IT Security Auditor

vTech Solution Inc
Richmond, United States of America
6 days ago

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 122K

Job location

Richmond, United States of America

Tech stack

Microsoft Access
Microsoft Active Directory
Batch Processing
Oracle WebLogic Server
Microsoft Biztalk Servers
Configuration Management
Computer Security
Information Systems
Databases
Identity and Access Management
Information Technology Audit
Lightweight Directory Access Protocols (LDAP)
Windows Server
Oracle
Oracle Applications
PeopleSoft Financial Management
Peoplesoft People Tools
Powershell
Software Engineering
Oracle Linux
User Provisioning Software
Data Logging
File Transfer Protocol (FTP)
IT General Controls (ITGC)
People Soft
Patch Management
Data Objects
Oracle Erp

Job description

The Senior IT Security Auditor PeopleSoft FSCM is responsible for leading the SEC530 IT Security General Controls Audit of the Virginia Department of General Services PeopleSoft Financials environment. This role involves planning and executing audit procedures, assessing control design and effectiveness, maintaining audit documentation, and preparing audit reports. The auditor will collaborate closely with risk assessors and various stakeholders to ensure comprehensive audit coverage of PeopleSoft FSCM and related technical environments. Responsibilities:

  • Develop the SEC530 audit program, control matrix, testing procedures, sampling plan, evidence requirements, and audit schedule.
  • Participate in onsite kickoff, draft-report review, and final exit or wrap-up meetings.
  • Conduct interviews with technical, security, fiscal, system-owner, and management stakeholders.
  • Assess controls including identity and access management, privileged access, segregation of duties, user provisioning and termination, change and configuration management, application development, and production migration.
  • Evaluate vulnerability and patch management, logging, monitoring, incident response, backup, recovery, and continuity controls.
  • Review interface, batch-processing, and reconciliation controls along with sensitive-data protection and third-party/shared/inherited controls.
  • Examine PeopleSoft roles, permission lists, Process Scheduler, Integration Broker, custom objects, scripts, database links, service accounts, and environment separation.
  • Assess security controls for PowerShell, SFTP/FTP, BizTalk, database-link, and financial-system integrations.
  • Maintain the audit evidence-request register and track all requested items and their status.
  • Prepare comprehensive and defensible workpapers documenting audit procedures and results.
  • Develop findings with condition, criteria, cause, effect, and recommendation mapped to SEC530 controls.
  • Review management responses and corrective-action plans.
  • Prepare and present draft and final audit reports.
  • Deliver complete audit workpaper packages and reusable templates., * Experience reviewing PeopleTools, WebLogic, Oracle 19c, Windows Server, and Oracle Linux controls.
  • Familiarity with SFTP, PowerShell, BizTalk, Integration Broker, database links, and financial interfaces.
  • Additional certifications such as CISSP, CIA, CRISC, CISM, CGEIT, or CPA.

Special Considerations:

  • Mandatory onsite meetings in Richmond, Virginia.
  • Work must be performed from approved U.S.-based locations only.
  • Compliance with key-personnel designation and background-check requirements as per SOR.

Scheduling:

  • Work schedule aligned with audit project timelines and onsite meeting requirements.
  • Coordination with risk assessment activities to minimize duplication and maximize efficiency., Sr. IT Auditor 12 months contract with high potential to extend and convert Hybrid in Richmond, VA Role Overview: We are seeking a skilled Auditor to execute risk-based audits…
  • 1 month ago
  • Apply easily, Job Summary: The Senior Information Security Risk Assessor PeopleSoft FSCM will lead comprehensive SEC530 risk assessments for PeopleSoft Financials and related business function…
  • 10 hours ago
  • Apply easily

Requirements

  • Active Certified Information Systems Auditor (CISA) certification.
  • Minimum three years of relevant IT audit or IT general controls experience.
  • Experience developing and executing formal IT audit programs and testing control design and operating effectiveness.
  • Proficiency in preparing audit workpapers, findings, corrective-action recommendations, and final audit reports.
  • Experience auditing sensitive financial, tax, payment, vendor, or personally identifiable information.
  • Ability to provide a reference from another state government agency.
  • Availability for required onsite meetings in Richmond, Virginia.
  • Ability to perform all work from approved U.S.-based locations.
  • Knowledge of SEC530 or comparable government security audit standards.
  • Understanding of IT general controls, application controls, risk-based audit planning, and sampling.
  • Familiarity with PeopleSoft or Oracle ERP security concepts, Oracle database security, Active Directory/LDAP controls, interface and batch-processing controls.
  • Skills in audit evidence validation, workpaper preparation, root-cause analysis, corrective-action review, and executive/technical report writing.

Preferred Skills & Certifications:

  • Five or more years of IT audit experience.
  • Prior experience with SEC530, Commonwealth of Virginia, or VITA audits.
  • Experience auditing PeopleSoft FSCM, PeopleSoft Financials, or Oracle ERP environments.
  • Knowledge of GAGAS or Institute of Internal Auditors standards.

Apply for this position