Project Lead - Cyber Audit (Hybrid) presso United Airlines
United Airlines · Chicago, Stati Uniti d'America · Hybrid
- Professional
- Ufficio in Chicago
We believe that inclusion helps us thrive and grow at United across our collaborative Finance teams consisting of Financial Planning & Analysis, Internal Audit, Treasury, Global Procurement, Controllership, Investor Relations and more. These teams provide the financial fuel that keeps our operation running from providing detailed analyses of financial planning, performance, and forecasts to managing our investments and financial strategies. Our Finance team plays an integral role in making our airline profitable and successful by meeting our financial goals.
Job overview and responsibilities
The IT/Cyber Audit Project Lead will be responsible for leading and executing on the DT and Cyber Audit program and supporting the development of a next-generation, global IT audit function. This includes developing a deep understanding of technology and security processes and risks within the airline industry, creating strong partnerships with cross functional leaders, carrying out the cyber audit program and mentoring individuals to deliver on value-add audits and high-quality audit reports. This position reports directly to the Manager of IT/Cyber Audit.
- Audit Program and Project Management:
- Lead and support cybersecurity and technology audits, demonstrating a strong working knowledge of IT and cybersecurity standards/frameworks (for example, NIST, COBIT, ITIL) that impact the organization both in the United States and globally. Key activities include audit scoping (including incorporating technical security testing), planning, stakeholder management, fieldwork execution, reporting and validation of remediated audit findings.
- Supervise and schedule the work of 1-4 IT and cyber audit staff and/or senior IT and cyber auditors on concurrent projects, under the guidance of the Senior Manager of IT Audit or Manager of IT/Cyber Audit on project deliverables
- Conduct closing meetings with clients to discuss audit results and management action plans for corrective actions. Communicate progress of audit objectives and testing with clients, audit project team members and/or the IT and cyber Audit management team on a timely basis
- Utilize data analytics to draw conclusion and ensures that approved audit objectives are met, and that adequate coverage is achieved
- Review all team written communications such as audit reports, client correspondence, memos and other working papers that document the procedures performed, findings, and conclusions
- Assist with special projects, contracted services, and other agreed upon procedures requested of the Internal Audit department. Actively participate in ad-hoc committees and task forces. Strive to add value to the productivity and growth of the department.
Support the development of the technology and cybersecurity program to deliver against strategic program objectives and enhance integrated project delivery. Advance cyber assurance processes and techniques through red team principles, incorporation of security assessment tools, and enhanced technical testing
- Staff Development and Engagement
- Train audit staff on audit standards, department procedures and technical skills required for their position.
- Train audit staff on deepening technical auditing capability incorporating red team and blue team offensive and defensive cyber concepts.
- Coaches and mentors staff to improve audit delivery and leadership capabilities
- Business Unit Relationship Development and Risk Assessment:
- Influence client management to drive measurable action plans to address control deficiencies.
- Participate in meetings that develop business unit relationships which work to ensure audits address areas of concern relative to the business’ goals and performance objectives. Interact with client personnel to better understand their business and strategy, demonstrating a commitment to continually improve the organization.
- Assess risk, maintain knowledge of evolving cyber threats and risk management landscape, general business and economic developments and gain an understanding of the Company’s industry and related control risks
%3Cblockquote dir=%22ltr%22%3E%3Ch3%3EWhat’s needed to succeed (Minimum Qualifications):%3C/h3%3E%3Cp%3E%26nbsp;%3C/p%3E%3Cul%3E%3Cli%3EBachelor%27s degree in Cybersecurity, Information Systems, computer software engineering, Business, data science/analytics or related field%3C/li%3E%3Cli%3ECISSP or comparable designation%3C/li%3E%3Cli%3EMinimum of 4 years cybersecurity, IT audit, IT and/or a related field%3C/li%3E%3Cli%3E1+ years of experience with either supervising teams or project management%3C/li%3E%3Cli%3EStrong grasp of basic cybersecurity and technology concepts (infrastructure, applications, cloud architecture and security, engineering etc.)%3C/li%3E%3Cli%3EKnowledge of IT and cyber auditing processes/procedures%3C/li%3E%3Cli%3EKnowledge and skill in applying internal auditing principles and practices, management principles and preferred business practices%3C/li%3E%3Cli%3EKnowledge of Cybersecurity and IT frameworks, e.g., NIST 800-53, NIST CSF,COBIT, ISO 27001/2, CIS, OWASP, MITRE ATT%26amp;CK%26nbsp;%3C/li%3E%3Cli%3EProven knowledge of and skill in applying data analytics to audit projects%3C/li%3E%3Cli%3EStrong working knowledge of Microsoft applications such as Word, Excel, Visio, Outlook and Access%3C/li%3E%3Cli%3EStrong problem-solving skills and ability to communicate effectively, both in written form and orally%3C/li%3E%3Cli%3EWillingness and ability to travel up to 15%, both domestically and internationally%3C/li%3E%3Cli%3EMust be legally authorized to work in the United States for any employer without sponsorship%3C/li%3E%3Cli%3ESuccessful completion of interview required to meet job qualification%3C/li%3E%3Cli%3EReliable, punctual attendance is an essential function of the position%3C/li%3E%3C/ul%3E%3Cp%3E%26nbsp;%3C/p%3E%3Ch3%3EWhat will help you propel from the pack (Preferred Qualifications):%3C/h3%3E%3Cp%3E%26nbsp;%3C/p%3E%3Cul%3E%3Cli%3EOSCP or equivalent%3C/li%3E%3Cli%3EData analytics experience%3C/li%3E%3Cli%3EDirect experience in the transportation field%3C/li%3E%3Cli%3E%3Cp%3EExperience using cybersecurity assessment tools, for example burpsuite, snort, wireshark, password crackers, and other cyber%26nbsp;%3C/p%3E%3Cp%3Ereconessnence tools%3C/p%3E%3C/li%3E%3Cli%3EExperience using Microsoft Power BI, Spotfire and Audit Board%26nbsp;%3C/li%3E%3Cli%3EAbility to assess complex IT and business processes environments to identify risks%3C/li%3E%3Cli%3EExcellent analytical, organizational, problem solving and prioritization skills%3C/li%3E%3Cli%3EAbility to work under time pressure, prioritize a high workload, and meet strict deadlines%3C/li%3E%3Cli%3EPositive attitude and open mindset, not afraid to roll up your sleeves%3C/li%3E%3C/ul%3E%3C/blockquote%3E Candidarsi ora
 
			 
			 
			 
			