Jobs Companies Bridewell Data Centre Compliance Auditor

À propos de ce poste Data Centre Compliance Auditor chez Bridewell

Bridewell · Sur site · Florida City, Florida, United States

About Bridewell   

One of the most exciting prospects in the cyber security sector today, Bridewell is a leading cyber security services company specializing in protecting and transforming critical business functions for some of the world's most trusted organizations. We are the trusted partner for operators of essential services and provide end-to-end cyber security capabilities that help our clients overcome their security challenges, allowing them to operate safely and securely.  

Having expanded into North America in 2022, Bridewell is quickly increasing its presence across the United States, showing our commitment to becoming a major player in the US cyber security market. Our US operations are focused on delivering cyber security solutions in the critical infrastructure sector, providing critical support to organisations navigating security challenges.

Overview 

We are looking for a Data Center Compliance Auditor to support the delivery of Bridewell services to one of our most strategic clients. You will support our client's Security & Compliance team across critical business operations, compliance and data protection activities within its infrastructure data centers. 

The role will focus on ensuring that data center environments remain audit-ready, while supporting additional audit and compliance requirements as they arise. You will work closely with a broad range of cross-functional stakeholders, including facilities, engineering, physical security and infrastructure finance teams. 

Requirements

The Role - here's what you will do: 

As a Data Center Compliance Auditor, you will have a primary focus on regulatory and certification audit support across SOX, SOC 2, ISO 27001, PCI and additional data center audits as required. You will help ensure that the client's data center infrastructure is audit-ready and compliant with applicable standards, coordinating with internal teams and external auditors while driving continuous improvement across the control environment. 

You will play a critical role in maintaining certifications by planning and executing audit activities, owning evidence gathering, conducting site walkthroughs, performing readiness assessments and enabling data center teams to understand and meet their compliance obligations. 

Further Breakdown of key responsibilities 

Regulatory & Certification Audit Support 

  • Plan, coordinate and facilitate external audits, both remote and on-site, across the client's owned and leased data center portfolio. 
  • Support audits covering SOX, SOC 2, ISO 27001, PCI and other emerging audit requirements. 
  • Manage audit schedules, scope definition and logistics with external auditors. 
  • Act as a primary liaison between external auditors and internal cross-functional teams throughout audit engagements. 

Evidence Collection & Auditor Inquiry Response 

  • Own end-to-end evidence gathering across facilities, engineering, physical security and infrastructure finance teams to satisfy auditor requests for information (RFIs). 
  • Respond to auditor inquiries with accurate, timely and well-documented evidence. 
  • Maintain organized evidence repositories and ensure completeness of audit documentation. 
  • Interpret evidence requirements and guide control owners on the standard of evidence expected. 

Walkthrough Facilitation 

  • Attend and support on-site security walkthroughs with external auditors at data center facilities. 
  • Conduct virtual and on-site walkthroughs of data center security environments in support of SOC 2, ISO 27001 and SOX assessments. 
  • Prepare site teams for auditor walkthroughs through pre-audit briefings and rehearsals. 
  • Document walkthrough findings and coordinate any required follow-up actions. 

Audit Readiness & Control Testing 

  • Conduct control testing covering design effectiveness and advisory activities across physical and environmental security, logical access, change management and availability controls. 
  • Evaluate control design within a Three Lines of Defense (3LOD) framework and provide advisory input on control adequacy. 
  • Conduct mock audits and tabletop exercises to prepare sites for external assessments. 
  • Develop and deliver compliance training to data center teams on control requirements and audit expectations. 

Impact Assessments & Compliance Enablement 

  • Support compliance impact assessments for new processes, system changes and site launches. 
  • Advise cross-functional teams on the compliance implications of operational changes. 
  • Maintain documentation of control descriptions, policies and procedures relevant to audit scope.

Experience 

  • You will have strong, demonstrable experience in several of the following areas: 
  • 5+ years of experience in IT audit, compliance or information security, with demonstrable experience across SOC 2, ISO 27001, SOX and/or PCI. 
  • Proven experience managing compliance programmes within a Three Lines of Defense (3LOD) governance framework. 
  • Experience with the AICPA Trust Services Criteria and SOC 2 reporting framework, including Type I and Type II. 
  • Strong understanding of control design through to control testing, including evaluating both design and operating effectiveness. 
  • Demonstrable ability to interpret evidence and assess whether it satisfies control objectives and auditor expectations. 
  • Experience planning and executing compliance audits in data center or critical infrastructure environments. 
  • Familiarity with physical and environmental security controls, logical access controls and change management processes. 
  • Strong stakeholder management skills, with the ability to build relationships and influence cross-functional teams at all levels. 

Preferred Qualifications 

  • Professional certification such as CISA, ISO 27001 Lead Auditor, CISSP or CRISC. 

Eligibility: Due to requirements from clients this role will support, applicants must be authorized to work in the United States.  

Benefits

Why join us? 

Our vision is to create a safe, inclusive digital world where people and organization can thrive. Our values of Do the Right Thing, One Team and Above and Beyond emphasize the importance of the part we play in society, and our commitment to our people and clients. Our story to-date has been phenomenal, but success doesn't end here and as we continue to grow and scale, we want to keep the same culture, passion and commitment to high quality that has enabled us to get this far. Bridewell will provide a great career opportunity with continual development as well as the following: 

  • 15 Days Vacation - Plus buy and sell options 
  • Flexible Working (around core office hours) 
  • 401(k) 
  • Personal Day & Birthday Off - After 1 year of service 
  • Family Leave - After 1 year of service 
  • Life Assurance 
  • Private Healthcare 

 

Location: Bridewell operates a hybrid and flexible working policy; however, you will be required to travel to different data center sites for audit activities on occasion. Travel for this role is estimated at 25%. 

Bridewell values diversity in the workplace and is a fair and equal opportunity employer. We are committed to creating an equal and inclusive working environment, with the aim that our employees will be truly representative of all sections of society and each person feels respected and able to give their best. 

 

Prêt à postuler chez Bridewell ?
Postuler chez Bridewell

À propos de Bridewell

Bridewell is the trusted cyber security partner for organisations operating within Critical National Infrastructure (CNI), as well as companies who want the highest standard of cyber security. Our team are highly accredited by major industry bodies and have extensive experience of delivering cyber consulting and managed security services across highly regulated sectors. We work in continuous partnership with our clients to implement the right security solutions to defend and protect them against threats and attacks, allowing them to continue operating safely and securely.

On top of all of this, it's our people who truly make Bridewell who it is. We are always on the look out for talented individuals who are committed to doing the right thing, delivering exceptional work, and working as part of a rapidly growing organisation. What underpins this, is the fact our success as a team is built upon our values - Do The Right Thing, Above & Beyond and One Team. They guide every decision we make and ensure the best outcomes for everyone.

Voir tous les emplois chez Bridewell →

Emplois similaires

Inscrivez-vous pour des suggestions adaptées aux emplois que vous ouvrez et aux recherches que vous enregistrez.

Plus d’emplois chez Bridewell

Voir tous les emplois chez Bridewell →

Postuler maintenant
🤖

Doucement — un instant

JobsRadar a été conçu pour de vraies personnes qui traversent une période difficile dans leur recherche d’emploi — pas pour des requêtes automatisées. Vous cliquez beaucoup trop vite et vous êtes maintenant temporairement bloqué.

Revenez plus tard. Si vous cherchez réellement un emploi, nous sommes de votre côté — agissez simplement comme un être humain.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Prenez une longueur d’avance dans votre recherche d’emploi.

Rejoignez notre canal Telegram pour ce qui vous aide à décrocher le poste — références salariales, le pouls hebdomadaire du marché et les annonces de nouveautés. Pas de spam, que du signal.

Rejoindre le canal — c’est gratuit