syffer

Internal Control Specialist

syffer  •  Lisbon, PT (Hybrid)  •  4 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Syffer is an all-inclusive consulting company focused on talent, tech and innovation. We exist to elevate companies and humans all around the world, making change, from the inside to the outside.

We believe that technology + human kindness positively impacts every community around the world. Our approach is simple, we see a world without borders, and believe in equal opportunities. We are guided by our core principles of spreading positivity, good energy and promote equality and care for others.

Our hiring process is unique! People are selected by their value, education, talent and personality. We dont present ethnicity, religion, national origin, age, gender, sexual orientation or identity.

Its time to burst the bubble, and we will do it together!

What You'll do:

- Test controls at design effectiveness level

- Test controls at operating effectiveness level

- Conduct structured walkthroughs with LOD1 control owners to understand how controls function and collect evidence

- Produce completed control testing workpapers as formal outputs of each testing cycle

- Review, validate, and assess control evidence (logs, screenshots, access records, configuration files, ticketing records)

- Document findings, gaps, and recommendations clearly

- Maintain findings and remediation tracking logs; follow corrective actions through to closure

- Prepare control assessment and testing reports

- Support the preparation of reporting materials for management and governance committees

- Engage proactively with stakeholders across IT and business functions;

- Hybrid work model.


Who You Are:

- Minimum 2 to 3 years of hands-on experience in IT audit, cybersecurity audit, internal control, GRC consulting, or a second-line assurance function;

- Background in a Big Four firm or recognized GRC/audit consultancy is a strong differentiator;

- Solid, practical experience with ISO 27001 (audit, implementation, or formal control testing);

- Working knowledge of NIST Cybersecurity Framework as applied to control assessment;

- Familiarity with ICT control domains: access management, change management, incident management, patch management, vulnerability management, asset management, endpoint security, logging and monitoring;

- Understanding of business continuity and disaster recovery controls, including BIA principles and RTO/RPO concepts;

- Awareness of DORA, NIS2, or other ICT regulatory frameworks applicable to financial services - a genuine plus, not a hard requirement;

- Demonstrated ability to conduct formal walkthroughs with control owners and translate outcomes into testing documentation;

- Strong written communication in both Portuguese and English for reporting and stakeholder interaction;

- Ability to work autonomously in a project-based, deadline-driven environment.



What you'll get:

- Wage according to candidate's professional experience;

- Remote Work whenever possible;

- Delivery of work equipment adjusted to the performance of functions;

- Benefits plan;

- And others.

Work together with expert teams on projects of large magnitude and intensity, long term together with our clients, all leaders in their industries.

Are you ready to step into a diverse and inclusive world with us?

Together we will promote uniquess!

syffer

About syffer

We are a consultancy focused on talent, tech and innovation, with global impact more and more everyday. We believe that innovation, technology + human kindness positively impacts every community around the world.

And we are here to make it happen!

Industry
IT & Software
Company Size
11-50 employees
Headquarters
Lisbon, PT
Year Founded
Unknown
Social Media