> Markdown version of [/jobs/ext/3073770-it-security-audit-manager](https://www.wearedevelopers.com/jobs/ext/3073770-it-security-audit-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Audit Manager - **Company:** vTech Solution Inc - **Location:** Richmond, VA, United States - **Experience:** Expert - **Salary:** $96,500.0 - $110,100.0 - **Contract:** Permanent contract - **Skills:** VoIP, Software as a Service, Collaborative Software, Cyber Security, Information Technology Audit, Call Tracing - **Published:** September 25, 2026 - **Apply:** https://www.careerjet.com/jobad/us883be75bc1e3c5dc0fc0f9f550e2fe47 ## About the Role * 10+ years of experience in IT audit, cybersecurity assurance, technology risk, or compliance. * 5+ years of experience leading IT security or system compliance audits, including fixed-price deliverable-based engagements. * Demonstrated knowledge of SEC530, SEC502, and/or SEC520 standards. * Experience with NIST SP 800-53 control assessments and vendor-managed/shared-responsibility controls (SOC 2 reliance). * Proficiency in preparing audit programs, work papers, findings, corrective action plans, and final reports for government or regulated clients. * Understanding of GAGAS or IIA Global Internal Audit Standards. * Strong project, schedule, risk, and stakeholder management skills across concurrent audits. * Experience with third-party and SaaS risk assessment including SOC 2 evaluations. Preferred Skills & Certifications: * Experience auditing asset management/ITSM platforms, SaaS collaboration tools, or VoIP/call-recording systems. * CISA or CISSP certification preferred but not required. * PMP certification is desirable. * CIA or CRISC certification is desirable. ## Description The IT Security Audit Manager / Lead Auditor is responsible for leading and managing SEC530 security compliance audits across multiple systems, acting as the primary liaison for internal audit leadership. This role oversees audit planning, execution, evidence review, findings development, and reporting to ensure compliance with relevant standards and regulations. Responsibilities: * Develop and maintain project plans, integrated audit schedules, evidence request lists, and system-specific SEC530 audit programs. * Serve as the primary client contact, leading entrance conferences, weekly status updates, evidence coordination, findings reviews, and exit conferences. * Determine control applicability across 109 system-specific controls, identify controls for scope exclusion, and approve risk-based sampling approaches. * Review audit evidence and work papers for completeness, sufficiency, and reliability. * Validate access-termination testing for contractor accounts to ensure timeliness. * Develop and validate audit findings using the client s risk-rating methodology. * Prepare and finalize draft and final audit reports; manage corrective action plan processes. * Oversee secure evidence repository management and coordinate reliance on SOC 2 reports for relevant systems. * Ensure compliance with SEC530, SEC502, SEC520, NIST SP 800-53, and GAGAS/IIA standards. * Manage overall engagement risk, escalation procedures, and change control., * Role requires managing multiple concurrent audits with strict adherence to regulatory standards. * Must handle sensitive audit evidence securely using designated repositories. * Coordination with various stakeholders and adherence to risk escalation and change management protocols are essential. Scheduling: * Work schedule may involve managing overlapping audit engagements and coordinating with internal and external stakeholders. * Flexibility to accommodate audit timelines and reporting deadlines is expected., Senior Staff Auditor, Bank and Support Functions Audit (Hybrid) The Internal Audit function within Capital One is a dedicated group of audit professionals focused on delivering t… + 1 month ago, Job Summary: The Senior IT Security Auditor / Technical Security SME is responsible for performing hands-on security control testing and technical evidence analysis across Lanswe… + 15 hours ago + Apply easily + ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [WeAreDevelopers LIVE - Playing in Production](https://www.wearedevelopers.com/videos/100363-wearedevelopers-live-playing-in-production) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Synthetic Insiders: The New AI Risk to Your Org](https://www.wearedevelopers.com/videos/100057-synthetic-insiders-the-new-ai-risk-to-your-org) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How to Find Tech Jobs in Vienna](https://www.wearedevelopers.com/magazine/292-how-to-find-tech-jobs-in-vienna) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How should you format your IT resume?](https://www.wearedevelopers.com/magazine/68-how-should-you-format-your-it-resume) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Dev Digest 176: Expensive Agents, Taking Over VSCode and Safer Vibe Coding](https://www.wearedevelopers.com/magazine/603-dev-digest-176-expensive-agents-taking-over-vscode-and-safer-vibe-coding)