IT Security Auditor
vTech Solution
Job Summary:
The Senior IT Security Auditor / Technical Security SME is responsible for performing hands-on security control testing and technical evidence analysis in various IT environments including Fairfax Quick Modules, PrintSafe, and Prisma Print. This role involves leading technical walkthroughs, sampling, preparing audit work papers, and developing initial findings to ensure compliance with security standards and effective risk management. Responsibilities:
- Execute system-specific SEC530 audit procedures.
- Conduct technical walkthroughs and analyze configurations, reports, logs, access records, tickets, vulnerability results, and vendor documentation.
- Test controls related to access management, timely access termination, privileged access, authentication, logging, configuration management, vulnerability remediation, encryption, backup, recovery, and system integrity.
- Assess controls across AWS-hosted SaaS, Windows Server, Active Directory, SQL Server, endpoints, interfaces, and enterprise print platforms.
- Review third-party controls and assurance documentation for service providers.
- Prepare complete, traceable, evidence-supported audit work papers.
- Document control exceptions and support findings development with practical recommendations.
- Support finding reviews, corrective action plan validation, exit conferences, and final reporting.
- 7+ years of experience in IT security assessment, IT audit, cybersecurity, or technology risk.
- 4+ years of hands-on technical security control testing.
- Experience with Commonwealth of Virginia standards such as SEC530, SEC502, SEC520.
- Experience auditing financial, tax, payment-processing, or revenue systems handling sensitive financial data.
- Familiarity with NIST SP 800-53 security control testing.
- Experience assessing cloud/SaaS environments, Windows infrastructure, SQL Server, identity and access management, and third-party services.
- Proven ability to prepare audit work papers and technical findings.
- Strong skills in AWS shared-responsibility assessment, Active Directory, endpoint and SQL security, privileged access testing, logging/monitoring, configuration/patch management, encryption, backup/recovery, and SOC report review.
- CISA and/or CISSP certification strongly preferred.
- Experience in enterprise print-management or production-printing security.
- Government or regulated-industry assessment experience.
- AWS Certified Security, CCSP, Security+, CRISC, or relevant Microsoft security certifications.
- Must be able to handle sensitive financial and security data with discretion.
- Duration: 3 months.
- Work schedule: 40 hours per week.
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the IT Security Auditor in Richmond, VA vacancy
- ...Senior IT Auditor FedTec is seeking a Senior IT Auditor to support audit, compliance, and risk management initiatives for the Virginia... ...Certified Public Accountant (CPA), Certified Information Systems Security Professional (CISSP) or Certified in Risk and Information...SuggestedTemporary workWork experience placementWork at office
- ...Sr. IT Auditor 12 months contract with high potential to extend and convert Hybrid in Richmond, VA Role Overview: We are seeking... ...Public Accountant (CPA), Certified Information Systems Security Professional (CISSP), or Certified in Risk and Information Systems...SuggestedContract workWork at office
- About The Role The SCC’s Health Benefit Exchange division is seeking an experienced IT auditor to support our transition to a new security standard and strengthen our third‑party risk management program. This role will help interpret and implement updated security requirements...Suggested
- Job Summary: The IT Security Audit Manager / Lead Auditor is responsible for leading and managing SEC530 security audits across multiple systems including Fairfax Quick Modules, PrintSafe, and Prisma Print. This role acts as the primary client contact and oversees all...Suggested
- ...looks like in this role: Position SummaryThe Unisys Information Security Officer (ISO) provides dedicated cybersecurity leadership in support... ...across the Commonwealth to ensure statewide compliance with IT security standards, perform risk assessments, support incident response...SuggestedFull timeContract workRemote work2 days per week1 day per week
- Job Description IT Audit Manager - Remote Work Required skillset: Must have 5+ years in IT Audit/IT Risk Management, with SOX and... ...around risk Someone with an AWS Cloud Practitioner certification is ideal - not required Must have NIST security experience 3B Staffing LLCRemote work
- ...physical science, natural science, computer science or other academic fields related to intelligence. INTELLIGENCE AND INFORMATION SECURITY CAREERS IN THE NAVY INTELLIGENCE OFFICER Analyze top-secret information, interpret spy reports and direct the analysis of top-...Full timePart timeWorldwide
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Security Auditor. Be the first to apply!




