IT Audit Liaison

vTech Solution Inc
Harrisburg, PA, United States
8 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$83,000.0 - $111,000.0
Working hours
Regular working hours

Tech stack

Cyber Security Information Security Management Information Technology Audit IT Management

Job description

The OA-EISO-Audit Liaison serves as a critical support role within the Enterprise Information Security Office (EISO), assisting the Commonwealth’s Governance, Risk, and Compliance (GRC) Department. Reporting to the IT Governance, Risk and Compliance Manager, this position facilitates IT audit coordination, evaluates information security controls, identifies compliance gaps, and supports remediation efforts to enhance cybersecurity and regulatory compliance. Responsibilities:

  • Coordinate and support IT audits conducted by internal and external oversight entities, including state auditors and regulatory bodies.
  • Review documentation and technical evidence to assess compliance with laws, regulations, policies, and security standards.
  • Evaluate information security and technology controls against frameworks such as NIST CSF, NIST SP 800-53, ISO 27001, and Commonwealth security policies.
  • Identify control deficiencies, document findings, and recommend corrective actions to mitigate risks.
  • Assist stakeholders in preparing audit responses and gathering supporting evidence.
  • Track audit findings, validate corrective actions, and report remediation status and residual risk to management.
  • Support the development and maintenance of automated workflows for audit management, compliance tracking, and evidence collection.
  • Create dashboards, metrics, and executive reports on audit trends, compliance posture, and remediation progress.
  • Perform risk-based assessments to prioritize audit activities and evaluate control effectiveness.
  • Assist in developing audit procedures, compliance documentation, metrics, and management reports.
  • Participate in continuous improvement initiatives related to governance, risk management, and internal controls.

Requirements

  • Knowledge of IT auditing principles and practices.
  • Experience evaluating information security and technology controls against established frameworks.
  • Ability to analyze technical and audit documentation and evaluate compliance with policies and standards.
  • Strong report writing and communication skills for technical and non-technical audiences.
  • Experience tracking audit findings and managing remediation efforts.
  • Ability to support audit management automation and develop compliance metrics and reports.

Preferred Skills & Certifications:

  • Familiarity with cybersecurity governance and risk management.
  • Knowledge of NIST CSF, NIST SP 800-53, ISO 27001, and related security frameworks.
  • Professional certifications such as CISA, CRISC, CISM, or equivalent.
  • Experience supporting IT audits, regulatory examinations, or compliance assessments.

Special Considerations:

  • Strict prohibition on taking or using government equipment outside of the United States.
  • Non-compliance with equipment use policy results in immediate termination and ineligibility for rehire.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:14 min

Establishing legal admissibility through immutable blockchain attestations

Frederik Gregaard Frederik Gregaard +1 · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah · World Congress 2025

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:43 min

Auditing third-party technical quality and team skill profiles

Loïc Carbonne Loïc Carbonne · World Congress 2024

Videos

See all

Related articles

See all