IT Auditor

Brandt
Tallahassee, FL, United States
28 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$107,000.0 - $120,000.0
Working hours
Regular working hours
Job source

Tech stack

Information Systems Information Technology Audit PCI Data Security Standards IT General Controls (ITGC) Information Technology

Job description

The IT Auditor is responsible for maintaining and advancing Brandt’s information security compliance posture across PCI DSS, SOC 2 Type 2, and GovRAMP, ensuring the company’s internal controls, policies, and procedures satisfy regulatory and contractual requirements. This role reviews and assesses the adequacy of Brandt’s IT controls, produces findings and remediation recommendations, and provides guidance for client contract governance related to security and compliance obligations. The Auditor works across every department to educate stakeholders, answer compliance questions, deliver training, and hold departments accountable to their compliance standards, while managing external relationships with assessors, pen testers, auditors, and compliance vendors. Success in this role requires being a stickler for standards without becoming a blocker: someone comfortable saying no, but who collaborates with stakeholders to find workable paths to compliance., * Own day-to-day compliance execution for PCI DSS, SOC 2 Type 2, and GovRAMP, including audit prep, evidence collection, and remediation tracking

  • Conduct internal audits and control assessments; produce formal reports with findings and prioritized recommendations for improvement
  • Conduct periodic gap analyses and readiness assessments ahead of formal audits or certification milestones
  • Assess and maintain controls against the NIST 800-53 control framework as it applies to GovRAMP/FedRAMP authorization
  • Maintain and administer Brandt’s GRC tool as the system of record for controls, policies, and evidence
  • Provide guidance on client contract governance, ensuring security/compliance terms are understood and achievable before commitments are made
  • Partner with all departments (not limited to IT and Security) to educate staff on compliance requirements, answer questions, and deliver training
  • Hold department heads accountable to their compliance obligations; escalate persistent gaps to the CIO
  • Draft, maintain, and enforce company security policies, ensuring adherence within Security, IT, and beyond
  • Manage relationships with external compliance organizations, third-party assessors, penetration testers, and compliance-related vendors
  • Monitor changes in regulatory and framework requirements (PCI, SOC 2, GovRAMP/FedRAMP, NIST 800-53) and update Brandt’s compliance program accordingly
  • Collaborate with Security Engineers and IT/Hosting teams to translate audit findings into practical, implementable controls
  • Balance rigor with pragmatism: apply consistent standards while working with stakeholders to find compliant solutions rather than simply issuing denials

Requirements

  • 4-6 years of experience in IT audit, information security compliance, or GRC, ideally spanning multiple frameworks (PCI DSS, SOC 2, GovRAMP/FedRAMP, or similar)
  • GovRAMP or FedRAMP experience strongly preferred
  • Familiarity with NIST 800-53 controls and their application to GovRAMP/FedRAMP authorization
  • Security certification such as CISA, CISSP, or CISM (CISA preferred)
  • Hands-on experience with a GRC platform (e.g., Vanta, Drata, Secureframe, OneTrust, or equivalent)
  • Working knowledge of IT general controls (ITGCs), risk assessment methodology, and control testing
  • Demonstrated experience working collaboratively and cross-functionally, with a positive, solutions-oriented attitude
  • Excellent written and verbal communication skills; able to translate technical findings for non-technical audiences
  • Bachelor’s degree in Information Systems, Computer Science, Business, or related field, or equivalent experience

Benefits & conditions

Compensation is set within Brandt’s job architecture for the Senior band with a salary range of $107,000.00-$120,000.00. Level and salary are determined by your experience, the scope of the team you’ll lead, and internal equity. We back the role with benefits built for people staying for the long haul:

  • Health insurance, with several plans fully covered for you and discounted coverage for family members.
  • Vision insurance fully covered for you, with discounted coverage available for family members; dental insurance available for purchase.
  • A flexible, open PTO policy available after 30 days of continuous service, plus nine paid holidays.
  • A 401(k) plan with company matching contributions, plus eligibility for an annual year-end performance bonus targeted at 7% of base salary.
  • Up to eight weeks of paid parental leave.
  • Life insurance and long-term disability insurance, both fully covered by the company.
  • A free Udemy account for ongoing professional development.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

2:43 min

Auditing third-party technical quality and team skill profiles

Loïc Carbonne Loïc Carbonne · World Congress 2024

1:26 min

Bridging the sim-to-real gap with multi-control networks

Alexander Schwarz Alexander Schwarz · World Congress 2025

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

2:49 min

Verifying dependency metadata accuracy through controlled package installations

Uwe Korn Uwe Korn · World Congress 2026 Europe

2:14 min

Establishing legal admissibility through immutable blockchain attestations

Frederik Gregaard Frederik Gregaard +1 · World Congress 2026 Europe

Videos

See all

Related articles

See all