×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Cybersecurity Audit Associate II

Job in San Diego, San Diego County, California, 92101, USA
Listing for: Sempra
Full Time position
Listed on 2026-08-30
Job specializations:
  • IT/Tech
    Cybersecurity
Job Description & How to Apply Below

Sempra:
Where Opportunity Powers Impact

At Sempra, a better world begins with better energy—and with people who want to make a difference. That's why we're tackling the biggest challenges facing our industry while building a high-performance culture where you can do your best work. Together, our teams support nearly 40 million consumers across the U.S., strengthening the communities we serve and creating impact that extends far beyond the workplace.

Here, collaboration, inclusivity and shared purpose empowers you to grow your passion, build a rewarding career and contribute to something bigger—helping shape a better energy future for all.

Primary Purpose

The role conducts internal audits of IT systems with an emphasis on cybersecurity. The position executes testing primarily of cybersecurity controls in IT and operational technology audits, strengthening critical infrastructure cybersecurity. It applies experience in audit documentation and techniques and a passion for cybersecurity excellence to effectively obtain relevant evidence, perform testing, and communicate issues and improvement recommendations in reports. It recommends practical adjustments to test steps, communicate routine issues to stakeholders, and contribute to reporting, as well as executes a broad range of testing and analysis for information systems audits.

Duties

and Responsibilities
  • Performs control testing for application, technology, and operations processes and evaluates whether evidence meets defined criteria.
  • Analyzes privileged access, security configuration hardening, logging and other cybersecurity control artifacts to identify exceptions and potential impact.
  • Summarizes testing results and drafts preliminary observations that link criteria, condition, cause, and effect.
  • Coordinates with technology teams to obtain extracts or configuration exports required for sampling and analysis.
  • Participates in entrance and exit meetings, explaining straightforward procedures and conclusions.
  • Contributes to follow-up reviews by confirming remediation activities and gathering validation evidence.
  • Performs other duties as assigned.
Education
  • Typically requires a 4-year degree in a relevant field, or equivalent combination of relevant education and experience.
Experience
  • Typically requires 2 years of related experience.
  • Must reside in Southern California or be willing to relocate upon hire.
Skills and Abilities
  • Clear and Professional Verbal and Written Communication
    - Proficiency in clearly requesting specific evidence relevant for cybersecurity control testing both written and verbally, interpreting that evidence, and documenting and sharing the outcome of testing.
  • Teamwork and Client Service – Clear communication and positive attitude towards teamwork approach to auditing. Understanding and commitment to client service standards of providing value and performing efficient, relevant, timely, courteous audits with practical and reasonable recommendations for improvement aligned with prioritized threat mitigation guidance.
  • Continuous Learning – Engagement with continuous cybersecurity learning as it relates to protecting enterprise IT environments and OT, including pursuing cybersecurity and technology certification(s). Interest in learning about internal auditing profession and IIA Global Internal Audit Standards.
  • Risk Assessment Techniques
    - Expertise in identifying and assessing risks associated with information systems, and developing strategies to mitigate these risks.
  • Information Security Standards
    - Understanding of industry standards and frameworks such as ISO 27001, NIST, and COBIT for evaluating and improving information security practices.
  • Network Security Assessment
    - Ability to evaluate and assess network security controls, identifying vulnerabilities and recommending improvements to protect information assets.
  • Cybersecurity Fundamentals
    - Knowledge of cybersecurity principles and practices to assess the effectiveness of security measures and protect against digital threats.
  • System and Application Controls
    - Expertise in evaluating system and application controls to ensure accuracy, reliability, and security of data processing and information flows.
  • Report Writing and Documentation
    - Skill in preparing detailed reports and documentation of fraud investigations and prevention activities for stakeholders.
  • Continuous Monitoring Tools
    - Proficiency in implementing and utilizing continuous monitoring tools to track system performance and detect potential security breaches in real time.
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary