> Markdown version of [/jobs/ext/3076663-senior-it-security-auditor-technical-security-sme](https://www.wearedevelopers.com/jobs/ext/3076663-senior-it-security-auditor-technical-security-sme). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior IT Security Auditor / Technical Security SME - **Company:** vTech Solution Inc - **Location:** Richmond, VA, United States - **Experience:** Expert - **Contract:** Temporary to permanent - **Skills:** Software System Penetration Testing, Audit Trail, Backup Devices, VoIP, Software as a Service, Cloud Computing, CompTIA Security+, Cyber Security, Document Management Systems, Identity and Access Management, Information Technology Audit, Role-Based Access Control, Screenshots, Software Vulnerability Management, Smartsheet, Data Logging, Okta, Patch Management - **Published:** September 25, 2026 - **Apply:** https://www.careerjet.com/jobad/us8a01b1117adae6c3a63230aa15776ddd ## About the Role * 7+ years: IT security assessment, IT audit, cybersecurity, or technology risk experience * 4+ years: hands-on technical security control testing, including remote-evidence environments without direct system access * Demonstrated experience with SEC530, SEC502, and/or SEC520 standards * Experience testing SaaS platforms, asset/endpoint/ITSM-adjacent platforms, or VoIP/call-recording/workforce-optimization systems * Experience with NIST SP 800-53 control testing and identity providers (Okta or comparable SSO/IdP) * Experience preparing audit work papers, technical findings, and evidence-traceability documentation for government/regulated clients * IAM review skills (SSO/Okta, RBAC, privileged access) * Audit logging, security monitoring, and configuration/change management review * Vulnerability/patch management evidence review (no active scanning/pen testing) * Encryption, secure communications, backup/recovery assessment * Third-party assurance and SOC 2 report review/reliance * Audit sampling, evidence analysis, and findings development Preferred Skills & Certifications: * CISA and/or CISSP strongly preferred * Cloud or identity-focused certifications desirable - CCSP, Security+, CRISC, or relevant Microsoft/Okta security certification ## Description We are seeking a Senior IT Security Auditor / Technical Security SME to perform hands-on SEC530 security control testing and technical evidence analysis across the Lansweeper, Smartsheet, and Verint environments, supporting the IT Security Audit Manager with technical walkthroughs, sampling, and findings development., * Execute system-specific SEC530 audit procedures for Lansweeper (asset/endpoint), Smartsheet (SaaS), and Verint (VoIP/workforce optimization) * Conduct technical walkthroughs with system owners/admins; analyze exports, screenshots, configs, logs, tickets, and vendor documentation * Test IAM controls (including Okta-based auth for Smartsheet), privileged access, contractor termination timeliness, logging, config management, vulnerability remediation, encryption, backup/recovery * Assess controls across Lansweeper asset inventory, Smartsheet admin roles, and Verint Call Manager/UCCX infrastructure * Review third-party/vendor assurance documentation, including SOC 2 reports; coordinate additional evidence requests * Prepare complete, traceable, evidence-supported work papers for each system prior to exit conferences * Document control exceptions and draft initial findings (condition, criteria, cause, effect, recommendation) * Support findings validation, corrective action plan review, exit conferences, and final report preparation, Job Summary: We are seeking an IT Security Audit Manager / Lead Auditor to lead and manage SEC530 security compliance audits for Lansweeper, Smartsheet, and Verint, serving as th… + 13 hours ago + Apply easily, Sr. IT Auditor 12 months contract with high potential to extend and convert Hybrid in Richmond, VA Role Overview: We are seeking a skilled Auditor to execute risk-based audits… + 6 days ago + Apply easily + ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [WeAreDevelopers LIVE - Playing in Production](https://www.wearedevelopers.com/videos/100363-wearedevelopers-live-playing-in-production) - [Getting under the skin: The Social Engineering techniques](https://www.wearedevelopers.com/videos/38-getting-under-the-skin-the-social-engineering-techniques) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [How to Find Tech Jobs in Vienna](https://www.wearedevelopers.com/magazine/292-how-to-find-tech-jobs-in-vienna) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)