Senior IT Security Auditor

vTech Solution Inc
Richmond, VA, United States
5 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$96,500.0 - $110,100.0
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Cyber Security Information Systems Information Technology Audit Information Systems Security Architecture Professional Information Technology Vulnerability Analysis

Job description

The Senior IT Security Auditor / Engagement Lead is responsible for leading and executing IT security audits for multiple systems within the Virginia Department of Professional and Occupational Regulation (DPOR). This role involves planning, conducting, documenting, and reporting audits in compliance with Commonwealth of Virginia standards and Generally Accepted Government Auditing Standards (GAGAS). The position combines hands-on auditing with engagement management, ensuring thorough assessment and compliance of IT security controls across DPOR systems. Responsibilities:

  • Serve as primary contact for DPOR stakeholders including Information Security Officer and IT Director.
  • Develop and maintain comprehensive project plans, audit schedules, milestones, and status reports.
  • Conduct IT security audits in accordance with GAGAS, SEC530-01.2, and SEC502-05 standards.
  • Create and maintain audit programs for EAGLES, ETS, and IRIS systems.
  • Assess system-specific SEC530 controls and maintain traceability between requirements, procedures, evidence, and findings.
  • Prepare and manage audit evidence requests and coordinate follow-ups.
  • Review relevant documentation including security plans, risk assessments, policies, and prior audits.
  • Evaluate shared and inherited controls involving third-party service providers.
  • Document compliance conclusions, control deficiencies, and audit findings with clear rationale and recommendations.
  • Prepare draft and final audit reports for each system and facilitate management discussions.
  • Lead entrance and exit conferences with DPOR management.
  • Deliver complete audit workpapers and maintain confidentiality within authorized environments.
  • Escalate risks related to evidence, schedule, scope, or independence as necessary., * One dedicated Senior IT Security Auditor / Engagement Lead resource required; offshore resources are prohibited.
  • Work primarily performed remotely within the continental United States (CONUS).
  • Must attend entrance and exit conferences at DPOR’s Henrico, Virginia office unless otherwise agreed.
  • Must satisfy background check and security requirements.
  • Maintain audit independence throughout the engagement.
  • Audit evidence must remain within DPOR-authorized environments; no storage in unauthorized repositories.
  • No requirement for penetration testing, vulnerability scanning, source-code review, or automated security testing; auditor assesses DPOR-provided evidence only.

Scheduling:

  • Work schedule aligned with project milestones and audit timelines.
  • Availability required for scheduled entrance and exit conferences at DPOR facilities.
  • Typical remote work with occasional on-site meetings as mutually agreed., Sr. IT Auditor 12 months contract with high potential to extend and convert Hybrid in Richmond, VA Role Overview: We are seeking a skilled Auditor to execute risk-based audits…
  • 2 months ago
  • Apply easily, Senior Staff Auditor, Bank and Support Functions Audit (Hybrid) The Internal Audit function within Capital One is a dedicated group of audit professionals focused on delivering t…
  • 10 days ago

Requirements

  • Bachelor’s degree in Information Systems, Cybersecurity, Computer Science, IT, Accounting, Auditing, Business Administration, Risk Management, or equivalent experience.
  • Minimum five years of direct IT audit, cybersecurity audit, or information security compliance experience.
  • Demonstrated experience performing or leading audits under GAGAS/Yellow Book standards.
  • Experience with audit planning, control testing, evidence evaluation, and report writing.
  • Knowledge of NIST-based security controls or comparable government frameworks.
  • Strong skills in stakeholder communication and independent management of audit workstreams.
  • Certified Information Systems Auditor (CISA) or equivalent professional certification.

Preferred Skills & Certifications:

  • Seven or more years of overall relevant IT audit, cybersecurity, risk, or compliance experience.
  • Certified Information Security Manager (CISM), Certified Internal Auditor (CIA), Certified in Risk and Information Systems Control (CRISC), Certified Information Systems Security Professional (CISSP), or Certified Public Accountant (CPA).
  • Experience with Commonwealth of Virginia IT audit standards SEC530 and SEC502.
  • Prior IT security audit experience with Virginia state agencies or other U.S. state-government entities.
  • Experience auditing sensitive government information systems and interpreting government IT compliance requirements.

Benefits & conditions

  • $96,500-110,100 per year

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:30 min

Integrating automated security and vulnerability scanning

Alexandra Petri · World Congress 2023

2:46 min

Missing equipment retrieval processes for departing employees

Jasmin Azemović Jasmin Azemović · World Congress 2026 Europe

2:28 min

Preventing sensitive information disclosure in RAG systems

Deepu Deepu · World Congress 2025

Videos

See all

Related articles

See all