> Markdown version of [/jobs/ext/1487087-information-systems-auditor-all-levels](https://www.wearedevelopers.com/jobs/ext/1487087-information-systems-auditor-all-levels). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Auditor | All Levels - **Company:** Silverthorne Advisory Group LLC - **Location:** Arlington, VA, United States - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Antivirus, Microsoft Azure, Backup Devices, Cloud Computing, Configuration Management, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Systems, Information Technology Consulting, Databases, Disaster Recovery, Identity and Access Management, Information Technology Audit, Python (Programming Language), Oracle (Applications), PCI Data Security Standards, Windows PowerShell, Power BI, Azure Active Directory, SAP (Applications), SQL Databases, Software Vulnerability Management, Data Logging, Google Cloud, Enterprise Software Applications, Cloud Platform System, IT General Controls (ITGC), Microsoft InTune, Information Technology, Data Analytics, Microsoft Sentinel, Workday, Servicenow - **Published:** July 29, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9063182/information-systems-auditor-all-levels ## About the Role Certified Information Systems Auditor (CISA) certification. - 3+ years of experience in IT audit, information security, cybersecurity, risk management, internal audit, or technology consulting. - At least one (1) year of experience in federal audit or federal audit readiness. - Bachelor's degree in Information Systems, Computer Science, Cybersecurity, Accounting, Information Technology, or a related discipline. - Experience performing IT General Controls (ITGC) testing and technology risk assessments. - Knowledge of NIST Cybersecurity Framework, NIST SP 800-53, NIST SP 800-171, COBIT, COSO, and FISCAM. - Experience evaluating identity and access management, change management, logical access, backup and recovery, and configuration management controls. - Strong understanding of cybersecurity principles, security controls, and enterprise risk management. - Experience developing audit reports, documenting findings, and communicating recommendations to stakeholders. - Excellent analytical, problem-solving, organizational, and written communication skills. - Ability to manage multiple projects and work independently in a fast-paced environment. - Experience supporting federal civilian, Department of War, or Intelligence Community clients. - Knowledge of FISMA, FedRAMP, RMF, CMMC 2.0, GAO Green Book, and OMB Circular A-123. - Experience with cloud platforms including Microsoft Azure, Amazon Web Services (AWS), or Google Cloud Platform (GCP). - Familiarity with Microsoft Defender, Microsoft Sentinel, Microsoft Entra ID, Microsoft Intune, ServiceNow, SAP, Oracle, or Workday. - Experience with data analytics, SQL, Power BI, Python, PowerShell, or audit automation tools. - Professional certifications such as CISSP, CISM, CRISC, CIA, CPA, CGFM, Security+, or PMP. - Experience supporting SOC 1, SOC 2, ISO 27001, PCI DSS, HIPAA, or SOX compliance initiatives. - Active Secret or Top Secret security clearance, or the ability to obtain and maintain one. - Experience leading audit engagements, mentoring junior staff, and presenting to executive leadership. - Strong consulting, stakeholder management, and client relationship skills. - Compensation - We carefully consider a wide range of compensation factors, including but not limited to prior experience, skills, expertise, location, and other considerations permitted by law. ## Description Silverthorne Advisory Group is seeking an Information Systems Auditor to join an exciting and growing opportunity supporting clients across the Defense sector. This role is responsible for evaluating the effectiveness of information technology controls, cybersecurity safeguards, governance processes, and enterprise risk management programs while supporting federal financial management, audit readiness, and digital modernization initiatives. The successful candidate will perform risk-based IT audits, assess the design and operating effectiveness of IT General Controls (ITGCs), application controls, and cybersecurity controls, and provide recommendations to strengthen security, compliance, and operational efficiency. Day-to-day responsibilities will emphasize foundational knowledge of federal financial management while expanding expertise beyond traditional system audit disciplines through the use of modern data, analytics, and artificial intelligence technologies. The role partners closely with business leaders, information technology teams, cybersecurity professionals, finance organizations, and external auditors to identify and mitigate technology risks while ensuring compliance with federal regulations, industry standards, and evolving cybersecurity frameworks. This position offers an exceptional opportunity to combine information systems auditing, cybersecurity, data analytics, and emerging AI capabilities in support of high-impact defense and federal missions. Responsibilities: - Plan, execute, and document risk-based information systems audits. - Evaluate IT General Controls (ITGCs), application controls, and automated business processes. - Assess the effectiveness of cybersecurity, identity and access management, and data protection controls. - Perform technology risk assessments and identify control gaps, vulnerabilities, and compliance risks. - Conduct testing of security, operational, and financial system controls. - Develop audit workpapers, findings, recommendations, and executive-level reports. - Validate corrective actions and monitor remediation efforts through completion. - Support compliance with NIST, COBIT, ISO 27001, FISMA, CMMC, SOX, FedRAMP, and other regulatory frameworks. - Participate in internal and external audits, assessments, and regulatory examinations. - Evaluate cloud environments, enterprise applications, databases, and infrastructure security controls. - Assess change management, configuration management, backup, disaster recovery, and business continuity processes. - Review logging, monitoring, incident response, vulnerability management, and privileged access management practices. - Analyze technology risks associated with emerging technologies, cloud computing, automation, and artificial intelligence. - Collaborate with cybersecurity, engineering, finance, and business stakeholders to improve governance and internal controls. - Identify opportunities to improve audit methodologies, automate testing procedures, and enhance operational efficiency. - Stay current on evolving cybersecurity threats, regulatory requirements, and industry best practices. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Destigmatizing the Workplace: Building Real Inclusion](https://www.wearedevelopers.com/videos/1492-destigmatizing-the-workplace-building-real-inclusion) - [Beyond Dashboards: Fixing Text-to-SQL with Semantic RAG](https://www.wearedevelopers.com/videos/2036-beyond-dashboards-fixing-text-to-sql-with-semantic-rag) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [IT Salaries in Austria](https://www.wearedevelopers.com/magazine/286-it-salaries-in-austria)