About the Role The Audit Manager, Information Security will be a key member of the Information Security and Risk Management team, leading internal and external audits and supporting Information Security Governance, Risk & Compliance initiatives.
This role combines IT Audit, Information Security, Risk and Compliance, with a focus on evaluating security controls, identifying risks, driving remediation, and supporting audit and compliance programs across the organization.
Key Responsibilities
- Lead and manage internal and external IT and Information Security audits.
- Develop audit plans, coordinate engagements, and oversee audit execution.
- Perform control testing and evaluate the design and operating effectiveness of security controls.
- Identify risks and control gaps and develop practical remediation plans.
- Support compliance with ISO 27001, SOC 2, NIST 800-53, NIST CSF, GDPR and other applicable standards.
- Use GRC tools to manage assessments, risks, controls, evidence and remediation.
- Partner with Control Owners and cross-functional stakeholders to strengthen security and compliance programs.
- Support risk assessments, policy reviews and audit readiness.
- Prepare clear risk, compliance and audit reports for leadership.
What You Bring
- Experience in IT Audit, Information Security, Risk, Compliance or GRC.
- Experience with IT audits, control testing and security controls.
- Knowledge of frameworks such as NIST, ISO 27001, SOC 2, COSO or HITRUST.
- Experience with GRC tools and regulatory requirements.
- Strong communication, organization and stakeholder management skills.
- Bachelor’s degree in Computer Science, Engineering or related field, or equivalent experience.
- B2+ English proficiency, written and verbal.
- CISA, CRISC, CISM or CISSP certifications are preferred.
📌 Information Security Audit & GRC Manager (Bogotá)
🏢 Auxis
📍 Bogotá