> Markdown version of [/jobs/ext/1337940-it-security-auditor](https://www.wearedevelopers.com/jobs/ext/1337940-it-security-auditor). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Auditor - **Company:** vTech Solution Inc - **Location:** Richmond, VA, United States - **Experience:** Expert - **Salary:** $93,499.0 - $121,551.0 - **Contract:** Temporary to permanent - **Skills:** Microsoft Access, Active Directory, Batch Processing, Oracle WebLogic Server, Microsoft Biztalk Servers, Configuration Management, Cyber Security, Information Systems, Databases, Identity and Access Management, Information Technology Audit, Lightweight Directory Access Protocols (LDAP), Windows Servers, Oracle Databases, Oracle (Applications), PeopleSoft Financial Management, Peoplesoft People Tools, Windows PowerShell, Software Engineering, Oracle Linux, User Provisioning Software, Data Logging, File Transfer Protocol (FTP), IT General Controls (ITGC), People Soft, Patch Management, Data Objects, Oracle Erp - **Published:** July 18, 2026 - **Apply:** https://www.careerjet.com/jobad/us5d56380258996e2c99549954b1a5b763 ## About the Role * Active Certified Information Systems Auditor (CISA) certification. * Minimum three years of relevant IT audit or IT general controls experience. * Experience developing and executing formal IT audit programs and testing control design and operating effectiveness. * Proficiency in preparing audit workpapers, findings, corrective-action recommendations, and final audit reports. * Experience auditing sensitive financial, tax, payment, vendor, or personally identifiable information. * Ability to provide a reference from another state government agency. * Availability for required onsite meetings in Richmond, Virginia. * Ability to perform all work from approved U.S.-based locations. * Knowledge of SEC530 or comparable government security audit standards. * Understanding of IT general controls, application controls, risk-based audit planning, and sampling. * Familiarity with PeopleSoft or Oracle ERP security concepts, Oracle database security, Active Directory/LDAP controls, interface and batch-processing controls. * Skills in audit evidence validation, workpaper preparation, root-cause analysis, corrective-action review, and executive/technical report writing. Preferred Skills & Certifications: * Five or more years of IT audit experience. * Prior experience with SEC530, Commonwealth of Virginia, or VITA audits. * Experience auditing PeopleSoft FSCM, PeopleSoft Financials, or Oracle ERP environments. * Knowledge of GAGAS or Institute of Internal Auditors standards. ## Description The Senior IT Security Auditor PeopleSoft FSCM is responsible for leading the SEC530 IT Security General Controls Audit of the Virginia Department of General Services PeopleSoft Financials environment. This role involves planning and executing audit procedures, assessing control design and effectiveness, maintaining audit documentation, and preparing audit reports. The auditor will collaborate closely with risk assessors and various stakeholders to ensure comprehensive audit coverage of PeopleSoft FSCM and related technical environments. Responsibilities: * Develop the SEC530 audit program, control matrix, testing procedures, sampling plan, evidence requirements, and audit schedule. * Participate in onsite kickoff, draft-report review, and final exit or wrap-up meetings. * Conduct interviews with technical, security, fiscal, system-owner, and management stakeholders. * Assess controls including identity and access management, privileged access, segregation of duties, user provisioning and termination, change and configuration management, application development, and production migration. * Evaluate vulnerability and patch management, logging, monitoring, incident response, backup, recovery, and continuity controls. * Review interface, batch-processing, and reconciliation controls along with sensitive-data protection and third-party/shared/inherited controls. * Examine PeopleSoft roles, permission lists, Process Scheduler, Integration Broker, custom objects, scripts, database links, service accounts, and environment separation. * Assess security controls for PowerShell, SFTP/FTP, BizTalk, database-link, and financial-system integrations. * Maintain the audit evidence-request register and track all requested items and their status. * Prepare comprehensive and defensible workpapers documenting audit procedures and results. * Develop findings with condition, criteria, cause, effect, and recommendation mapped to SEC530 controls. * Review management responses and corrective-action plans. * Prepare and present draft and final audit reports. * Deliver complete audit workpaper packages and reusable templates., * Experience reviewing PeopleTools, WebLogic, Oracle 19c, Windows Server, and Oracle Linux controls. * Familiarity with SFTP, PowerShell, BizTalk, Integration Broker, database links, and financial interfaces. * Additional certifications such as CISSP, CIA, CRISC, CISM, CGEIT, or CPA. Special Considerations: * Mandatory onsite meetings in Richmond, Virginia. * Work must be performed from approved U.S.-based locations only. * Compliance with key-personnel designation and background-check requirements as per SOR. Scheduling: * Work schedule aligned with audit project timelines and onsite meeting requirements. * Coordination with risk assessment activities to minimize duplication and maximize efficiency., Sr. IT Auditor 12 months contract with high potential to extend and convert Hybrid in Richmond, VA Role Overview: We are seeking a skilled Auditor to execute risk-based audits… + 1 month ago + Apply easily, Job Summary: The Senior Information Security Risk Assessor PeopleSoft FSCM will lead comprehensive SEC530 risk assessments for PeopleSoft Financials and related business function… + 10 hours ago + Apply easily + ## Related Videos - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [The Chief Joy Officer and Decoding Motivation@Work](https://www.wearedevelopers.com/videos/1501-the-chief-joy-officer-and-decoding-motivation-work) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Building Organizations That Can Actually Adapt](https://www.wearedevelopers.com/videos/100316-building-organizations-that-can-actually-adapt) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools)