Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

IT Security Auditor

vTech Solution

Job Summary:

The Senior IT Security Auditor / Technical Security SME is responsible for performing hands-on security control testing and technical evidence analysis across Lansweeper, Smartsheet, and Verint environments. This role supports the IT Security Audit Manager by conducting technical walkthroughs, sampling, and findings development to ensure compliance with SEC530 standards and related security frameworks. Responsibilities:

  • Execute system-specific SEC530 audit procedures for Lansweeper (asset/endpoint), Smartsheet (SaaS), and Verint (VoIP/workforce optimization).
  • Conduct technical walkthroughs with system owners and administrators; analyze exports, screenshots, configurations, logs, tickets, and vendor documentation.
  • Test IAM controls including Okta-based authentication for Smartsheet, privileged access, contractor termination timeliness, logging, configuration management, vulnerability remediation, encryption, and backup/recovery.
  • Assess controls across Lansweeper asset inventory, Smartsheet admin roles, and Verint Call Manager/UCCX infrastructure.
  • Review third-party and vendor assurance documentation such as SOC 2 reports and coordinate additional evidence requests.
  • Prepare complete, traceable, evidence-supported work papers for each system prior to exit conferences.
  • Document control exceptions and draft initial findings including condition, criteria, cause, effect, and recommendations.
  • Support findings validation, corrective action plan review, exit conferences, and final report preparation.
Required Skills & Certifications:
  • 7+ years of experience in IT security assessment, IT audit, cybersecurity, or technology risk.
  • 4+ years of hands-on technical security control testing, including working with remote evidence environments without direct system access.
  • Demonstrated experience with SEC530, SEC502, and/or SEC520 standards.
  • Experience testing SaaS platforms, asset/endpoint/ITSM-adjacent platforms, or VoIP/call-recording/workforce-optimization systems.
  • Knowledge of NIST SP 800-53 control testing and identity providers such as Okta or comparable SSO/IdP.
  • Experience preparing audit work papers, technical findings, and evidence-traceability documentation for government or regulated clients.
  • IAM review skills including SSO/Okta, RBAC, and privileged access.
  • Audit logging, security monitoring, and configuration/change management review capabilities.
  • Vulnerability and patch management evidence review experience (excluding active scanning or penetration testing).
  • Encryption, secure communications, and backup/recovery assessment expertise.
  • Third-party assurance and SOC 2 report review and reliance experience.
  • Audit sampling, evidence analysis, and findings development skills.
Preferred Skills & Certifications:
  • CISA and/or CISSP certifications strongly preferred.
  • Cloud or identity-focused certifications such as CCSP, Security+, CRISC, or relevant Microsoft/Okta security certifications are desirable.
Special Considerations:
  • Work involves handling sensitive and regulated government or client data requiring strict adherence to confidentiality and security protocols.
  • May require coordination with multiple system owners and vendors for evidence collection and validation.
Scheduling:
  • Standard business hours with potential flexibility depending on audit timelines and coordination needs.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the IT Security Auditor in Richmond, VA vacancy
  •  ...Senior IT Auditor Location: Richmond, VA (Onsite, with potential for hybrid schedule) Duration: 1-year contract with potential to...  ...and controls (Logical Access, Change Management, IT Operations, Security). Experience with automated workpapers and data analytics... 
    Suggested
    Contract work
    Work at office

    ASCENDING LLC

    Richmond, VA
    3 days ago
  •  ...Job Summary: The Senior IT Security Auditor - PeopleSoft FSCM is responsible for leading the SEC530 IT Security General Controls Audit of the Virginia Department of General Services PeopleSoft Financials environment. This role involves planning and executing audit... 
    Suggested

    vTech Solution

    Richmond, VA
    4 days ago
  • Job Summary: The Senior IT Security Auditor / Technical Security SME is responsible for performing hands-on security control testing and technical evidence analysis in various IT environments including Fairfax Quick Modules, PrintSafe, and Prisma Print. This role involves... 
    Suggested

    vTech Solution

    Richmond, VA
    1 day ago
  •  ...About The Role The SCC’s Health Benefit Exchange division is seeking an experienced IT auditor to support our transition to a new security standard and strengthen our third‑party risk management program. This role will help interpret and implement updated security requirements... 
    Suggested

    STI

    Richmond, VA
    4 days ago
  •  ...Sr. IT Auditor 12 months contract with high potential to extend and convert Hybrid in Richmond, VA Role Overview: We are seeking...  ...Public Accountant (CPA), Certified Information Systems Security Professional (CISSP), or Certified in Risk and Information Systems... 
    Suggested
    Full time
    Contract work
    Work at office

    ASCENDING

    Richmond, VA
    9 days ago
  •  ...Senior IT Auditor FedTec is seeking a Senior IT Auditor to support audit, compliance, and risk management initiatives for the Virginia...  ...Public Accountant (CPA), Certified Information Systems Security Professional (CISSP) or Certified in Risk and Information Systems... 
    Temporary work
    Work experience placement
    Work at office

    Fedtec

    Richmond, VA
    1 day ago
  •  ...important role will execute risk-based audits of IT, operational, compliance, financial and...  .... Experience in serving as a Senior auditor. Bachelor’s degree in information systems...  ...(CPA), Certified Information Systems Security Professional (CISSP) or Certified in Risk... 
    Work experience placement
    Work at office

    22nd Century Technologies

    Richmond, VA
    4 days ago
  • Job Summary: The IT Security Audit Manager / Lead Auditor is responsible for leading and managing SEC530 security audits across multiple systems including Fairfax Quick Modules, PrintSafe, and Prisma Print. This role acts as the primary client contact and oversees all... 

    vTech Solution

    Richmond, VA
    1 day ago
  • Job Summary: The IT Security Audit Manager / Lead Auditor is responsible for leading and managing SEC530 security compliance audits across multiple systems, acting as the primary liaison for internal audit leadership. This role oversees audit planning, execution, evidence... 
    For contractors

    vTech Solution

    Richmond, VA
    1 day ago
  •  ...Senior IT Internal Auditor We're looking for a Senior IT Internal Auditor. The Senior IT Internal Auditor supports the organization's Sarbanes-Oxley (SOX) compliance program and contributes to risk-based internal audit and advisory engagements. This role is responsible... 
    Work at office
    Home office

    Hamilton

    Richmond, VA
    1 day ago
  •  ...looks like in this role: Position SummaryThe Unisys Information Security Officer (ISO) provides dedicated cybersecurity leadership in support...  ...across the Commonwealth to ensure statewide compliance with IT security standards, perform risk assessments, support incident response... 
    Full time
    Contract work
    Remote work
    2 days per week
    1 day per week

    Unisys

    Richmond, VA
    3 days ago
  • $78.68k - $157.88k

     ...Audit and Assurance Information Technology Auditor - Senior Consultant Do you thrive in...  ...Reports (SOC 1,2,3)System ImplementationsCyber Security AuditsInternal Control AssessmentsDigital...  ...services, external audit, or IT auditDemonstrated ability to plan and manage... 
    Work experience placement
    Work at office
    Local area
    Visa sponsorship

    Deloitte

    Richmond, VA
    20 hours ago
  • Title: Information Security Officer #00111 (State Employee only)State Role Title: Info Technology Specialist IIIHiring Range: Commensurate...  ...security, technology governance, and compliance with statewide IT standards. This position is responsible for developing, implementing... 
    For contractors

    Commonwealth of Virginia, USA

    Richmond, VA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to IT Security Auditor. Be the first to apply!