About this role
Senior IT Auditor
Job Description
About The Role
The successful candidate will join Ferrovial Internal Audit, located in Madrid. He/she will enjoy a double reporting line to the Audit Manager and the Head of IT Audit located in Madrid.
Key Responsibilities
- Take part in the planning of internal audits and in their execution, contributing to the establishment of added value action plans.
- Plan and execute technical cybersecurity audits across key domains: IAM, network and cloud security (Azure, AWS, M365), endpoint protection, vulnerability management, SIEM/SOC and cyber resilience.
- Support data protection and privacy audits when required, covering governance, classification, retention, DPIA, data subject rights and technical controls (encryption, DLP).
- Gather and analyze evidence, document findings and discuss recommendations with auditees at the appropriate level.
- Communicate and discuss conclusions and recommendations with auditees, adapting the message to the audience and hierarchical level.
Qualifications
-
Degree in Computer Science, Telecommunications Engineering or a related technical field.
-
4–5 years of experience in external audit or consulting, or at least 3 years in internal audit or an IT/Information Systems function.
-
Knowledge of key cybersecurity frameworks and regulations, including NIST CSF 2.0, ISO 27001, CIS Controls, NIS2, ENS and GDPR.
-
Hands-on technical expertise across cybersecurity and data protection/privacy domains, including the areas outlined in the role responsibilities.
-
Ability to assess gaps between best practices, regulatory requirements and internal policies, and translate them into practical control improvements.
-
Strong analytical mindset and experience working with data and audit analytics tools such as IDEA, ACL or Power BI.
-
Fluent business English, both written and spoken.
-
Reliable, structured and self-organised, with strong analytical judgement and decision-making skills.
-
Excellent communication and advisory skills, with the ability to adapt complex messages to different audiences and seniority levels.
-
Flexible and collaborative approach, with the ability to adapt to changing priorities, scenarios and deadlines.
-
Availability to travel up to 30% of the year.
-
Desirable / Highly Valued
-
Professional certifications such as CISA, ISO 27001, ISO 22301 or cloud security certifications will be highly valued.
-
Specialised training in cybersecurity, data protection or information systems governance will be considered a plus.
-
Practical experience using Artificial Intelligence and Large Language Models — including tools such as Claude, Copilot, ChatGPT and Gemini — to enhance audit efficiency, automate routine tasks and support smarter, data-driven decision-making.
-
Scripting and querying skills — Python, PowerShell, SQL or KQL — applied to audit testing, continuous auditing and automation of repetitive activities.
-
Experience auditing in multinational environments, working across different geographies, stakeholders and regulatory frameworks.
-
Seize the challenge. Move the world together! Innovative, creative, respectful, and diverse are some of the ways we describe ourselves. We are motivated by challenges, and we collaborate across our business units to move the world together. Your journey to a fulfilling career starts here!
-
Ferrovial is an equal opportunity employer. We treat all jobs applications equally, regardless of gender, color, race, ethnicity, religion, national origin, age, disability, pregnancy, sexual orientation, gender identity and expression, covered veteran status or protected genetic information (each, a “Protected Class”), or any other protected class in accordance with applicable laws.
-
WeAreFerrovial