IT Security Auditor

Infojini Inc
United States
25 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours
Job source

Tech stack

Software Documentation Cyber Security Information Security Management Verification and Validation (Software) Information Technology Crosswalk Vulnerability Analysis

Job description

BACKGROUND: The Information Security & Privacy Branch of the Division of Information Technology propose to engage two to three contractors to provide compliance and information security support to in preparation for annual FISMA audits, provide support in conducting an independent verification and validation of current policies and procedures, and assist with remediation of process improvements. This will also include assisting with ongoing IV&V assessments and audit support., * Participates in the process to evaluate, develop, maintain, and update the technology compliance program. Advises the technology support officer and technology managers on compliance, information security, and internal controls.

  • Prepares the technology departments for the yearly FISMA audits.
  • Assist in developing required documents in support of internal FISMA reviews.
  • Develop solutions with team members to minimize vulnerabilities.
  • Advises the technology officer of compliance issues and recommends solutions
  • Provides a weekly status report to the COR documenting concerns, issues, risks, and progress.
  • Recommends and helps implement automated solutions in the areas of compliance, auditing, and vulnerability detection for the branch.
  • Designs, tests, and implements audit mechanisms to detect non-compliance and to support evaluations of evidentiary materials. Ensures proper audit trails are recorded.
  • Creates audit and monitoring reports used by the team, as directed.

The External Auditor Consultant shall deliver, but not limited to, the following:

  • Thoroughly assess and validate the audit findings for identified systems of record against Board policies. Document findings and recommendations.
  • Crosswalk the evidence and latest Board Information Security Program (BISP) against the CISA and FedRamp standards and procedures and document the results.
  • Provide recommendations, develop action plans, and help implement capabilities to improve compliance and security practices.
  • Document updates to compliance related policies, processes, procedures, and/or standards as directed.

Requirements

  • Experience with cloud and on-premis applications desirable.
  • Simultaneously works on several complex assignments requiring analysis of intricately related complex variables.
  • Experience with leading and successfully developing audit and security related system documentation and requirements desired.
  • Must have at least ten years of progressively responsible experience in the information technology arena as an IT auditor, IT security analyst, IT manager, business analyst, system administrator or a combination of these.
  • Possess clear, concise, and effective verbal and written communication and project management skills needed for functioning in an unstructured matrix management environment.
  • Experience with assessing financial systems leveraging NIST 800 series, or FISMA Compliance strongly desired.
  • CISSP or CISA certification strongly desired.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

Integrating automated security and vulnerability scanning

Alexandra Petri · World Congress 2023

1:58 min

Measuring productivity gains from agent-assisted code refactoring

Dr. Alexander Wachtel Dr. Alexander Wachtel +1 · World Congress 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:32 min

The danger of unverified assumptions in critical systems

Luís Ventura Luís Ventura · World Congress 2024

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all