Information Systems Auditor II
Role details
Job location
Tech stack
Job description
Information Systems Auditor II
About the Job: As an Information Systems Auditor II, you will independently plan and conduct audits of IT systems, cybersecurity controls, and technology-enabled business processes. This role requires strong technical acumen, risk-based thinking, and the ability to evaluate complex systems and data environments. You will contribute to the City's commitment to accountability, transparency, and continuous improvement by ensuring that technological risks are effectively managed.
Learn more about the department: https://coloradosprings.gov/cityauditor
This position is subject to budget required furloughs to be implemented in the 2026 calendar year.
As an Information Systems Auditor II, you will:
- Plan and perform IT audits and IT audit steps, including risk assessment, audit program development, and fieldwork.
- Evaluate IT governance, cybersecurity, and internal controls using frameworks such as NIST (National Institute of Standards and Technology), COBIT (Control Objectives for Information Technologies), etc..
- Conduct interviews, analyze data, and document findings clearly and objectively.
- Draft audit reports and present findings and recommendations to management.
- Perform data analysis to identify anomalies, trends, and control gaps using tools such as Excel, Power Query, or Audit Command Language (ACL).
- Assess compliance with IT policies, procedures, and regulatory requirements.
- Support external audits, fraud investigations, and consulting engagements.
- Participate in internal quality assessments and contribute to process improvements.
- Other duties as assigned.
- Learn more about this job by reviewing the class specification on the City of Colorado Springs Class Specifications page
Knowledge, Skills, and abilities:
- Applies the Global Internal Audit Standards and the International Professional Practices Framework (IPPF).
- Demonstrates ethical judgment, objectivity, confidentiality, and professional skepticism.
- Uses risk-based audit methodologies and critical thinking to evaluate IT controls, cybersecurity, and fraud risk.
- Communicates clearly and professionally with technical and non-technical stakeholders; builds consensus and resolves conflicts constructively.
- Uses data analysis tools (e.g., Excel, Power Query, Audit Command Language (ACL)) to identify trends and support audit findings.
- Manages time, budget, and tasks across multiple projects using project management principles.
- Understands IT governance, cybersecurity, data protection, and system resilience.
- Applies knowledge of IT control frameworks (e.g., National Institute of Standards and Technology (NIS)T, Control Objectives for Information Technologies (COBIT)) and enterprise systems (e.g., ERP, cloud platforms).
- Collaborates with IT, compliance, and risk management to align audit coverage and enhance risk oversight.
We value a diverse range of qualifications and experiences. Our organization views each year of further education as equivalent to each year of relevant work experience, and each year of additional relevant work experience as equivalent to each year of required education.
- Bachelor's degree from an accredited college or university with major coursework in Information Systems, Computer Science, Information Technology, or a related field.
- Three years of full-time, professional experience in a related field.
The following qualifications are not required, but they are considered desirable. If you possess any of the preferred qualifications, please include specific details in your application. This information may be used to identify a top group of applicants.
- Experience in municipal or public sector IT environments.
- Certifications such as Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA), Certified Information Systems Security Professional (CISSP), or advanced degree
- Experience with cloud security, data analytics, or IT general controls.
Please contact City Recruiting at city.recruiting@coloradosprings.gov for any questions about this position.
Requirements
We value a diverse range of qualifications and experiences. Our organization views each year of further education as equivalent to each year of relevant work experience, and each year of additional relevant work experience as equivalent to each year of required education.
- Bachelor's degree from an accredited college or university with major coursework in Information Systems, Computer Science, Information Technology, or a related field.
- Three years of full-time, professional experience in a related field.
The following qualifications are not required, but they are considered desirable. If you possess any of the preferred qualifications, please include specific details in your application. This information may be used to identify a top group of applicants.
- Experience in municipal or public sector IT environments.
- Certifications such as Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA), Certified Information Systems Security Professional (CISSP), or advanced degree
- Experience with cloud security, data analytics, or IT general controls.