Information Security Audit Lead
Description
Information Security Audit Lead
1.1 Overview
DNEG’s expanding global Information Security program requires an experienced Information Security Audit Lead to lead, operate, and continuously mature the Information Security internal audit program across DNEG Group.
The Information Security Audit Lead forms part of the Security Audit & Assurance function within the Global CISO Office and is responsible for providing structured, objective, risk-based assurance over DNEG locations, business-critical systems and applications, and security control environments.
The role will lead and personally execute DNEG’s internal Information Security audit program across three primary areas:
- Internal audits required to support applicable ISO certification and assurance requirements.
- Physical and site security audits against the DNEG Unified Security Control Framework, including applicable mappings to ISO, TPN, and other relevant security requirements.
- Technical security audits of business-critical systems, applications, platforms, infrastructure, and supporting technology environments.
This is both a program leadership and hands-on audit role. The successful candidate must be capable of developing and operating a mature, scalable internal security audit program while personally planning, leading, executing, documenting, and reporting complex audits.
The role requires a combination of formal audit expertise and strong Information Security technical knowledge. The Information Security Audit Lead must be capable of independently evaluating technical environments, examining objective evidence, testing security controls, identifying material control deficiencies, and reaching clear and well-supported audit conclusions.
The Information Security Audit Lead will work collaboratively across the Global CISO Office and with business, technology, engineering, facilities, and control owners while maintaining the independence and objectivity required of the Security Audit & Assurance function.
1.2 Mandatory Requirements and Expectations
An experienced Information Security audit professional who works in a methodical, objective, technically rigorous, and efficient manner is required to lead the DNEG Group Information Security internal audit program.
- Demonstrable experience developing, leading, operating, and continuously improving a risk-based Information Security or technology internal audit program.
- Demonstrable experience personally planning, leading, and executing Information Security audits from initial scoping through fieldwork, reporting, and follow-up.
- Strong working knowledge of recognized audit methodologies and the principles of independence, objectivity, professional judgment, evidence-based assessment, sampling, control testing, audit documentation, and reporting.
- Demonstrable experience conducting internal audits supporting ISO 27001 and ISO 42001 certification requirements, including the ability to conduct complete internal audits in accordance with applicable internal audit requirements and established audit criteria.
- Experience conducting physical or site security audits against established security standards, control frameworks, or certification requirements.
- Strong technical Information Security knowledge and experience conducting audits or control assessments of complex systems, applications, infrastructure, cloud environments, networks, identity and access environments, security technologies, or other business-critical technology.
- Ability to distinguish material security and control weaknesses from lower-value procedural or administrative observations and reach defensible, evidence-supported conclusions.
- Excellent analytical, investigative, interviewing, documentation, reporting, and stakeholder-management skills.
- Ability to communicate complex audit findings and technical control deficiencies clearly to both technical and non-technical stakeholders.
- Ability to operate independently while collaborating effectively with the Global CISO Office, technology teams, business stakeholders, Facilities, Shared Services, and other control owners.
- Demonstrable ability to manage multiple concurrent audits, priorities, dependencies, and reporting requirements across a global organization.
- Strong commitment to continuously improving audit quality, efficiency, consistency, and scalability.
- Demonstrable ability and willingness to leverage AI, automation, data analytics, and modern audit technologies to improve audit planning, evidence analysis, testing, documentation, reporting, and overall audit execution2. Duties and Operational Responsibilities
- Lead, manage, and continuously mature the DNEG Group Information Security internal audit program, including the risk-based audit plan, methodology, schedule, standards, and reporting.
- Personally lead and conduct Information Security audits across DNEG Group, applying consistent audit methodology from planning and scoping through testing, reporting, and follow-up.
- Lead and conduct required ISO Information Security internal audits, including ISO 27001 and ISO 42001, supporting certification and assurance requirements.
- Conduct physical and site security audits across DNEG Group locations against the DNEG Unified Security Control Framework, including applicable mappings to ISO, TPN, SOC, and other relevant security requirements.
- Conduct risk-based technical security audits of business-critical systems, applications, platforms, infrastructure, cloud environments, and supporting technology services.
- Evaluate the design, implementation, and operating effectiveness of security controls through appropriate evidence review, sampling, technical analysis, interviews, and control testing.
- Apply sufficient technical depth to independently evaluate technical environments, challenge control assertions, identify material control weaknesses, and reach clear, evidence-supported audit conclusions.
- Produce clear and defensible audit documentation and reports covering audit scope, testing performed, findings, control deficiencies, conclusions, and required management responses.
- Manage audit findings through the audit lifecycle and independently verify remediation before findings are considered closed, while ensuring remediation ownership remains with the appropriate control owner.
- Identify recurring and systemic control weaknesses and provide meaningful audit reporting and assurance insights to Information Security leadership and other appropriate stakeholders.
- Maintain the independence and objectivity of the Security Audit & Assurance function while collaborating effectively with GRC, Architecture & Engineering, Security Operations, ISPM, Data Protection & Privacy, technology teams, Facilities, business stakeholders, and other control owners.
- Maintain current knowledge of security standards, audit practices, technologies, and industry developments necessary to keep the internal audit program effective and relevant.
- Proactively leverage approved AI, automation, analytics, and technology-assisted audit techniques to improve audit planning, evidence analysis, control testing, documentation, reporting, coverage, and execution speed.
- Continuously improve and automate repeatable audit processes while maintaining appropriate human judgment, evidence integrity, audit quality, and defensible assurance outcomes.
3. Job Requirements
3.1 Mandatory Job Requirements
A successful candidate will meet the majority of the requirements listed below and will be able to demonstrate suitable experience and competency in each of the following:
- Approximately 5–10+ years of relevant professional experience across Information Security audit, technology audit, cybersecurity audit, security assurance, technical security assessment, or closely related disciplines.
- Demonstrable experience leading or materially contributing to an enterprise Information Security or technology internal audit program.
- Demonstrable ability to both lead an audit program and personally execute complex audits.
- Practical experience developing risk-based audit plans, audit programs, engagement scopes, testing procedures, sampling approaches, working papers, findings, and formal audit reports.
- Strong knowledge of internal audit principles, control design and operating-effectiveness testing, objective evidence, audit sampling, documentation, findings development, and follow-up verification.
- Demonstrable experience conducting ISO 27001 internal audits and strong working knowledge of applicable ISO 27001 requirements and controls, with knowledge or experience of ISO 42001, SOC 2, TPN, and other relevant security and assurance frameworks.
- Practical experience auditing against recognized Information Security standards, frameworks, or control environments.
- Experience conducting physical or site-based security audits within complex organizational environments.
- Strong technical knowledge across multiple Information Security domains, which may include:
- Identity and Access Management and privileged access.
- Network and infrastructure security.
- Cloud security.
- Application and product security.
- Vulnerability and exposure management.
- Security monitoring and logging.
- Security operations and incident-response controls.
- Endpoint and platform security.
- Data security and protection controls.
- Secure configuration and change management.
- Software development and supporting technology processes.
- Ability to understand complex technology environments, interrogate technical evidence, ask incisive questions, challenge control assertions constructively, and reach independent, well-supported conclusions.
- Demonstrable experience evaluating both the design and operating effectiveness of Information Security controls.
- Ability to identify material control deficiencies and clearly articulate the associated security exposure and business implications.
- Strong written communication skills and experience producing professional audit reports suitable for technical stakeholders, senior management, and executive leadership.
- Strong stakeholder-management skills and the confidence to constructively challenge control owners while maintaining effective professional relationships.
- Demonstrable ability to manage multiple audit engagements and deliver high-quality work against defined schedules.
- Experience working within complex, distributed, or global technology environments.
- Demonstrable practical experience using AI, automation, analytics, scripting, or technology-assisted audit techniques to improve audit efficiency, coverage, evidence analysis, testing, or reporting, or a demonstrated ability to rapidly develop and apply these capabilities.
- A continuous-improvement mindset with the ability to challenge unnecessarily manual or time-consuming audit processes and develop more efficient approaches without compromising audit quality or professional standards.
3.2 Desired Job Requirements
A successful candidate may also have experience with the following:
- Experience auditing organizations operating across multiple countries, business units, or geographically distributed locations.
- Experience conducting audits within film, visual effects, media, entertainment, technology, or other environments handling highly confidential intellectual property and client information.
- Working knowledge of the Trusted Partner Network (TPN) or comparable content-security requirements.
- Experience working with unified or common control frameworks that map organizational controls across multiple standards, regulatory requirements, or customer assurance frameworks.
- Experience conducting audits of cloud-native or hybrid technology environments.
- Experience auditing business-critical applications, internally developed systems, SaaS platforms, production technology, or complex technology services.
- Experience using GRC, audit-management, data-analysis, automation, or evidence-management platforms to support audit execution.
- Experience using scripting, querying, APIs, or data-analysis techniques to independently analyze large evidence sets or validate control operation.
- Experience applying AI-assisted techniques to audit scoping, evidence analysis, control testing, anomaly identification, documentation, or reporting.
- Understanding of other commonly used security frameworks and standards such as NIST, CIS Controls, CSA CCM, TPN or comparable frameworks relevant to enterprise security environments.
- Experience presenting audit results, systemic findings, and assurance trends to senior Information Security or business leadership.
3.3 Education
- A bachelor’s degree in Information Security, Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, Accounting, Audit, or a related discipline is desirable but not essential where equivalent practical experience can be demonstrated.
- ISO/IEC 27001 Lead Auditor and/or ISO/IEC 42001 Lead Auditor or equivalent recognized audit qualifications are strongly preferred.
- Relevant professional certifications such as CISA, CISSP, CIA, CISM, CRISC, CCSP, or comparable Information Security, technology audit, or assurance credentials are desirable.
- Technical security, cloud, application security, or other relevant technology certifications are advantageous where they demonstrate the technical depth required to conduct substantive security audits.
About Us
We are DNEG, one of the world’s leading visual effects and animation companies for the creation of award-winning feature film,
television, and multiplatform content. We employ more than 9,000 people
with worldwide offices and studios across North America (Los Angeles,
Montréal, Toronto, Vancouver), Europe (London), Asia (Bangalore, Mohali,
Chennai, Mumbai) and Australia (Sydney).
At DNEG, we fundamentally believe that embracing our differences is a vital component of our collective success. We are committed to creating an equitable, diverse and inclusive work environment for our global teams, where everyone feels they matter and belong. We welcome and encourage applications from all, regardless of background, experience or disability. Please let us know if you need any adjustments or support during the application process, we will do our best to accommodate your needs. We look forward to meeting you!