Senior Security Auditor

Reynolds and Reynolds
Dayton, OH, United States
3 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Software as a Service Cloud Computing Security Code Review Continuous Integration Identity and Access Management Information Technology Audit Integrated Development Environments Log Analysis PCI Data Security Standards Systems Development Life Cycle Software Vulnerability Management
+1 more
Okta

Job description

The Senior Security Auditor leads complex and high-risk security audits across our cybersecurity, cloud, and software development environments. As a key technical leader, you ensure our security controls are effective, provide audit expertise, and mentor junior team members-all while balancing independence and cross-department collaboration., * Lead and execute end-to-end audits for AWS, on-premises, SDLC, IAM, and key SaaS platforms.

  • Develop engagement scopes, audit programs, and translate security frameworks (NIST CSF 2.0, NIST 800-53, PCI DSS, FTC Safeguards) into test procedures.
  • Assess controls through walkthroughs, configuration reviews, and log analysis; draft clear, actionable findings and remediation recommendations.
  • Guide NIST CSF 2.0 maturity assessments and document gaps.
  • Serve as audit liaison during external assessments, preparing evidence and managing requests.
  • Mentor mid- and junior auditors in methodologies and standards.
  • Track and validate remediation of findings.
  • Contribute to team operations, process improvements, and automation efforts.

Requirements

Do you have experience in Vulnerability management?, * 8+ years’ experience in security/IT audit or technical risk roles, leading audits independently

  • Deep knowledge of AWS cloud security and infrastructure-as-code
  • Strong understanding of NIST CSF 2.0, NIST 800-53, PCI DSS, and FTC Safeguards, with practical application experience
  • Experience auditing SDLC, code reviews, CI/CD, and vulnerability management
  • Proficiency with identity providers (e.g., Okta), SSO, and privileged access
  • Excellent written communication and ability to produce executive-level reports
  • Proven mentoring and leadership skills
  • Certifications (CISA, CISSP, CCSP, AWS Security Specialty, QSA) strongly preferred
  • Experience in regulated industries (automotive, industrial, etc.) is a plus
  • Able to maintain objectivity and strong working relationships with control owners

Benefits & conditions

Pulled from the full job description

  • Referral program
  • Professional development assistance
  • Parental leave
  • 401(k)
  • Health insurance
  • 401(k) matching
  • Paid time off, * 401(k)
  • 401(k) matching
  • Dental insurance
  • Flexible schedule
  • Health insurance
  • Health savings account
  • Life insurance
  • Paid time off
  • Parental leave
  • Professional development assistance
  • Referral program
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

Integrating automated security and vulnerability scanning

Alexandra Petri · World Congress 2023

11:18 min

Addressing audience questions on security and microservice architectures

Reinhard Kugler · LIVE

3:39 min

Addressing code review surrender and process exploitation

Laura Tacho Laura Tacho · World Congress 2026 Europe

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

3:48 min

Leveraging multi-agent systems for autonomous software testing

Ondřej Gróf Ondřej Gróf · World Congress 2026 Europe

56 sec

The hidden costs of delayed peer code reviews

Tim Gilboy Tim Gilboy

Videos

See all

Related articles

See all