> Markdown version of [/jobs/ext/1921027-public-sector-it-internal-audit-risk-senior-consultant](https://www.wearedevelopers.com/jobs/ext/1921027-public-sector-it-internal-audit-risk-senior-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Public Sector IT Internal Audit & Risk Senior Consultant - **Company:** The Baker - **Location:** McLean, VA, United States - **Experience:** Expert - **Salary:** $90,000.0 - $150,360.0 - **Contract:** Permanent contract - **Skills:** Accounting Information Systems, Adobe InDesign, Cyber Security, Computer Engineering, Information Technology Audit, Information Technology Operations, IT General Controls (ITGC), Information Technology, Data Analytics - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d67cc3f5ce100df8 ## About the Role * Bachelor's degree in management/computer information systems, computer science, accounting information systems, computer engineering, industrial engineering, or related program * CISA, CISSP, CISM, CIA, or CPA certifications preferred * 3+ year(s) experience with risk advisory, internal/external audit, business process reengineering, and/or internal controls * 3+ year(s) experience with IT audit or cybersecurity, previous experience performing public sector IT and cybersecurity audits, Virginia Information Technologies Agency (VITA) SEC530 IT security audits/assessments, NIST (e.g., 800-53 and CSF2.0) cybersecurity assessments, third party cybersecurity risk assessments, and SOC audits preferred * Experience as a client serving professional for a consulting firm desired * Knowledge of public sector operations broadly, specific knowledge or experience in a public sector setting - state or local government, public utility, transit, and/or K-12 schools. * Excellent analytical, technical and problem solving skills, with strong attention to detail * Exceptional verbal and written communication, collaboration, and time management skills * Ability to go onsite to the client 2-3 days a week as needed ## Description * You want to continue to expand your work experiences and hone your skills as a comprehensive risk professional in the areas of compliance, enterprise risk management, governance, internal controls, and data analytics. * You crave the opportunity to be part of a fast growing, entrepreneurial risk consulting practice where your hard work and creativity will be rewarded * You do your best work when you are part of a talented, down-to-earth team that thrives in collaboration and truly enjoys working together * You feel valued when you are provided the resources and support to continually sharpen your technical skills and build your career now, for tomorrow What you will do: * Work closely with client executives and management teams to understand their businesses and assist in identifying and managing financial and operational risks within their business processes and systems to ensure technology risks are managed: + Develop in-depth knowledge of clients' operations by having direct client interaction while working on multiple aspects of an engagement + Think independently and strategically about your clients' business processes, systems and risks providing recommendations for process improvements based upon knowledge gained relative to the client's operations, processes and organizational objectives + Provide strategic assurance to clients by assisting in the implementation of new processes and controls that address key risks + Assess, manage and optimize information technology risk across a wide range of areas, including cybersecurity, IT strategy and governance, IT regulatory and compliance requirements, and business continuity + Review clients' processes and controls against industry frameworks, identifying gaps in design and execution, and communicating issues and recommendations to clients + Assist in the development of audit programs and the execution of internal audits and IT control assessments in the areas of: o IT strategy and governance o IT operations, business continuity and disaster recovery o Cybersecurity o Third party risk o ITGC and application controls o SOC reporting o Regulatory and compliance requirements + Assist in drafting comprehensive executive summaries and final reports for delivery to the client, documenting and reviewing engagement work papers in accordance with industry-accepted methodologies + Act as a valued business advisor, build relationships and communicate effectively with the client to provide superior client service + Facilitate professional and effective presentations to internal and external audiences + Continue to develop your knowledge and experience working with a variety of technology environments, platforms, applications and tools/utilities * Demonstrate the desire to continually grow, learn and develop skills and knowledge through external and internal education, training and cross-training opportunities to maximize personal contribution to the organizational goals and ongoing career development * Utilize your entrepreneurial skills to network and build strong relationships internally and externally with clients * Support the growth and development of team members through the Baker Tilly Care and Teach philosophy, helping associates meet their professional goals * Enjoy friendships, social activities and team outings that encourage a work-life balance ## Related Videos - [PySpark - Combining Machine Learning & Big Data](https://www.wearedevelopers.com/videos/44-pyspark-combining-machine-learning-big-data) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [How Data is Shaping our Games](https://www.wearedevelopers.com/videos/176-how-data-is-shaping-our-games) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)