Future Opening: Site Security Auditor: Los Angeles Metro REMOTE

We are anticipating the need to hire a Site Security Auditor in the future.

 

The Site Security Auditor at ISE will assist in the growth of our media and entertainment vendor audit program. Our ideal candidate for the Site Security Auditor must have hands-on technical expertise with GRC tools, intrusion prevention & detection and direct experience with security audits.  

 

What you’ll do at ISE: 

  • Perform site assessments of services facilities, which conduct workflows at physical premises, including commercial and residential scenarios. 

  • Drive client security through knowledge of security protocols and demonstrating responsible cybersecurity practices, including risk management, control implementation, ISMS implementation, and business continuity management, among other topics, to build a stronger overall security posture. 

  • Conduct meetings with clients and clients’ vendors’ employees, while addressing the vendors’ security policies, workflow, physical, and digital security parameters. 

  • Create audit plans to test key controls and verify compliance. Assess the severity of identified weakness and the impact of the risk involved. 

  • Identify security gaps based on Motion Pictures Association (MPA) Best Practices and other best practice and standard bodies, understand any underlining causes or related impact, and how to address them. 

  • Document and present audit findings, observations, and conclusions to internal and external stakeholders. 

  • Evaluate and develop recommendations to ensure vendors compliance with industry best practices. 

  • Collaborate with leadership to develop adjustments to existing policies and practices in order to address gaps within business processes and within the audit process.  

  • Ensure completion of the project within the agreed-upon level of effort and time frame. 

 

Must Haves: 

  • One year of experience within the last four years in Media & Entertainment industry audit experience. 

  • Reside in Los Angeles, California metro area
  • Knowledge of security audit frameworks, practices, tools, and techniques. 

  • Auditors should possess analytical and technical knowledge together with interviewing, interpersonal and presentation skills. 

  • Experience with Motion Picture Association (MPA) Best Practices and how they are integrated in vendor locations. 

  • Minimum of two years of experience conducting IT audits covering Content Security, Cyber Security, Information Security, and/or Information Systems. 

  • At least one active information security, cybersecurity, and/or IT audit certification below. 

    • CompTIA  

      • Security+ 

      • CASP+ 

      • PenTest+ 

    • EC-Council 

      • CEH 

    • GIAC 

      • GSEC 

      • GISF 

      • GWAPT 

      • GISP 

    • ISACA 

      • CISA 

      • CISM 

      • CRISC 

      • CGEIT 

      • CDPSE 

      • CSX-P 

    • ISC2 

      • CISSP 

    • PECB 

      • ISO 27001 Certified Auditor 

What you bring to the table:   

  • Experience reading and illustrating architecture and network diagrams. 

  • Understanding of the principals of information security policies, business continuity plans, and industry control requirements as they pertain to the security of the content. 

  • Ability to identify gaps and develop recommendations around operations, policy management, and physical and digital security. 

  • Knowledge of compensating controls or alternatives due to restraints such a budget, employment, nature of content, etc. 

  • Strong writing, communication, logistics/time management, professionalism. 

  • Ability to travel internationally. 

 

Salary: 

Associate to Mid Level: $70K-$90K

Senior Level: $90K-$110K

 

If you don't meet all the criteria above but are still interested in the job, please apply. Nobody checks every box, and we're looking for someone excited to join the team. 

 

What we bring to the table:    

  • Check out joinise.io for full details
  • Work that matters; projects that impact people’s everyday life and wellbeing

  • Quality, integrity, dedication, and education: our core values. 

  • Life balance: flexible schedule, work from home option, and unlimited vacation 

  • $0 health premium plan option, including spouse and family.   

  • Opportunities to research and publish, speak at major security events and conferences. 

  • Leadership and peers that support and mentor you: your growth is our growth, your success is our success. 

  • Relaxed and fun environment: ditch the suit and tie, sit or stand at your desk or find a sofa. 

  

How you’ll learn at ISE:    

Everyone has a mentor, or two or three sometimes. We hold you and ourselves accountable for your advancement. You’ll learn directly from your mentor, your colleagues, resources vetted by the team, and at regular firetalk lunches by your peers. You also have access to paid training, workshops, university courses, certification courses, and we’ll pay for the certs too. Want to learn a new skill that you aren’t currently using but want to? Great! Innovation is key–new technology is important.   

  

    

About ISE:    

ISE is an independent security consulting and software firm headquartered in Baltimore, Maryland dedicated to securing high value assets for global enterprises and performing groundbreaking security research. Using an adversary-centric perspective driven by our elite team of analysts and developers, we improve our clients’ overall security posture, protect digital assets, harden existing technologies, secure infrastructures, and work with development teams to ensure product security prior to deployment. Our team enjoys working in a creative, educational, and comfortable environment where they can thrive professionally.    

 

Building a Better Community:

We value different viewpoints and fresh perspectives. We embrace people who challenge our thinking and question the status quo. We are opposed to narrow minded, exclusionary, and discriminatory viewpoints or practices that inherently undermine our creative process, hinder growth, and impede innovation.

 

Need more info?    

Be sure you spend some time at www.ise.io. Make sure you look through all the perks on the Careers page, then check out our Research and Blog, our events page for the IoT Village, and About page. Follow us on Twitter @ISEsecurity and @IoTvillage 

Back to blog
Ads

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...