The Role - here’s what you will do:
As a Data Center Compliance Auditor, you will have a primary focus on regulatory and certification audit support across SOX, SOC 2, ISO 27001, PCI and additional data center audits as required. You will help ensure that the client’s data center infrastructure is audit-ready and compliant with applicable standards, coordinating with internal teams and external auditors while driving continuous improvement across the control environment.
You will play a critical role in maintaining certifications by planning and executing audit activities, owning evidence gathering, conducting site walkthroughs, performing readiness assessments and enabling data center teams to understand and meet their compliance obligations.
Further Breakdown of key responsibilities
Regulatory & Certification Audit Support
•
Plan, coordinate and facilitate external audits, both remote and on-site, across the client’s owned and leased data center portfolio.
•
Support audits covering SOX, SOC 2, ISO 27001, PCI and other emerging audit requirements.
•
Manage audit schedules, scope definition and logistics with external auditors.
•
Act as a primary liaison between external auditors and internal cross-functional teams throughout audit engagements.
Evidence Collection & Auditor Inquiry Response
•
Own end-to-end evidence gathering across facilities, engineering, physical security and infrastructure finance teams to satisfy auditor requests for information (RFIs).
•
Respond to auditor inquiries with accurate, timely and well-documented evidence.
•
Maintain organized evidence repositories and ensure completeness of audit documentation.
•
Interpret evidence requirements and guide control owners on the standard of evidence expected.
•
Attend and support on-site security walkthroughs with external auditors at data center facilities.
•
Conduct virtual and on-site walkthroughs of data center security environments in support of SOC 2, ISO 27001 and SOX assessments.
•
Prepare site teams for auditor walkthroughs through pre-audit briefings and rehearsals.
•
Document walkthrough findings and coordinate any required follow-up actions.
Audit Readiness & Control Testing
•
Conduct control testing covering design effectiveness and advisory activities across physical and environmental security, logical access, change management and availability controls.
•
Evaluate control design within a Three Lines of Defense (3LOD) framework and provide advisory input on control adequacy.
•
Conduct mock audits and tabletop exercises to prepare sites for external assessments.
•
Develop and deliver compliance training to data center teams on control requirements and audit expectations.
Impact Assessments & Compliance Enablement
•
Support compliance impact assessments for new processes, system changes and site launches.
•
Advise cross-functional teams on the compliance implications of operational changes.
•
Maintain documentation of control descriptions, policies and procedures relevant to audit scope.