Rigsrevisionen (the National Audit Office of Denmark) is an independent institution under the Danish Parliament (Folketinget) and part of the parliamentary oversight in Denmark. It operates in the space between Parliament and the public administration, acting as Parliament’s watchdog.
Rigsrevisionen is responsible for auditing the accounts of state and state-funded enterprises and reviews the accounts of organizations that receive state subsidies and similar support. It carries out annual audits and larger investigations. In doing so, it ensures that state authorities, other state-funded agencies, and enterprises comply with applicable laws and regulations and are managed economically, productively, and efficiently. The results of the audits are published in the form of memos and reports to the Public Accounts Committee of the Danish Parliament.
Organizationally, Rigsrevisionen consists of 18 offices spread across 4 departments with a total of approximately 280 employees. Rigsrevisionen places a high priority on independence and flexibility, meaning that employees help organize their own work and have significant influence over their tasks. There is also a strong focus on the social environment and internal relationships; among other things, there is a staff association that organizes social events such as the DHL relay race, wine tasting, and a Christmas party.
The Department
Office 16, a specialist office for IT auditing, has an authorized staff of 15 employees who audit IT security across the entire state. They audit critical societal systems as well as finance, accounting, and subsidy systems. The office brings together employees with different skills and backgrounds. There are IT technicians, IT auditors, and social science professionals who work closely together to solve tasks.
The office is characterized by team spirit and teamwork. Tasks are solved in audit teams of 2-3 employees, with each employee handling several tasks at a time. The composition of teams varies throughout the year depending on the specific task. Each team has a team leader who ensures that the audit is completed on time and to the right quality. Audits are carried out on-site at state institutions, where auditors and IT specialists work closely together.
The Position
In the role of Infrastructure Specialist at Rigsrevisionen, you will play an important part in helping to determine whether the state is prepared to withstand the threat of cyberattacks. For example, you will also examine whether the state’s access management and logging are in order, and whether the data in the state’s accounting systems can be trusted to be correct.
In this context, you will encounter various technologies and systems such as SIEM, AD, VLAN, DMZ, MS SQL, PowerShell, IDS, AWS and Azure. It is therefore important that you have a broad technical profile with good knowledge of several of the technologies mentioned above.
Your tasks during the audits will focus on identifying technical risks, including gaining an overview of the existing system landscape, identifying weaknesses in the IT environment under review, and reviewing and documenting specific technical shortcomings.
It is important to emphasize that this position is hands-off, meaning that your job is to identify technical risks and issues in different parts of the state. You must also be able to communicate your findings to others without a technical background, but you are not permitted to advise the audited parties on specific solutions. This is because Rigsrevisionen must remain independent and cannot audit solutions it has itself proposed.
As Infrastructure Specialist, you will have many different and varied tasks, so it is important that you can maintain an overview when you have many balls in the air.
Responsibilities
- Gain an overview of varying system landscapes and target the areas where you expect the most significant challenges to be
- Participate in external meetings, where you must be able to find the “needle in the haystack” and identify weaknesses in state systems
- Be curious and think creatively about how errors and weaknesses can be found (hands-off) and “proven”
- Translate technical issues so that others without an IT technical background, both in your team and among the audited parties, can understand them
- Help your colleagues with input for the reporting they are responsible for – you do not need to be a great writer yourself
- Participate in discussions of the reporting in meetings with the audited parties, where you must be able to argue for the technical findings
Requirements
It is important that you have:
- Several years of experience from an IT environment, e.g. as a systems administrator, IT architect, or IT security advisor.
- A broad technical profile with good knowledge of infrastructure systems such as SIEM, AD, VLAN, DMZ, MS SQL, PowerShell, IDS, AWS, Azure, etc.
- The ability to maintain an overview of many different systems and audits at once.
Recent Comments