Cyber Security Audit Engineer

The Timberline Group
St. Louis, MO, United States
3 days ago
Apply on www.careerbuilder.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Data Analysis User Authentication Cloud Computing Cloud Computing Security Control Objectives for Information and Related Technology (COBIT) CompTIA Security+ Cyber Security Information Systems Computer Networks Databases
+29 more
Data Security Linux Disaster Recovery Identity and Access Management Information Technology Audit Networking Hardware Internet Security Intrusion Detection Systems Information Systems Security Architecture Professional Information Technology Security Auditing Security Information and Event Management Software Engineering Network Routers Scripting Data Classification In-Plane Switching (IPS) IT General Controls (ITGC) Malware Firewalls (Computer Science) Information Technology Nessus Malware Detection Data Management Cyber Warfare Network Server Cisco Qualys Vulnerability Analysis Programming Languages

Job description

  • The Cyber Security Audit Engineer will manage a variety of technical security auditing capabilities, including a holistic auditing approach of applications, databases, servers, networking devices, and software. Responsible for demonstrating skills in assessing IT process and technology risks, identifying and evaluating the design of IT controls, designing, executing and documenting IT audit tests, and making initial determination of reportable issues. Assist with HIPAA / HITECH assessments, and data breach preparedness. Will work in close coordination with team members and other business owner’s partners to carry our customer requirements.* ROLES and RESPONSIBILITIES:

  • Design, build, implement and monitor a holistic audit program across the enterprise.
  • Develop understanding of appropriate business aspects, IT risks, IT control requirements, processes and systems under review.
  • Perform process and technology risk analysis with a cybersecurity mindset and focus, prepare process maps and flowcharts, prepare effective and efficient compliance and substantive technical approach; and execute in depth IT audit review.
  • Perform assessment of IT process and security controls within information systems environment.
  • Evaluate test results: accurately identify symptoms, root cause, problems, identify alternative controls and develop recommendations.
  • Perform audit reviews of technology such as applications, databases, servers, networking devices (i.e., firewalls and routers), and security tools such as IDS/IPS, anti-malware, and authentication systems (e.g., Active Directory).
  • Performing technology assessments in a wide variety of business environments, including:
  • Information Technology Operational and Cyber Security Assessments in accordance with industry frameworks, such as COBIT 5, ISO 27001, ISO 27005, and NIST SP 800-30 and Cybersecurity Framework
  • HIPAA Security Rule and HITECH Act Compliance
  • Cloud Security Compliance
  • Assisting clients with the performance of Business Impact Analyses (BIAs) along with the development of business continuity and disaster recovery plans (BCPs and DRPs);
  • Assisting organizations with all aspects of data breach and information security Incident Response preparation and management
  • Performing Service Organization Control Examinations in accordance with AICPA requirements (SOC 1 SSAE 16, SOC 2 AT 101, SOC 3 AT 101)
  • Providing data classification services
  • Developing information technology and security policies and procedures
  • Providing trusted advisory services and guidance to clients that will reduce organizational risk and improve their overall cyber security posture
  • Preparing reports and other deliverables that contain strategy, technical analysis, and findings in connection with our advisory and assessment engagements and communicating those results to client management
  • Excellent technical and interpersonal skills required.
  • Experience with Qualys / Nessus Vulnerability scanning tools.
  • Cloud Experience a plus

Requirements

  • Minimum of 5 of experience with Enterprise Network, DMZ, and Security infrastructure, including design, implementation, and ongoing management and troubleshooting required.
  • Minimum of 5 years’ experience in designing, developing, implementing, and managing solutions across cybersecurity domains (Cyber Defense, Threat and Vulnerability Management. Advanced Security Analytics, Data Security, Identity Management, Security Operations and Managed Security Services etc.)
  • Three years or more of professional experience or job-related experience in Information Security, or Information Technology
  • Extensive knowledge and skill of IT analysis which includes expertise in analyzing confidentiality, integrity, availability of complex IT systems.
  • Familiarity with Secure Software Development practices
  • Hands On experience with various programming languages or scripting languages and tools.
  • Effective oral and written communication skills.
  • Strong interpersonal skills and demonstrable leadership ability.
  • Certifications in one or more of the following: CISSP, CWSP, CCNP, ACE, CCNP Security, Security+, or related.
  • Familiarity with various operating system platforms (Linux, Windows) and databases security best practices for each.
  • Strong analytical and problem-solving ability.
  • Ability to work independently., American Institute of Certified Public Accountants (AICPA), Analysis Skills, Auditing, Authentication, Best Practices, Business Development, Business impact analysis (BIA), CCNP - Cisco Certified Network Professional, CISSP - Certified Information Systems Security Professional, Cloud Computing, Communication Skills, CompTIA Security+, Computer Security, Control Objectives for Information and related Technology (COBIT), Customer Support/Service, DMZ, Design Evaluation, Disaster Recovery, Documentation, Firewalls, HIPAA (Health Insurance Portability and Accountability Act), ISO (International Organization for Standardization), IT Requirements, Identify Issues, Identity Data Management, Incident Response, Information Technology & Information Systems, Information Technology/Systems Audit, Information/Data Security (InfoSec), Internet Security, Interpersonal Skills, Intrusion Detection Systems, Intrusion Prevention Systems, Leadership, Linux Operating System, Malware, Microsoft Active Directory, Microsoft Windows Operating System, Nessus, Network Routers, Network Software, Operating Systems, Operations Security (OPSEC), Presentation/Verbal Skills, Problem Solving Skills, Process Analysis, Protective Services, Reporting Skills, Risk Analysis, Risk Management, Root Cause Analysis, Sales Management, Scripting (Scripting Languages), Security Analysis, Security Attacks, Security Auditing, Security Compliance, Security Information and Event Management (SIEM), Security Infrastructure, Security Monitoring, Software Development, Strategic Analysis, Technical Analysis, Technology Analysis, Test Plan/Schedule, Testing, U.S. National Institute of Standards and Technology (NIST), Vulnerability Scanners, Writing Skills

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:45 min

Prototyping deterministic agents with n8n and PyATS

Alfonso Sandoval Rosas Alfonso Sandoval Rosas · Europe 2026 Virtual

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all