Functiebeschrijving
Internal IT Auditor
Medior, Senior
Den Haag
Als Internal IT Auditor bij BNG Bank voer je zelfstandig IT-audits uit, analyseer je IT-risico's, adviseer je over systemen en projecten, rapporteer je helder en bespreek je bevindingen met senior management; je versterkt IT-governance en risicomanagement.
Direct solliciteren Neem contact op
Automatisch verbeterd voor betere leesbaarheid
Internal IT Auditor
Role purpose: Evaluate and strengthen IT controls, cybersecurity practices, and technology risk management to support compliance, operational resilience, and reliable financial and business reporting. Core responsibilities - Plan and execute risk-based IT audits across infrastructure, applications, cloud services, and third-party providers. - Assess IT general controls (access management, change management, operations, backup/recovery) and application controls. - Review cybersecurity governance, vulnerability management, incident response, logging/monitoring, and data protection controls. - Test controls for regulatory and internal standards (e.g., SOX, ISO 27001, NIST, SOC reports) as applicable. - Document audit scope, procedures, evidence, and results; produce clear reports with prioritized findings and remediation actions. - Partner with IT, security, and business stakeholders to validate corrective actions and track remediation to closure. - Identify control gaps, process inefficiencies, and automation opportunities to improve risk management and audit effectiveness. Required skills and qualifications - IT audit and risk: Experience with ITGCs, application controls, and technology risk assessment. - Security knowledge: Familiarity with identity and access management, network security, endpoint security, and cloud security concepts. - Frameworks: Working knowledge of COBIT, NIST, ISO 27001, and/or SOC 1/SOC 2 reporting. - Analytics and tooling: Ability to use audit workpapers, evidence collect...