Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

IT Auditor

Vaco Charlotte

Contract IT Auditor / Risk Assessor Location: Remote - must work during Eastern Standard Time business hours Engagement: Contract, initial term of 3-5 months with potential extension Start: As soon as possible Reports to: IT Risk, Compliance, or Internal Audit Leadership About the Role We are seeking a technically capable Contract IT Auditor / Risk Assessor to help relaunch and execute our IT risk and controls assessment methodology. Our business risk program has been operating successfully for more than a year. However, we have determined that our approach to IT risk and control assessments needs to be rebuilt. We are starting fresh with a revised methodology based on the organization's top 20 IT risk areas and business functions. The methodology, control requirements, and recommended testing procedures will be provided. Your responsibility will be to execute the assessment process: identify the appropriate Control Owner, explain the control and testing expectations, request and evaluate evidence, document the results, identify gaps, and help move approved risks and controls into our GRC platform. This is a hands-on role for someone who combines IT audit and GRC experience with enough technical depth to engage credibly with infrastructure, cybersecurity, application, and operations teams. The ideal candidate is broad technically-"an inch deep and a mile wide"-and can ask informed questions across a wide range of IT environments. Key Responsibilities Execute risk and control assessments across the organization's prioritized IT risk areas. Review provided control descriptions and recommended test procedures, then translate them into practical assessment activities. Identify and engage the appropriate Control Owner or technical subject-matter expert. Explain the purpose of each control, the associated risk, and the evidence required to demonstrate that the control is operating. Request, collect, organize, and evaluate appropriate evidence, such as: Policies and procedures. System reports and configuration exports. Access reviews and approval records. Change tickets and release documentation. Vulnerability and patch-management reports. Security monitoring records and logs. Backup, recovery, and operational reports. Screenshots or other system-generated evidence. Assess whether controls are properly designed and operating effectively. Distinguish between complete, incomplete, insufficient, and unsupported evidence. Challenge unclear, inconsistent, or unsupported responses professionally and constructively. Identify control gaps, exceptions, deficiencies, and potential risks. Document testing procedures, evidence reviewed, results, conclusions, and recommended remediation. Follow up with Control Owners to resolve open questions and obtain missing evidence. Coordinate approval of assessed risks and control results with appropriate stakeholders. Work with Amber to upload approved risks, controls, evidence, and assessment results into the GRC platform. Help establish consistent, audit-ready documentation standards within the GRC system. Train and coach Control Owners so they can perform future assessments and maintain their controls independently. Educate Control Owners on: The business and technology risks addressed by each control. Their control responsibilities. Acceptable evidence. Testing frequency and procedures. How to document and upload evidence in the GRC platform. Support current PCI audit activities and FDIC-related requests as needed. Track outstanding requests, findings, action items, and remediation commitments through completion. Escalate unresponsive Control Owners, unsupported assertions, or material control concerns appropriately. Technical Scope The successful candidate does not need to be the deepest expert in every technology. However, they must have sufficient practical knowledge to understand how controls operate and to determine whether evidence is credible. Relevant experience may include: IT general controls. Identity and access management. Privileged access and segregation of duties. Patch and vulnerability management. Endpoint management, including tools such as Microsoft Intune or SCCM. Change and release management. Configuration and security baselines. Network and infrastructure operations. Cloud platforms and SaaS applications. Backup, disaster recovery, and business continuity. Security operations, logging, and monitoring. Incident response. Third-party and vendor risk. Data protection and encryption. Application controls and system interfaces. Asset and configuration management. IT operations and service management. For example, when assessing a Patch Management control, you should be able to understand how patch compliance is measured, what systems are in scope, how exceptions are handled, and whether reports from Intune, SCCM, vulnerability-management platforms, or related tools sufficiently support the control conclusion. Required Qualifications 5 years of experience in IT audit, technology risk, cybersecurity compliance, GRC, controls assurance, or a closely related field. Experience executing IT control assessments from evidence request through documented conclusion. Strong understanding of IT general controls and cybersecurity control environments. Experience working directly with technical Control Owners, engineers, system administrators, and IT leadership. Ability to understand a broad range of technologies and operational processes without requiring deep specialization in a single platform. Experience evaluating whether evidence is relevant, sufficient, reliable, and complete. Strong written documentation and workpaper skills. Experience identifying control deficiencies and explaining risk in clear business language. Experience using a GRC platform or structured risk-and-control repository. Ability to manage multiple assessments, evidence requests, deadlines, and stakeholders independently. Strong interpersonal skills and the confidence to respectfully challenge incomplete or questionable responses. Ability to work remotely and maintain consistent availability during Eastern Time business hours. Preferred Qualifications Experience in a regulated financial-services environment. Experience supporting PCI DSS, FDIC, FFIEC, GLBA, SOX, NIST, CIS, or similar requirements. Experience with GRC platforms such as ServiceNow GRC, Archer, AuditBoard, OneTrust, LogicGate, or comparable systems. CISA, CISSP, CRISC, CIA, CISM, or comparable certification. Experience creating Control Owner training or control self-assessment materials. Experience supporting external audits, regulatory examinations, or remediation programs. Familiarity with Microsoft security and endpoint-management technologies, including Intune, SCCM, Entra ID, and related reporting. Success Measures Success in this role will be measured by the ability to: Complete assessments across the prioritized risk areas using the new methodology. Obtain timely and appropriate evidence from Control Owners. Produce clear, defensible, audit-ready testing documentation. Identify unsupported claims, control gaps, and meaningful risk issues. Move approved risks and controls into the GRC platform accurately. Reduce the amount of follow-up required from internal IT risk and compliance staff. Enable Control Owners to perform future testing and evidence submissions independently. Support timely responses to PCI and FDIC-related requirements. Establish a repeatable, sustainable assessment process rather than simply completing one-time requests. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. EEO Notice Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law. Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact View email address on click.appcast.io . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal . Representation Notice By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. For residents of Ontario, Canada: Based on Highspring's discussions with its Client, Highspring's understanding is that this position for employment is a current vacancy (either through Highspring as a contractor or with the client directly). Privacy Notice Vaco by Highspring and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") respects your privacy and are committed to providing transparent notice of our policies. California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here . Virginia residents may access our state specific policies here . Residents of all other states may access our policies here . Canadian residents may access our policies in English here and in French here . Residents of countries governed by GDPR may access our policies here . Additionally, submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. More details about Vaco by Highspring's use of AI can be found here ( ). Further assessment of candidates beyond this initial phase will be conducted by recruiters and hiring managers. Vaco by Highspring does not know and cannot opine on if its client's use of AI products in hiring. Pay Transparency Notice Determining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to: the individual's skill sets, experience and training; licensure and certification requirements; office location and other geographic considerations; other business and organizational needs. With that said, as required by local law, Vaco by Highspring believes that the following salary range referenced above reasonably estimates the base compensation for an individual hired into this position in geographies that require salary range disclosure. The individual may also be eligible for discretionary bonuses. Vaco

