The opportunity
SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are not. Today SpaceX is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars.
What you'll do
Lead and support ITGC testing, SOC 1, SOC 2, SOX-related IT controls, and: other relevant audits/certification efforts.
Partner with engineers and system owners to gather, validate, and package: technical evidence for security controls (access management, change management, computer operations, system development lifecycle, configurations, logs, etc.).
Perform technical security and risk assessments of systems, supporting IT: infrastructure, and related networks; identify deviations from security policy, standards, ITGC requirements, or regulatory expectations.
Identify security controls, ITGC, and compliance gaps (especially those: impacting financial reporting or SOC readiness), advise on remediation, and drive timely resolution with engineering and process owners.
Maintain clear documentation of security controls, control processes, risk: assessments, evidence, and audit artifacts.
Identify and drive assessment and audit efficiency through system: integration, data analytics/utilization, GRC tooling, automation, and process improvement.
What they're looking for
- Support third-party risk management efforts for suppliers, including: onboarding assessments and periodic reviews.
- Identify and propose business-enabling actions by maintaining an up-to-date: understanding of emerging information security and IT risks, changes in SOC 1/SOC 2 standards, ITGC best practices, and new compliance/assurance techniques.
- Mentor fellow teammates and take an active role in their development.
- High school diploma or equivalency certificate.