IT Security Audit Manager

vTech Solution Inc
Richmond, VA, United States
9 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$96,500.0 - $110,100.0
Working hours
Regular working hours

Tech stack

VoIP Software as a Service Collaborative Software Cyber Security Information Technology Audit Call Tracing

Job description

The IT Security Audit Manager / Lead Auditor is responsible for leading and managing SEC530 security compliance audits across multiple systems, acting as the primary liaison for internal audit leadership. This role oversees audit planning, execution, evidence review, findings development, and reporting to ensure compliance with relevant standards and regulations. Responsibilities:

  • Develop and maintain project plans, integrated audit schedules, evidence request lists, and system-specific SEC530 audit programs.
  • Serve as the primary client contact, leading entrance conferences, weekly status updates, evidence coordination, findings reviews, and exit conferences.
  • Determine control applicability across 109 system-specific controls, identify controls for scope exclusion, and approve risk-based sampling approaches.
  • Review audit evidence and work papers for completeness, sufficiency, and reliability.
  • Validate access-termination testing for contractor accounts to ensure timeliness.
  • Develop and validate audit findings using the client s risk-rating methodology.
  • Prepare and finalize draft and final audit reports; manage corrective action plan processes.
  • Oversee secure evidence repository management and coordinate reliance on SOC 2 reports for relevant systems.
  • Ensure compliance with SEC530, SEC502, SEC520, NIST SP 800-53, and GAGAS/IIA standards.
  • Manage overall engagement risk, escalation procedures, and change control., * Role requires managing multiple concurrent audits with strict adherence to regulatory standards.
  • Must handle sensitive audit evidence securely using designated repositories.
  • Coordination with various stakeholders and adherence to risk escalation and change management protocols are essential.

Scheduling:

  • Work schedule may involve managing overlapping audit engagements and coordinating with internal and external stakeholders.
  • Flexibility to accommodate audit timelines and reporting deadlines is expected., Senior Staff Auditor, Bank and Support Functions Audit (Hybrid) The Internal Audit function within Capital One is a dedicated group of audit professionals focused on delivering t…
  • 1 month ago, Job Summary: The Senior IT Security Auditor / Technical Security SME is responsible for performing hands-on security control testing and technical evidence analysis across Lanswe…
  • 15 hours ago
  • Apply easily +

Requirements

  • 10+ years of experience in IT audit, cybersecurity assurance, technology risk, or compliance.
  • 5+ years of experience leading IT security or system compliance audits, including fixed-price deliverable-based engagements.
  • Demonstrated knowledge of SEC530, SEC502, and/or SEC520 standards.
  • Experience with NIST SP 800-53 control assessments and vendor-managed/shared-responsibility controls (SOC 2 reliance).
  • Proficiency in preparing audit programs, work papers, findings, corrective action plans, and final reports for government or regulated clients.
  • Understanding of GAGAS or IIA Global Internal Audit Standards.
  • Strong project, schedule, risk, and stakeholder management skills across concurrent audits.
  • Experience with third-party and SaaS risk assessment including SOC 2 evaluations.

Preferred Skills & Certifications:

  • Experience auditing asset management/ITSM platforms, SaaS collaboration tools, or VoIP/call-recording systems.
  • CISA or CISSP certification preferred but not required.
  • PMP certification is desirable.
  • CIA or CRISC certification is desirable.

Benefits & conditions

  • $96,500-110,100 per year

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:26 min

Spear phishing IT administrators with malicious VoIP spoofing

Mauro Verderosa · LIVE

1:30 min

Integrating automated security and vulnerability scanning

Alexandra Petri · World Congress 2023

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:16 min

Tracing process generation with kernel probe system calls

Ozan Sazak Ozan Sazak · World Congress 2024

5:13 min

Audience Q&A on maturity assessments and external consultants

Mathias Tausig · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all