> Markdown version of [/jobs/ext/2249116-practice-manager-it-auditing](https://www.wearedevelopers.com/jobs/ext/2249116-practice-manager-it-auditing). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Practice Manager / IT Auditing - **Company:** VACO LLC - **Location:** St. Petersburg, FL, United States - **Experience:** Starter - **Salary:** $98,500.0 - $120,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Information Technology Audit, Systems Development Life Cycle - **Published:** August 26, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18073399?backUrl=%2Fcareer%2F18073399%2FPractice-Manager-It-Auditing-Florida-St-Petersburg ## About the Role * Bachelor's in MIS, Cybersecurity, Accounting, Finance, or related field. At least one of: CPA, CISA, or CISSP. 4+ years in cybersecurity compliance, security assessment, or architecture design/review * 2+ years of professional services experience at the senior level; 1-3 years of supervisory/management experience * Executive presence, strong writing and technical skills, and proven ability to mentor others * Track record of delivering engagements on time and on budget Preferred Qualifications: MBA or MS * Willingness to pursue additional certifications (CISM, ISO 27001 LA, PCI QSA, HITRUST CCSFP, etc.) * Working knowledge of multiple security frameworks, application controls, and the SDLC; entrepreneurial, client-centric mindset; works well independently and on teams * Extensive completed engagement history (25+ professional services projects preferred) ## Description Full-time, client-facing leadership role with a growing cybersecurity professional services practice. Overtime may be required to meet client deliverables. This person will lead security and compliance assessment engagements, manage project teams, and contribute to overall practice management. One of the following credentials is required: CISA, CISSP, or CPA. What You'll Do * Lead projects, teams, and client relationships across compliance and assessment engagements (SOC reporting, PCI, HIPAA, ISO 27001, NIST 800-53/171, HITRUST, vendor privacy assurance, GDPR, and other risk-based work) * Plan, execute, and close cybersecurity assessment and compliance projects tailored to each engagement's scope * Own a book of business with multiple concurrent projects, including scheduling and administration * Draft and review audit reports describing procedures performed, testing results, control weaknesses, and risk exposure * Document and test client information systems; recommend improvements to technology and infrastructure * Verify that applications, infrastructure, and controls operate as intended. Perform risk-based integrated reviews of financial, operational, systems, and management controls. Build and maintain strong client and team relationships; support retention on both sides. Coach, train, and develop junior staff; foster a collaborative team environment * Perform detailed reviews of workpapers, reports, and proposals to ensure quality deliverables * Execute hands-on technical work in complex areas when needed. Travel to client sites as needed ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Fireside Chat: AI and Sustainability - Thorsten Jonas](https://www.wearedevelopers.com/videos/1769-fireside-chat-ai-and-sustainability-thorsten-jonas) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How to Write a CV and Interview if You Don't Fully Qualify For The Job](https://www.wearedevelopers.com/magazine/183-how-to-write-a-cv-and-interview-if-you-don-t-fully-qualify-for-the-job)