, and reach clear, evidence-supported audit conclusions. - Produce clear and defensible audit do