Information Technology Auditor
Translated automatically from the original posting. Read the original in Georgian →
Public Service Institution "Pension Fund of Georgia" is announcing a competition for a vacant position of Information Technology (IT) Auditor in the Internal Audit Service.
Work location: Tbilisi, Georgia Work schedule: To be agreed upon Qualification requirements:
- Higher education, preferably in Information Technology or Engineering;
- At least 3 years of work experience in IT audit, cybersecurity, information security, or technological risk management;
- High-level English language skills;
- Knowledge of ISACA standards;
- Experience working with COBIT, ISO/IEC 27001/27002, NIST, or similar frameworks;
- CISA, CISM, CISSP, or CIA certification is desirable, or being in the certification process.
- The candidate must have at least 5 years of experience working with logging systems (preferably Arcsight);
- The candidate must have at least 5 years of experience working with corporate enterprise networks;
- Experience in designing controls and testing operational effectiveness;
- Work experience in financial institutions or the public sector will be considered a priority;
Other requirements:
- Communication skills, punctuality, and organization;
- Quick and effective response to assigned tasks;
- Excellent analytical skills;
- Motivation and high sense of responsibility;
Job functions and responsibilities:
- Audit of IT and information asset identification and classification processes;
- Audit of IT and cybersecurity risk assessment methodologies (risk assessment, risk appetite, risk register);
- Audit of third-party and vendor cybersecurity risk management controls;
- Audit of access management and identity controls (IAM, PAM, MFA, SoD);
- Audit of data protection controls (Data Classification, DLP, Encryption);
- Audit of configuration and hardening standards (GPO, baseline configurations);
- Assessment of Security Awareness and training effectiveness;
- Audit of change management and SDLC process security controls;
- Evaluation of network and perimeter protection controls (WAF, NGFW, segmentation);
- Audit of security monitoring architecture (SIEM, log management, XDR/EDR);
- Evaluation of log completeness, quality, and storage controls;
- Audit of notable incident coverage, alert system tuning, and refinement;
- Assessment of security incident timely detection effectiveness;
- Evaluation of SOC process compliance and KPI/KRI;
- Audit of Business Continuity (BCP) and Disaster Recovery (DR) plans;
- Audit of recovery time (RTO/RPO) and business requirement compliance;
- Assessment of information security governance (policies, procedures, roles, responsibilities) compliance;
- Preparation of clear, risk-based recommendations.
Interested candidates should send their resume to within 12 days of the publication of this announcement. The subject field should indicate the corresponding position title; otherwise, your resume will not be considered. Only shortlisted candidates will be contacted.
We publish a copy of this advert so people looking for work in Georgia can find it, with a link back to your original. If it is yours, you can take over managing it, or ask us to take it down.
A claimed listing becomes Direct: it shows above collected listings for a week after it is posted or bumped, you can edit, bump and close it, and it joins Google job search.