Information Systems Auditor (CISA Preferred) - Secret Clearance

LaunchCode
St. Louis, MO, United States
5 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$100,000.0 - $150,000.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Amazon Web Services Microsoft Antivirus Microsoft Azure Backup Devices Cloud Computing Configuration Management Control Objectives for Information and Related Technology (COBIT) Cyber Security Information Systems Information Technology Consulting Databases
+23 more
Disaster Recovery Identity and Access Management Information Technology Audit Python (Programming Language) Oracle (Applications) PCI Data Security Standards Windows PowerShell Power BI Azure Active Directory SAP (Applications) SQL Databases Software Vulnerability Management Data Logging Enterprise Software Applications Cloud Platform System IT General Controls (ITGC) Microsoft InTune SC Clearance Information Technology Data Analytics Microsoft Sentinel Workday Servicenow

Job description

Our partner is seeking an Information Systems Auditor to evaluate information technology controls, cybersecurity safeguards, governance processes, and enterprise risk management programs supporting Defense sector clients. The successful candidate will lead a team in performing risk-based IT audits, assessing IT General Controls (ITGCs), application controls, cybersecurity controls, and technology risks, while providing recommendations to strengthen security, compliance, and operational efficiency. This role combines information systems auditing, cybersecurity, data analytics, and emerging technologies while working closely with IT, cybersecurity, finance, business, and audit teams. The ideal candidate has strong experience in IT audit and risk management, excellent communication skills, and the ability to lead audit engagements and mentor junior staff.

Position Responsibilities:

  • Lead a team of junior staff and ensure completion of technical and functional deliverables.
  • Plan, execute, and document risk-based information systems audits.
  • Evaluate IT General Controls (ITGCs), application controls, and automated business processes.
  • Assess cybersecurity, identity and access management, and data protection controls.
  • Perform technology risk assessments and identify control gaps, vulnerabilities, and compliance risks.
  • Conduct testing of security, operational, and financial system controls.
  • Develop audit workpapers, findings, recommendations, and executive-level reports.
  • Validate corrective actions and monitor remediation efforts through completion.
  • Support compliance with NIST, COBIT, ISO 27001, FISMA, CMMC, SOX, FedRAMP, and other regulatory frameworks.
  • Participate in internal and external audits, assessments, and regulatory examinations.
  • Evaluate cloud environments, enterprise applications, databases, and infrastructure security controls.
  • Assess change management, configuration management, backup, disaster recovery, and business continuity processes.
  • Review logging, monitoring, incident response, vulnerability management, and privileged access management practices.
  • Analyze technology risks associated with cloud computing, automation, artificial intelligence, and other emerging technologies.
  • Collaborate with cybersecurity, engineering, finance, and business stakeholders to improve governance and internal controls.
  • Identify opportunities to improve audit methodologies, automate testing procedures, and enhance operational efficiency.
  • Stay current on evolving cybersecurity threats, regulatory requirements, and industry best practices.

Requirements

  • CISA certification.
  • 10+ years of experience in IT audit, information security, cybersecurity, risk management, internal audit, or technology consulting.
  • Bachelor’s degree in Information Systems, Computer Science, Cybersecurity, Accounting, Information Technology, or a related discipline.
  • U.S. Citizenship with an active Secret Clearance.
  • Experience performing IT General Controls (ITGC) testing and technology risk assessments.
  • Knowledge of NIST Cybersecurity Framework, NIST SP 800-53, NIST SP 800-171, COBIT, COSO, and FISCAM.
  • Experience evaluating identity and access management, change management, logical access, backup and recovery, and configuration management controls.
  • Strong understanding of cybersecurity principles, security controls, and enterprise risk management.
  • Experience developing audit reports, documenting findings, and communicating recommendations to stakeholders.
  • Excellent analytical, problem-solving, organizational, and written communication skills.
  • Ability to manage multiple projects and work independently in a fast-paced environment.

Desired Skills/Experience:

  • Experience supporting federal civilian, Department of War, or Intelligence Community clients.
  • Knowledge of FISMA, FedRAMP, RMF, CMMC 2.0, GAO Green Book, and OMB Circular A-123.
  • Experience with cloud platforms such as Microsoft Azure, AWS, or GCP.
  • Familiarity with Microsoft Defender, Microsoft Sentinel, Microsoft Entra ID, Microsoft Intune, ServiceNow, SAP, Oracle, or Workday.
  • Experience with data analytics, SQL, Power BI, Python, PowerShell, or audit automation tools.
  • Professional certifications such as CISSP, CISM, CRISC, CIA, CPA, CGFM, Security+, or PMP.
  • Experience supporting SOC 1, SOC 2, ISO 27001, PCI DSS, HIPAA, or SOX compliance initiatives.
  • Experience leading audit engagements, mentoring junior staff, and presenting to executive leadership.
  • Strong consulting, stakeholder management, and client relationship skills.

Benefits & conditions

  • Healthcare - Health, Vision, and Dental Plans are available for employees and their families.
  • Retirement Plan - Competitive 401(k) plan with 100% matching on employee contributions up to the first 6%, with access to Vanguard Admiral funds.
  • Paid Time Off - Generous paid leave based on length of service.
  • Bonus System - Bonuses are available to employees who meet and exceed goals throughout the year.
  • Professional Development - Support for career growth through training programs and certifications.
  • Company Retreats & Team Events - Sponsored trips, team-building activities, and annual conferences related to your skillset.

About the company

Company: The name of our partner organization will be disclosed during the interview process. This is not a direct role with LaunchCode; it is a position through LaunchCode, working with one of our partner companies.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

6:22 min

Eliminating HR bureaucracy and trusting employees

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

1:24 min

Moving the semantic layer upstream to avoid vendor lock-in

Piotr Menclewicz Piotr Menclewicz · Europe 2026 Virtual

1:44 min

Coordinating security mitigations with the CISA clearinghouse

Adrian Mouat Adrian Mouat · World Congress 2026 Europe

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all