Senior IT Security Auditor / Technical Security SME

vTech Solution Inc
Richmond, VA, United States
9 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Audit Trail Backup Devices VoIP Software as a Service Cloud Computing CompTIA Security+ Cyber Security Document Management Systems Identity and Access Management Information Technology Audit Role-Based Access Control
+6 more
Screenshots Software Vulnerability Management Smartsheet Data Logging Okta Patch Management

Job description

We are seeking a Senior IT Security Auditor / Technical Security SME to perform hands-on SEC530 security control testing and technical evidence analysis across the Lansweeper, Smartsheet, and Verint environments, supporting the IT Security Audit Manager with technical walkthroughs, sampling, and findings development., * Execute system-specific SEC530 audit procedures for Lansweeper (asset/endpoint), Smartsheet (SaaS), and Verint (VoIP/workforce optimization)

  • Conduct technical walkthroughs with system owners/admins; analyze exports, screenshots, configs, logs, tickets, and vendor documentation
  • Test IAM controls (including Okta-based auth for Smartsheet), privileged access, contractor termination timeliness, logging, config management, vulnerability remediation, encryption, backup/recovery
  • Assess controls across Lansweeper asset inventory, Smartsheet admin roles, and Verint Call Manager/UCCX infrastructure
  • Review third-party/vendor assurance documentation, including SOC 2 reports; coordinate additional evidence requests
  • Prepare complete, traceable, evidence-supported work papers for each system prior to exit conferences
  • Document control exceptions and draft initial findings (condition, criteria, cause, effect, recommendation)
  • Support findings validation, corrective action plan review, exit conferences, and final report preparation, Job Summary: We are seeking an IT Security Audit Manager / Lead Auditor to lead and manage SEC530 security compliance audits for Lansweeper, Smartsheet, and Verint, serving as th…
  • 13 hours ago
  • Apply easily, Sr. IT Auditor 12 months contract with high potential to extend and convert Hybrid in Richmond, VA Role Overview: We are seeking a skilled Auditor to execute risk-based audits…
  • 6 days ago
  • Apply easily +

Requirements

  • 7+ years: IT security assessment, IT audit, cybersecurity, or technology risk experience
  • 4+ years: hands-on technical security control testing, including remote-evidence environments without direct system access
  • Demonstrated experience with SEC530, SEC502, and/or SEC520 standards
  • Experience testing SaaS platforms, asset/endpoint/ITSM-adjacent platforms, or VoIP/call-recording/workforce-optimization systems
  • Experience with NIST SP 800-53 control testing and identity providers (Okta or comparable SSO/IdP)
  • Experience preparing audit work papers, technical findings, and evidence-traceability documentation for government/regulated clients
  • IAM review skills (SSO/Okta, RBAC, privileged access)
  • Audit logging, security monitoring, and configuration/change management review
  • Vulnerability/patch management evidence review (no active scanning/pen testing)
  • Encryption, secure communications, backup/recovery assessment
  • Third-party assurance and SOC 2 report review/reliance
  • Audit sampling, evidence analysis, and findings development

Preferred Skills & Certifications:

  • CISA and/or CISSP strongly preferred
  • Cloud or identity-focused certifications desirable - CCSP, Security+, CRISC, or relevant Microsoft/Okta security certification

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann Chris Heilmann +2 · LIVE

1:30 min

Integrating automated security and vulnerability scanning

Alexandra Petri · World Congress 2023

1:26 min

Spear phishing IT administrators with malicious VoIP spoofing

Mauro Verderosa · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

6:38 min

Blending retro technology with conversational AI integrations

Andrew MacLean Andrew MacLean +2 · LIVE

Videos

See all

Related articles

See all