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the IT Auditor in New York, NY vacancy
  • Responsibilities: • Plan and execute the day-to-day activities of IT audit engagements for clients, including system development, package implementation, SOC and control readiness assessments, and/or platform reviews within multiple industries. • Evaluate the design and... 
    Suggested
    For contractors
    H1b
    Local area

    KPMG

    New York, NY
    3 days ago
  • $95k

     ...Job Description The New York City Employees’ Retirement System (NYCERS) is recruiting one (1) IT Project Specialist (Senior IT Auditor) in the Internal Audit Division. The senior IT auditor is responsible for continuously inspecting and assessing the effectiveness... 
    Suggested
    Full time

    City of New York

    New York, NY
    1 day ago
  •  ...Stripe is seeking an IT SOX Controls Specialist to join its SOX Compliance team in New York. You will own the design, implementation, and monitoring of controls over third-party applications that affect Stripe's financial reporting. In this role, you will work with... 
    Suggested

    Stripe

    New York, NY
    1 day ago
  • BDO is seeking an Assurance Experienced Senior in Technology Risk Assurance to plan IS audit work, test general controls, and analyze security and access controls across diverse technology environments. You will supervise IS Assurance Associates, review engagement work...
    Suggested

    Chris Baily

    New York, NY
    2 days ago
  •  ...employment. Click HERE to discover how we empower team members to grow, thrive, and advance in their careers. Responsibilities The IT Internal Auditor audits information systems, platforms, and operating procedures in accordance with established corporate standards for... 
    Suggested
    Work at office
    Local area
    Night shift

    Penn Entertaiment

    New York, NY
    3 days ago
  •  ...Job Description Job Description Job Title - Senior IT Auditor Location - 405 Lexington Ave 14th floor, New York, NY 10174 Job Summary: We are currently looking for a Senior IT Auditor with SOX experience to support our Internal Audit team. The job will... 

