Overview
Skills
Job Details
It is an internal control testing team (NOT AUDIT OR RISK). - that means they follow specific steps in the GRC Tool, document clearly and then someone reviews. Some of these controls could include: change records that are tested and approved prior to deployment OR enduring all production services are backed up (these are two examples of what they may be testing). Tests can be done weekly, quarterly or annually. they test over 1000 test annually.
The role is 100% control testing (0% risk). She said most candidates will have titles like "Internal Technology Auditor" "control Tester" etc..They may test controls like: Access Management, change Management", Security baselines, etc.
Tools they should be familiar with:
GitHub
AWS
Service Now
Sailpoint
All helpful along with others in the job listed.
* Must have at least 2 years of experience as technology auditor.
They have to be very detailed in documentation as well