Anyone here part of an organization where cybersecurity sits within Internal Audit? Reports directly to the Chief Audit Executive? If yes, would love to hear more!

likefunny
Posting as :
works at
You are currently posting as works at

Cyber security sitting within internal audit would be a hard NO for me as a chief information security officer

This organizational configurations send a signal that the organization views cyber security as a checkbox function rather than an org-wide risk management capability

like

Run.

I would not take that job, your pay will be aligned to the rest of internal audit which would be generally lower than a pure cybersecurity function.

Related Posts

How’s the freelance producer market doing these days? Busy, slow?

like

Anyone have experience in bringing over a blood relatives children as a dependent into usa? If so, which visa ? And what’s the process to follow

like

How much is CMT valued in investment banking companies?

Hi There....Citi-zens.... Can someone help with referral in anti money laundering, Finance crime,KYC roles in SME & TL roles? I don't have the exact job codes

like

How long is the recruitment process from E2E? From first time recruiter reaches out to when you sign offer letter? I know this will vary but very curious because the people I’m interviewing with talk about how long it is a lot

like

Is it possible to switch path from tax associate to data analysis?

like

BDO recruiter reached out for an audit senior position in the DC area. Recommended or not? And why? Insights appreciated!!

likefunny
like

Looking for a cannabis play that isn’t SNDL (sorry financials look like shit). Anyone have a view on GRAMF (JayZs company which just SPACed) ?

like
like

This might sound silly but if the job is still posted after you've done your loop, is that an indication the team is still looking? It's day 2 after my loop so excuse my anxiety.

like

My Creative Directors, who are strong copywriters, are really struggling to collaborate with Art Directors. Are there programs or classes that teach creative collaboration and the creative process?

like
like
like

Hey everyone, Can anyone help me out with a referral to McKinsey. Interested in applying for knowledge analyst, supply chain role that looks like a good fit.

1+ #YOE as an analyst in Procurement and purchasing

like

Anyone at MBB looking to make a referral?

funnylike

Worked for 10.5yrs in Infy Package is 11L and now I have an offer from Enquero(Genpact) for 20L and as a counteroffer from Infy:- 40% hike + Canada visa or 70% hike

Please suggest which will be better for the long term for Testing(Automation/Manual)

PS: I have not considered a Canada visa

like

Hello Fishers, Would like to know about company Aurigo it's culture , WLB , salary , growth . TIA .

like

Additional Posts in Cyber Security Bowl

Privacy fish - Anyone taken the CIPM and can share what the exam is like?

Content outline seems like application of standard consulting approach, so how do they test it on an exam?

Currently stuck in risk but interested in Cyber. Have done one related engagement from a regulatory perspective. But a lot of posts here making me think it’s harder to break into than I expected (non-technical background). If you had a six sigma green belt / supply chain degree/exp., would you still go through the effort of going into Cyber or take easy risk money being offered / easier transition back to supply chain? 2-3 YOE and trying to decide career course, any advice highly appreciated

like

Deloitte Cyber, how long did it take you to receive an offer after final interview?

like

AWS Cloud question- what the difference between an SCP and IAM? Thanks in advance

like

For those who have passed the CIPM exam, what is it like (and how does it compare to the CIPP/US exam)?

Any EY PPMD 🐠 willing to chat/connect? Interested in learning more about the cyber practice. I’m a new campus hire in the Hoboken office. Thanks in advance!

like

New to the U.S., is the Healthcare Industry (via HIPAA), the only industry in the U.S. that legally mandates having a designated Privacy Officer? So for example, although GLBA has obvious privacy requirements, unlike with healthcare, financial institutions in the U.S. are not mandated by law to have a designated Privacy Officer?

like

Thinking about getting the AWS Cloud Practitioner certification. Does EY have any amazon resources or training materials that they provide? Any advise from people who have taken it before? Thanks!

like

Views on carbon black as a product?

helpful

Anyone else at CyberArk Impact this week? Anything exciting going on?

I have interviews coming up with BCG. Any BCG Platinion folks willing to discuss example case interview questions?

like

Anyone know what kind of experience or certifications I should be aiming to get if I'm trying to break into a pentest role? I just graduated last year and have about a year of sysadmin experience and am trying to get into it asap. So, I'm already applying/job hunting and probably won't get much replies but. Should I be looking at more security analyst/admin roles first? Going for certs? Getting a masters? Wondering what I can do to improve my chances. TIA

like

What other professional services firms have people who have technical skills. Most the people I work with are security paper pushers who couldn’t tell you basic security shit.

like
like

How much does Deloitte pay for cybersecurity or devops senior Deloitte roles

like

Wondering if anyone here got "provisional" CISSP --obtaining the cert before five years in the industry. Have Security+ and CIPP/US and aiming for BISO role in Fortune 100. Pivoted from consulting. 15+ YOE. Masters degree Management experience. Advice? Thanks.

like

Would you expense a speeding ticket on your way to an IR?

funnylike

Security TPM on-site at big tech, how would you prepare/review? No coding. Expect high level q’s on vuln. Analysis& arch. design from security POV. I do NOT have an engr. Background. 1wk to prep

like

Currently working in an IT audit role, what is the best way to transition into cyber ?

like

Anyone familiar with Istari-Global and their collective of cyber risk companies? What’s their perception in the market? Opportunity to join US team. Thanks!

like

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal