Senior IT Security Auditor
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
The Senior IT Security Auditor / Engagement Lead is responsible for leading and executing IT security audits for multiple systems within the Virginia Department of Professional and Occupational Regulation (DPOR). This role involves planning, conducting, documenting, and reporting audits in compliance with Commonwealth of Virginia standards and Generally Accepted Government Auditing Standards (GAGAS). The position combines hands-on auditing with engagement management, ensuring thorough assessment and compliance of IT security controls across DPOR systems. Responsibilities:
- Serve as primary contact for DPOR stakeholders including Information Security Officer and IT Director.
- Develop and maintain comprehensive project plans, audit schedules, milestones, and status reports.
- Conduct IT security audits in accordance with GAGAS, SEC530-01.2, and SEC502-05 standards.
- Create and maintain audit programs for EAGLES, ETS, and IRIS systems.
- Assess system-specific SEC530 controls and maintain traceability between requirements, procedures, evidence, and findings.
- Prepare and manage audit evidence requests and coordinate follow-ups.
- Review relevant documentation including security plans, risk assessments, policies, and prior audits.
- Evaluate shared and inherited controls involving third-party service providers.
- Document compliance conclusions, control deficiencies, and audit findings with clear rationale and recommendations.
- Prepare draft and final audit reports for each system and facilitate management discussions.
- Lead entrance and exit conferences with DPOR management.
- Deliver complete audit workpapers and maintain confidentiality within authorized environments.
- Escalate risks related to evidence, schedule, scope, or independence as necessary., * One dedicated Senior IT Security Auditor / Engagement Lead resource required; offshore resources are prohibited.
- Work primarily performed remotely within the continental United States (CONUS).
- Must attend entrance and exit conferences at DPOR’s Henrico, Virginia office unless otherwise agreed.
- Must satisfy background check and security requirements.
- Maintain audit independence throughout the engagement.
- Audit evidence must remain within DPOR-authorized environments; no storage in unauthorized repositories.
- No requirement for penetration testing, vulnerability scanning, source-code review, or automated security testing; auditor assesses DPOR-provided evidence only.
Scheduling:
- Work schedule aligned with project milestones and audit timelines.
- Availability required for scheduled entrance and exit conferences at DPOR facilities.
- Typical remote work with occasional on-site meetings as mutually agreed., Sr. IT Auditor 12 months contract with high potential to extend and convert Hybrid in Richmond, VA Role Overview: We are seeking a skilled Auditor to execute risk-based audits…
- 2 months ago
- Apply easily, Senior Staff Auditor, Bank and Support Functions Audit (Hybrid) The Internal Audit function within Capital One is a dedicated group of audit professionals focused on delivering t…
- 10 days ago
Requirements
- Bachelor’s degree in Information Systems, Cybersecurity, Computer Science, IT, Accounting, Auditing, Business Administration, Risk Management, or equivalent experience.
- Minimum five years of direct IT audit, cybersecurity audit, or information security compliance experience.
- Demonstrated experience performing or leading audits under GAGAS/Yellow Book standards.
- Experience with audit planning, control testing, evidence evaluation, and report writing.
- Knowledge of NIST-based security controls or comparable government frameworks.
- Strong skills in stakeholder communication and independent management of audit workstreams.
- Certified Information Systems Auditor (CISA) or equivalent professional certification.
Preferred Skills & Certifications:
- Seven or more years of overall relevant IT audit, cybersecurity, risk, or compliance experience.
- Certified Information Security Manager (CISM), Certified Internal Auditor (CIA), Certified in Risk and Information Systems Control (CRISC), Certified Information Systems Security Professional (CISSP), or Certified Public Accountant (CPA).
- Experience with Commonwealth of Virginia IT audit standards SEC530 and SEC502.
- Prior IT security audit experience with Virginia state agencies or other U.S. state-government entities.
- Experience auditing sensitive government information systems and interpreting government IT compliance requirements.
Benefits & conditions
- $96,500-110,100 per year
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How to Find Tech Jobs in Vienna
IT Salaries in UK
Best Paying Jobs in Technology
How should you format your IT resume?