IT Auditor
Role details
Job location
Tech stack
Job description
We are seeking a dynamic and detail-oriented IT Auditor to join our team and drive excellence in information security and compliance. In this role, you will evaluate the effectiveness of IT controls, ensure adherence to regulatory standards, and identify opportunities for process improvements. Your expertise will help safeguard our technology infrastructure, mitigate risks, and uphold the integrity of our information systems. This position offers an exciting opportunity to leverage your cybersecurity knowledge and auditing skills in a fast-paced, innovative environment committed to continuous improvement., * Conduct comprehensive IT control testing across various domains including general IT controls, application controls, and operational processes.
- Perform IT security audits aligned with frameworks such as NIST cybersecurity framework, ISO standards, COBIT, and FISMA to assess compliance and security posture.
- Evaluate network security measures including firewall configurations, IDS (Intrusion Detection Systems), IPS (Intrusion Prevention Systems), VPNs, SAN (Storage Area Networks), LAN (Local Area Network), WAN (Wide Area Network), and cloud infrastructure like AWS and Azure.
- Review and analyze IT infrastructure components such as operating systems (Windows, Linux, macOS), system administration practices, and cloud architecture for vulnerabilities and compliance gaps.
- Assess cybersecurity incident management processes including incident response planning, disaster recovery strategies, and incident recovery procedures.
- Utilize data analytics tools like Splunk for log analysis, SIEM (Security Information and Event Management) systems for threat detection, and vulnerability research to identify potential security weaknesses.
- Document findings thoroughly, prepare audit reports, and communicate recommendations clearly to stakeholders to enhance internal controls and ensure regulatory compliance.
Requirements
- Strong knowledge of computer networking concepts including TCP/IP, DHCP, DNS, LDAP, IPsec, VPNs, load balancing, and network monitoring tools.
- Proficiency in cybersecurity standards such as NIST SP 800-53, FIPS (Federal Information Processing Standards), PCI DSS (Payment Card Industry Data Security Standard), FedRAMP, SOX (Sarbanes-Oxley Act), DIACAP (DoD Information Assurance Certification & Accreditation Process), and FISMA (Federal Information Security Management Act).
- Experience with IT governance frameworks like COBIT and ITIL; project management experience in technology projects is highly valued.
- Familiarity with cloud computing platforms including AWS, Google Cloud Platform, Azure; understanding of cloud architecture principles such as IaaS (Infrastructure as a Service) and PaaS (Platform as a Service).
- Technical skills in scripting languages such as Python, PowerShell, Bash; system administration on Windows/Linux/macOS environments; system security practices including encryption and authentication protocols.
- Ability to perform internal audits related to SOX compliance, internal controls testing, IT risk management, and internal controls evaluation.
- Knowledge of identity & access management systems like Active Directory and LDAP; experience with PKI (Public Key Infrastructure) implementation is advantageous.
- Strong analytical skills in data analysis for vulnerability research or incident management; familiarity with attack frameworks and DevOps practices is a plus.
- Excellent communication skills to present complex technical findings clearly; ability to work within Agile methodologies or SDLC processes for project delivery.
Benefits & conditions
Pulled from the full job description
- Tuition reimbursement
- 401(k)
- Retirement plan
- Dental insurance, * 401(k)
- Dental insurance
- Retirement plan
- Tuition reimbursement