    The Rockridge Group

    New York, NY
    21 days ago
  • UGI Corporation is hiring a Senior IT Auditor to conduct IT operational and SOX compliance audits across the enterprise. This role emphasizes strong project management skills and communication capabilities as it involves collaboration with various stakeholders. The ideal... 

    UGI Corporation

    New York, NY
    4 days ago
  • $115k - $140k

    ## Senior IT Internal AuditorApplyremote type: Hybridlocations: Purchase, New Yorktime type: Full timeposted on: Posted 3 Days Agojob...  ...Description**Sompo has a unique opportunity for a **Senior IT Auditor** to join our **Global IT Internal Audit** team.*This role will... 
    Full time
    Work at office
    Flexible hours

    Sompo Holdings, Inc.

    New York, NY
    3 days ago
  •  ...modernizes its infrastructure and strengthens control documentation, there is a strategic opportunity to enhance coordination across IT functions and accelerate remediation efforts. This expert position will serve as the internal change agent and strategic bridge... 
    Work at office

    3B Staffing LLC

    New York, NY
    1 day ago
  •  ...Swoon is seeking a Technology (IT) Audit Manager to lead technology audits across planning, testing and reporting. You will evaluate...  ...hands-on audit execution with team leadership, coaching auditors, and translating findings into actionable recommendations. The position... 

    SWOON Defunct

    New York, NY
    3 days ago
  • $110k - $130k

     ...— talk with your recruiter to learn more. Base pay range $110,000.00/yr - $130,000.00/yr Additional compensation types Annual Bonus IT Audit & Technology Risk Recruitment Specialist Hamlyn Williams has partnered with a top global banking organization that is looking to... 
    Full time

    Hamlyn Williams

    New York, NY
    5 days ago
  • $100k - $110k

     ...Diversity, Equity and Inclusion program including 7 Employee Resource Groups (ERGs)Your Role:We are currently looking for a Senior IT Auditor to support our Internal Audit team. The job will include IT audit, reviews of application implementations, and operational/SOX... 
    Full time

    OUTFRONT Media

    New York, NY
    2 days ago
  • $100k - $130k

    Our client is a global publishing firm. They seek a Senior IT Auditor to join their Manhattan, NY office.ResponsibilitiesLead information systems audits, technology risk assessments, and internal consulting engagements in accordance with audit standards and methodologiesDevelop... 
    Work at office
    Remote work

    Abacus Group

    New York, NY
    7 days ago
  •  ...JamesPosted: 2026-08-31Location: New York, United StatesCompany: Raymond JamesPosted: 2026-08-28Raymond James is seeking an experienced IT auditor to focus on virtual endpoint security reviews, network security reviews, and other technology‑related security assessments within... 

    Raymond James

    New York, NY
    1 day ago
  •  ...engagements, including scheduling, planning, fieldwork, and reporting. This individual will evaluate risks, assess the effectiveness of IT controls, drive data analysis to support conclusions, and ensure timely project completion. Additionally, this position involves... 

    Sysco

    New York, NY
    3 days ago
  •  ...the US-level Information Security risk framework is appropriately adhered to and evidenced. Coordinate with security operations, IT, Legal, Compliance, BCP, Head Office, and other relevant stakeholders during cybersecurity incidents, as part of the Incident Response... 
    Work at office
    Work from home
    Flexible hours
    2 days per week

    Sumitomo Mitsui Trust Bank

    New York, NY
    1 day ago
  • $99k - $252.45k

    Digital Assurance & Transparency - IT Audit Manager The Opportunity As a Digital Assurance & Transparency - IT Audit Manager, you will...  ...: an active CPA license or Certified Information Systems Auditor (CISA) certification What Sets You Apart Preference for a Bachelor... 

