IT Audit Liaison

TECHNOVISION INC
Harrisburg, PA, United States
26 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Cloud Computing Cyber Security Information Systems Information Security Management Information Technology Audit IT Management Information Technology

Job description

Our direct client is looking for an IT Audit Liaison for a Hybrid (3 Days/Week) Long Term Contract in Harrisburg, PA, Under the direction of the IT Governance, Risk and Compliance Manager, this position serves as an IT Audit Liaison within the Enterprise Information Security Office (EISO), supporting the Commonwealth’’’’’’'’s Governance, Risk, and Compliance (GRC) Department.

  • The GRC function provides governance, risk evaluation, and compliance oversight to support informed decision-making and the responsible adoption of technology across the Commonwealth.
  • The IT Audit Liaison provides technical audit and compliance support for the organization’’’’’’'’s Governance, Risk, and Compliance (GRC) program.
  • The employee participates in internal and external audit activities, evaluates the effectiveness of information technology controls, identifies compliance gaps, and supports remediation efforts to strengthen the organization’’’’’’'’s cybersecurity and regulatory compliance posture.

Description of Major Duties:

  • Coordinates and supports information technology audits conducted by internal and external oversight organizations, including GAAP/Single Audit, the Pennsylvania Auditor General, Attorney General, Bureau of Audits, and other regulatory entities.
  • Reviews documentation and technical evidence to determine compliance with applicable laws, regulations, policies, and security standards.
  • Evaluates information security and technology controls against established frameworks, including NIST Cybersecurity Framework (CSF), NIST Special Publication 800-53, ISO 27001, and Commonwealth security policies.
  • Identifies control deficiencies, documents findings, and recommends corrective actions to reduce organizational risk.
  • Assists business and technical stakeholders in preparing audit responses and collecting supporting evidence.
  • Tracks audit findings, validates corrective actions and reports remediation status and residual risk to management.
  • Supports development and maintenance of automated workstreams for audit management, compliance tracking, and evidence collection.
  • Develops dashboards, metrics and executive reports regarding audit trends, compliance posture and remediation progress.
  • Performs risk-based assessments to prioritize audit activities and evaluate control effectiveness.
  • Assists in developing audit procedures, compliance documentation, metrics, and management reports.
  • Participates in continuous improvement initiatives related to governance, risk management, and internal controls.
  • Performs related work as assigned., Evaluates information security and technology controls against established frameworks, including NIST Cybersecurity Framework (CSF), NIST Special Pu - Required
  • Identifies control deficiencies, documents findings, and recommends corrective actions to reduce organizational risk - Required
  • Assists business and technical stakeholders in preparing audit responses and collecting supporting evidence - Required
  • Tracks audit findings, validates corrective actions and reports remediation status and residual risk to management - Required
  • Supports development and maintenance of automated workstreams for audit management, compliance tracking, and evidence collection - Required
  • Develops dashboards, metrics and executive reports regarding audit trends, compliance posture and remediation progress - Required
  • Performs risk-based assessments to prioritize audit activities and evaluate control effectiveness - Required
  • Reviews documentation and technical evidence to determine compliance with applicable laws, regulations, policies, and security standards - Required
  • Cybersecurity governance and risk management - Strong Plus to have
  • NIST CSF, NIST 800-53, ISO 27001, and related frameworks - Strong Plus to have

Question 1: All consultants are prohibited from taking or using government-issued equipment outside the United States. Violation of this policy may result in serious consequences, as the equipment is government property. Do you understand and agree to abide by this provision? Question 2: This is a Hybrid (3 Days/Week Onsite) position. Are you fine with this?

Requirements

Information technology auditing principles and practices

  • Cybersecurity governance and risk management
  • Internal controls and compliance concepts
  • NIST CSF, NIST 800-53, ISO 27001, and related frameworks
  • IT infrastructure, applications, cloud technologies, and security controls

Ability to:

  • Analyze technical and audit documentation
  • Evaluate compliance with policies and standards
  • Prepare clear reports and recommendations
  • Communicate effectively with technical and non-technical staff
  • Organize multiple audit activities simultaneously

Preferred Qualifications:

  • Professional certification such as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manager (CISM) or equivalent
  • Experience supporting IT audits, regulatory examinations or compliance assessments

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah · World Congress 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

2:43 min

Auditing third-party technical quality and team skill profiles

Loïc Carbonne Loïc Carbonne · World Congress 2024

5:00 min

Managing complex state with scope-based resource management

Bjarne Stroustrup · World Congress 2022

Videos

See all

Related articles

See all