招聘
The Team: The Cybersecurity team is a growing group within the Hearst Internal Audit Department dedicated to providing independent and objective assurance over the organization’s cybersecurity risk management and control environment. The team partners with business units and technology stakeholders to assess risk, strengthen controls, and support continuous improvement across Hearst’s diverse global portfolio.
Job Description/Key Responsibilities:
Assist in the planning and execution of cybersecurity and IT audits under the direction of audit leadership, including walkthroughs, control testing, and evidence evaluation.
Perform testing of security controls related to access management, vulnerability management, change management, incident response, and third‑party risk.
Document audit procedures, results, and conclusions in accordance with Internal Audit standards and methodologies.
Identify control gaps and potential risks, escalating observations to senior team members with supporting evidence.
Support risk assessments and audit scoping activities by gathering background information on systems, processes, and technologies.
Participate in meetings with business and technology stakeholders to understand processes and validate audit observations.
Track remediation activities and assist in follow‑up testing to validate corrective actions.
Leverage AI-enabled tools and automation to enhance audit efficiency, including data analysis, documentation, risk identification, and research activities, while applying professional judgment to validate outputs.
Stay current on basic cybersecurity concepts, emerging threats, and industry standards to continuously build technical and audit knowledge.
Preferred Knowledge and Skills:
Foundational Cybersecurity Knowledge: Understanding of core security domains such as identity and access management, network security, vulnerability management, and secure system configuration.
Audit & Risk Mindset: Familiarity with internal audit concepts, risk assessment, and control testing methodologies.
Framework Awareness: Working knowledge of cybersecurity and IT frameworks such as NIST CSF, ISO 27001, COBIT, or CIS Controls.
Analytical Skills: Ability to analyze evidence, identify inconsistencies, and clearly document findings.
Communication Skills: Ability to communicate effectively with audit team members and stakeholders, both verbally and in writing.
Collaboration & Learning Orientation: Willingness to learn, accept feedback, and work collaboratively within a team environment.
Required Qualifications:
3–6 years of experience in IT audit, cybersecurity, information security, or a related technical field.
Bachelor’s degree in Information Systems, Computer Science, Cybersecurity, related discipline, or relevant military IT, cyber operations, or intelligence experience providing equivalent technical and operational expertise.
Prior experience with a Big Four public accounting firm (Deloitte, PwC, EY, or KPMG), typically 2–4 years, with a focus on IT audit, cybersecurity, or technology risk.
Active professional certification required: CISA, Security+, and/or CISSP.
Strong understanding of enterprise technology environments, security controls, and risk management concepts.
Ability to operate effectively in a multinational corporate environment and collaborate with diverse technical and business stakeholders.
Willingness and ability to travel domestically and internationally up to approximately 25–30% as part of audit activities.
Fluent in English.
We operate a hybrid work environment. During weeks of non-travel, 3 days a week in the Charlotte, NC office is required.
Total Views
0
Apply Clicks
0
Mock Applicants
0
Scraps
0
Similar Jobs

Information Security Engineer II Splunk
Mass General Brigham · Somerville-MA

Vice President, Technology Auditor, Cybersecurity
BNY Mellon · New York, NY, United States; Pittsburgh, PA, United States

Sr Lead Cybersecurity Architect
JPMorgan Chase · Chicago, IL; Columbus, OH; Jersey City, NJ; New York, NY; Plano, TX; Seattle, WA

PKI Security Engineer
Charles Schwab · Austin, TX; Southlake, TX

Assistant Vice President, WM Financial Crimes Risk & Controls
Morgan Stanley · Purchase, New York, United States of America
About Hearst

Hearst
PublicHearst Corporation, Hearst Holdings Inc. and Hearst Communications Inc. is an American multinational mass media and business information conglomerate owned by the Hearst family and based in Hearst Tower in Midtown Manhattan in New York City.
10,001+
Employees
New York
Headquarters
Reviews
3.7
16 reviews
Work Life Balance
3.5
Compensation
3.9
Culture
3.8
Career
3.8
Management
3.4
73%
Recommend to a Friend
Pros
Good work-life balance and flexible environment
Interesting projects and challenges
Competitive compensation and benefits
Cons
Some organizational bureaucracy
Room for improvement in processes
Work-life balance varies by team
Salary Ranges
31 data points
Junior/L3
Senior/L5
Staff/L6
Junior/L3 · Cybersecurity Analyst
0 reports
$95,475
total / year
Base
-
Stock
-
Bonus
-
$81,154
$109,796
Interview Experience
45 interviews
Difficulty
3.1
/ 5
Duration
14-28 weeks
Offer Rate
38%
Experience
Positive 61%
Neutral 20%
Negative 19%
Interview Process
1
Phone Screen
2
Technical Interview
3
Hiring Manager
4
Team Fit
Common Questions
Technical skills
Past experience
Team collaboration
Problem solving
News & Buzz
Hearst Union Delivers Strike Pledge Ahead of Contract Expiration - TheWrap
Source: TheWrap
News
·
5w ago
Hearst Global Solutions - facebook.com
Source: facebook.com
News
·
6w ago
Betsy Schlehuber ’25 earns Hearst Journalism Award for autism feature - Elon University
Source: Elon University
News
·
6w ago
Subids A-Z, Part 24: AuthDem Hearstian Democracy | We're in the Money
# [We're In The Money](https://youtu.be/W6XNpmxqst4?si=e2NQVNsfjDPRYK6O) How to get: Start as USA, switch over to PSA when the 2ACW starts, choose all the options that increase seccessionism during the opening event chain, then elect Hearst when the option comes up. Do not pick the focus that switc
·
8w ago
·
287
·
16