    PwC (US)

    New York, NY
    3 days ago
  • $270k - $320k

     ...encryption standards, access controls, and data governance policies. Leadership & Collaboration: Partner with executive leadership, IT teams, and external stakeholders to align security initiatives with business objectives. Employee Education & Awareness: Develop... 
    Work at office
    Flexible hours
    3 days per week

    CAIS

    New York, NY
    2 days ago
  • $250.44k - $375.67k

     ...problem-solver who's two years light on paper than the person coasting on a long CV. Confident, clear communication with executives, auditors and regulators alike. Comfortable with ambiguity. Happy to work as part of a lean team and within an outsourcing model to central... 

    OKX

    New York, NY
    2 days ago
  • $150k - $200k

     ...CMMC, PCI, COBIT, DFARS, HIPAA, etc. ~ Hands-on incident response coordination and oversight experience. ~ Strong understanding of IT Risk and components, including application, infrastructure, network, and vendors. ~ Bachelor’s degree in Computer Science,... 
    Work experience placement
    Remote work
    Flexible hours

    VISTRADA

    New York, NY
    1 day ago
  • $350k - $400k

     ...and retain top cybersecurity talent. Direct work and ensure appropriate performance levels for all security team members. Partner with IT, Legal, Risk, HR, and other business units to ensure a holistic approach to Information Security. Executive Leadership &... 
    Full time
    Contract work

    Barnes & Noble

    New York, NY
    3 days ago
  • $300k - $350k

     ...data. Instead of accepting the status quo, we decided to fix it. National security professionals, journalists, parents, and everyone...  ...~ Vet and manage relationships with external security vendors, auditors, and researchers, including running a responsible disclosure /... 
    Odd job
    Work at office
    Immediate start
    Relocation package

    Cape

    New York, NY
    2 days ago
  • Company Description As the world's leading vendor of Cyber Security, facing the most sophisticated threats and attacks, we've assembled a global team of the most driven, creative, and innovative people. At Check Point, our employees are redefining the security landscape...

    Check Point Software Technologies

    New York, NY
    1 day ago
  •  ...Chief Information Security Officer (CISO) to lead and advance its enterprise-wide information security, technology risk, compliance, and IT strategy. The CISO will be responsible for the protection of company assets, customer data, and critical systems, while also enabling... 

    Confidential

    New York, NY
    4 days ago
  • Chief Information Security Officer (CISO) About the Company Innovative provider of data safety & recovery solutions Industry Information Technology and Services Type Privately Held Founded 2024 Employees 51-200 Specialties cloud backup ...

    Confidential

    New York, NY
    3 days ago
  • Chief Information Security Officer (CISO), Information Security & Compliance About the Company Innovative artificial intelligence (AI) & marketing analytics platform Industry Information Technology and Services Type Public Company Founded 2014 ...

    Confidential

    New York, NY
    3 days ago
  • Who are we? Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems. We’re training and deploying frontier models for enterprises who are building...
    Full time
    Work at office
    Local area
    Remote work
    Home office

    Cohere

    New York, NY
    2 days ago
  • $100k - $180k

     ...compliance with relevant laws, regulations, and industry standards, such as GDPR and ISO 27001. Team Leadership: Manage and direct a team of IT security professionals, providing guidance and support in their roles. Collaboration: Work closely with other executives to align... 
    Full time
    Local area

    City of New York

    New York, NY
    2 days ago
  •  ...administration, software development, systems engineering, or deep familiarity with Linux-based systems.  - Experience accrediting IT systems against U.S. Government standards such as NIST SP 800-53, CNSSI 1253, and DISA STIGs.  - Hands-on experience supporting accreditation... 
    Full time
    Flexible hours

    Contact Government Services, LLC

    New York, NY
    21 days ago
  • $260k - $280k

     ...person physical presence at DataCT's principal offices in New York City. DataCT's core staff, CT Plan stakeholders, SIP Processors, auditors, and principal service providers are concentrated in the New York metropolitan area, and on-site collaboration is essential to the... 
    Local area

    DataCT LLC

    New York, NY
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to IT Auditor. Be the first to apply!