IT Operations Senior Specialist, Security - Audit
Listed on 2025-12-03
-
IT/Tech
Cybersecurity, IT Consultant
Overview and Summary
We are Automotive Business Scientists. We empower our clients to turn overwhelming industry data into discovery, action and measured success. We are unique market leaders because we find and examine possibilities through the clarity of a scientific lens. To solve the toughest client challenges, we need curious, creative and dedicated people to join our team.
We search out individuals who align with our core values and who adhere to the highest standards of integrity and ethics in everything they do. Our company is filled with the brightest minds and the biggest hearts at every level. We recognize that personal success takes on many different forms of the course of our lives – both professional and personally – so we provide a myriad of benefits and programs focused on Wellbeing, Growth, Community and Recognition.
One size does not fit all, so we encourage every Urban Scientist to discover their own formula for success. If this sounds like the kind of company you would like to work with, Apply Now!
POSITION OVERVIEW
The IT Operations Senior Specialist, Security works as an integral part of the Urban Science Security Team to protect the confidentiality, integrity and availability of company and client information assets. This individual will support ISO certified information, privacy, and environmental management systems – based on ISO 27001, 27701, and 14001 Standards. This includes management of the assessable asset catalog, risk/vulnerability assessment of information assets, risk management to full remediation and closure, and provision of ISMS/risk metrics and reporting.
This role has current Hybrid Workplace flexibility local to our Detroit, MI office location. Candidate must be available and willing to work in-person three times per week, and ad hoc as needed.
URBAN SCIENCE DOES NOT AND WILL NOT PROVIDE IMMIGRATION RELATED SPONSORSHIP FOR THIS ROLE, NOW OR IN THE FUTURE.
Essential Duties and Responsibilities- Support and operations of a global ISO 27001, 27701, and 14001 information security, privacy, and environmental management system.
- Author, update, and manage ISMS documentation set including process descriptions, flow diagrams, checklists, etc.
- Manage annual internal and external audit process including interaction with audit firms, audit/auditor scheduling, participant scheduling and related tasks.
- Manage Security Intranet site including standard SharePoint, Wiki, and Power BI sites.
- Work with virtual security teams on global security implementation, remediation, and improvement projects.
- Manage security corrective action and continuous improvement process including processing nonconformity reports, creation of corrective actions, and managing corrective actions to closure
- Occasionally work with clients and account teams to provide responses to security assessments and questionnaires.
- Support regular risk assessment, controls reviews, gap assessments, and access reviews.
- Provide security/privacy expertise and support to Urban Science business and technical teams.
- Participate in relevant security training events and activities.
- Achieve and maintain relevant technical and operational security skills and certifications.
- Must have a baccalaureate degree in information technology, or related field, from an accredited U.S. college or university, or equivalent foreign institution.
- Must have a minimum of five years relevant work experience.
- Strong understanding of various risk management frameworks, such as ISO 27000, SOC2, ITIL, etc.
- Understanding of global compliance law/regulation (e.g. GDPR, CCPA/CPRA, Privacy Guard, PIPEDA, etc.)
- Knowledge of risk management system like Zen GRC.
- One or more of the following certifications is desirable (or relevant):
- ITIL – Information Technology Infrastructure Library
- ISSAP – Information Systems Security Architecture Professional
- CISA – Certified Information Systems Auditor
- CISM – Certified Information Security Manager
- CRISC – Certified Risk and Information Systems Control
- Cybersecurity Audit Certificate
- ISO Lead Auditor Certification
The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
This description is intended to describe the type and level of work being performed by a person assigned to this position. It is NOT an exhaustive list of all duties and responsibilities required by a person so classified. The job may require additional hours beyond a traditional 40-hour workweek.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).