Our firm is seeking a Cybersecurity Auditor to join on an immediate, part-time basis.
Job ObjectiveThe objective of this role is to independently conduct a comprehensive audit of the client’s compliance with the Central Bank of Kuwait’s Cyber and Operational Resilience Framework (CORF). The role will involve identifying compliance gaps, reviewing supporting evidence, documenting audit findings, and providing practical recommendations to strengthen the client’s control environment and support ongoing compliance with CORF requirements.
Job Responsibilities
- Review the client’s Statement of Applicability and Inherent Risk Profile against applicable CORF requirements.
- Review the client’s governance and control framework across the Cyber Resilience, Operational Resilience, and Third-Party Risk Management baselines.
- Perform testing and validation of the client’s implemented cybersecurity and operational resilience controls.
- Assess identified risks and evaluate the client’s maturity against applicable CORF requirements.
- Document audit procedures, evidence, testing results, and conclusions through complete working papers.
- Support the preparation of the independent audit assessment report and related engagement deliverables.
- Coordinate with relevant client stakeholders to obtain documentation, evidence, clarifications, and walkthroughs.
- Perform the assigned engagement activities onsite at the client’s premises.
- Maintain the confidentiality of all client data, information, documents, and audit working papers.
- Educational
Qualifications
- Bachelor’s or master’s degree in Cybersecurity, Information Security, Information Technology, Computer Science, Risk Management, Audit, or a related field.
- Professional Certificates
- Professional certifications preferred (e.g., CISA, CISSP, CISM, CRISC, ISO/IEC 27001 Lead Auditor, ISO 22301 Lead Auditor, CIA, COBIT, or ITIL certifications).
- Experience (Areas of Expertise)
- Minimum 5–10 years of experience in cybersecurity audit, information technology audit, technology risk, operational resilience, or regulatory compliance.
- Demonstrated experience conducting cybersecurity and operational resilience audits within banks or regulated financial institutions.
- Strong experience reviewing cybersecurity controls against regulatory frameworks and baseline requirements.
- Prior involvement in Central Bank of Kuwait regulatory audits or compliance assessments.
- Experience working within banks or financial institutions.
- Experience interacting with senior management, Boards, Audit Committees, and regulators.
- Familiarity with cybersecurity, operational resilience, business continuity, technology resilience, and third-party risk management frameworks.
- Reporting Line
- Direct Report To: Director (Project Director of the CORF Audit).
- Indirect Coordination with Internal Bank Teams.
Required Skills
- Ability to prepare complete and well-supported audit working papers.
- Strong professional judgment, attention to detail, and professional skepticism.
- Ability to communicate technical findings clearly to technical and non-technical stakeholders.
- Strong stakeholder management and communication skills.