Internal Audit Manager - Cyber/Information Security and Cloud Infrastructure
Deutsche Bank
New York City, New York, United States
JOB DESCRIPTION About DWS: DWS Group (DWS) is one of the world's leading asset managers. Building on more than 60 years of experience, it has a reputation for excellence in Germany, Europe, the Americas and Asia. DWS is recognized by clients globally as a trusted source for integrated investment solutions, stability and innovation across a full spectrum of investment disciplines. We offer individuals and institutions access to our strong investment capabilities across all major asset classes and solutions aligned to growth trends. Our diverse expertise in Active, Passive and Alternatives asset management – as well as our deep environmental, social and governance focus – complement each other when creating targeted solutions for our clients. Our expertise and on-the-ground-knowledge of our economists, research analysts and investment professionals are brought together in one consistent global CIO View, which guides our investment approach strategically. DWS wants to innovate and shape the future of investing: with approximately 3,900 employees in offices all over the world, we are local while being one global team. We are investors – entrusted to build the best foundation for our clients’ future. Overview The “Internal Audit Manager DWS Cyber/Information Security and Cloud Infrastructure” is as Lead auditor / auditor responsible for conducting local and global Cyber and Information Security (IS) and IT Cloud Infrastructure audits. This includes in particular the assessment of existing risks, evaluates the adequacy and effectiveness of internal controls relating to risks and the reporting on identified deficiencies. As the Cyber/IS/Cloud Subject Matter Expert, the Internal Audit Manager also participates in integrated audits, which are conducted together with business audit teams. In this position, he reports to the Head of Internal Audit Information Technology. Your Key Responsibilities: You will support the Head of Internal Audit IT in managing a portfolio of audits and will actively contribute to risk assessment and business monitoring. Conducts as lead auditor / auditor the local and global IT audits, this includes writing the findings and drafting the audit report. Drafts high quality audit reports for review by audit management, facilitates finding tracking and validates actions taken to remediate previous audit findings. Executes audit fieldwork in line with the agreed audit approach e.g. documenting Process Flows, identification of key risks, testing of key controls to determine whether they are properly designed and are operating effectively and documenting work in accordance with standards. Partners with other divisional/teams during audit engagement to guarantee an integrated approach. Acts as a competent partner and challenger to clients in the closure process of findings. Communicates openly with management and the internal stakeholders; keeps them informed of potential findings and escalate problems/delays accordingly. Presents complex and sensitive messages comprehensively, professionally and reduces complex topics to simple statements. You will proactively develop and maintain professional consultative working relationships with the Internal Audit function, clients and respective support areas and will use a range of approaches to collect relevant information to assess key risks. Your Skills & Experience: University degree in Computer Science / (Commercial) Information Technology or equivalent qualification. Several years of work experience in IT Audit or in the Information Technology area (common operating systems, databases, threat operations, vulnerability management, cloud security, as well as cryptographic topics), preferably in the financial industry. Demonstrable experience of auditing IT Cyber/Information Security topics, risk-based auditing, and a clear understanding of the relationship between IT risk and underlying business process risk. Strong understanding of cyber security standards (e.g. NIST, OWASP, ISO27001) and knowledge of the regulatory environment in the financial sector (e.g. KAIT, BAIT, ESMA cloud guidelines). Professional / industry recognized certifications (e.g. CCSP, CISSP, OSCP, SEC488) are highly beneficial. Confident appearance and strong verbal and written communication skills and the ability to communicate on all hierarchy levels. Self-driven, eager to learn, well organized team player with strong analytical skills, and willing to travel on an occasional basis. What we’ll offer you: A healthy, engaged and well-supported workforce are better equipped to do their best work and, more importantly, enjoy their lives inside and outside the workplace. That’s why we are committed to providing an environment with your development and wellbeing at its center. You can expect: Competitive Salary and Matched 401K Savings Plan Generous Paid Time Away plus Bank Holidays Health and Life Insurance Plans for you and your family Work/Life Balance Programs including Adoption/Surrogacy/Infertility Assistance, Backup Care through Bright Horizons, Phase Back to Work and Support for New Mothers A range of flexible benefits including Retail Discounts, Commuter Discounts and Gym benefits The opportunity to support wide-ranging volunteer programs, + 1 day volunteering leave per year, matched personal donations to non-profit organizations dollar-for-dollar, up to $5,000 How we’ll support you: Training and development to help you excel in your career Flexible working to assist you balance your personal priorities Coaching and support from experts in your team Expectations It is DWS’s expectation that employees hired into this role will work in the office in accordance with the firm’s hybrid working model. DWS provides reasonable accommodations to candidates and employees with a substantiated need based on disability and/or religion. The salary range for this position in New York City/California is $140,000 - $200,000. Actual salaries may be based on a number of factors including, but not limited to, a candidate’s skill set, experience, education and other qualifications. Posted salary ranges do not include incentive compensation or any other type of remuneration. DWS Values & Diversity We believe talent is found in all cultures, countries, races, ethnicities, genders, sexual orientations, disabilities, beliefs, generations, backgrounds and experiences. We pursue a working environment where everyone can be authentic and feel a sense of belonging. Click here to find out more about our diversity and inclusion efforts. We are an Equal Opportunity Employer - Veterans/Disabled and other protected categories. Click these links to view the following notices: EEO is the Law poster and supplement ; Employee Rights and Responsibilities under the Family and Medical Leave Act ; Employee Polygraph Protection Act and Pay Transparency Nondiscrimination Provision Privacy Statement The California Consumer Privacy Act outlines how companies can use personal information. Click here to view DWS’ Privacy Notice. Our values define the working environment we strive to create – diverse, supportive and welcoming of different views. We embrace a culture reflecting a variety of perspectives, insights and backgrounds to drive innovation. We build talented and diverse teams to drive business results and encourage our people to develop to their full potential. Talk to us about flexible work arrangements and other initiatives we offer. We promote good working relationships and encourage high standards of conduct and work performance. We welcome applications from talented people from all cultures, countries, races, genders, sexual orientations, disabilities, beliefs and generations and are committed to providing a working environment free from harassment, discrimination and retaliation. Visit Inside Deutsche Bank to discover more about the culture of Deutsche Bank including Diversity, Equity & Inclusion, Leadership, Learning, Future of Work and more besides. We are an Equal Opportunity Employer - Veterans/Disabled and other protected categories. Click these links to view the following notices: "EEO is the Law poster" and supplement ; Employee Rights and Responsibilities under the Family and Medical Leave Act ; Employee Polygraph Protection Act and Pay Transparency Nondiscrimination Provision .