IT Security Audit Manager
vTech Solution
The IT Security Audit Manager / Lead Auditor is responsible for leading and managing SEC530 security compliance audits across multiple systems, acting as the primary liaison for internal audit leadership. This role oversees audit planning, execution, evidence review, findings development, and reporting to ensure compliance with relevant standards and regulations. Responsibilities:
- Develop and maintain project plans, integrated audit schedules, evidence request lists, and system-specific SEC530 audit programs.
- Serve as the primary client contact, leading entrance conferences, weekly status updates, evidence coordination, findings reviews, and exit conferences.
- Determine control applicability across 109 system-specific controls, identify controls for scope exclusion, and approve risk-based sampling approaches.
- Review audit evidence and work papers for completeness, sufficiency, and reliability.
- Validate access-termination testing for contractor accounts to ensure timeliness.
- Develop and validate audit findings using the client s risk-rating methodology.
- Prepare and finalize draft and final audit reports; manage corrective action plan processes.
- Oversee secure evidence repository management and coordinate reliance on SOC 2 reports for relevant systems.
- Ensure compliance with SEC530, SEC502, SEC520, NIST SP 800-53, and GAGAS/IIA standards.
- Manage overall engagement risk, escalation procedures, and change control.
- 10+ years of experience in IT audit, cybersecurity assurance, technology risk, or compliance.
- 5+ years of experience leading IT security or system compliance audits, including fixed-price deliverable-based engagements.
- Demonstrated knowledge of SEC530, SEC502, and/or SEC520 standards.
- Experience with NIST SP 800-53 control assessments and vendor-managed/shared-responsibility controls (SOC 2 reliance).
- Proficiency in preparing audit programs, work papers, findings, corrective action plans, and final reports for government or regulated clients.
- Understanding of GAGAS or IIA Global Internal Audit Standards.
- Strong project, schedule, risk, and stakeholder management skills across concurrent audits.
- Experience with third-party and SaaS risk assessment including SOC 2 evaluations.
- Experience auditing asset management/ITSM platforms, SaaS collaboration tools, or VoIP/call-recording systems.
- CISA or CISSP certification preferred but not required.
- PMP certification is desirable.
- CIA or CRISC certification is desirable.
- Role requires managing multiple concurrent audits with strict adherence to regulatory standards.
- Must handle sensitive audit evidence securely using designated repositories.
- Coordination with various stakeholders and adherence to risk escalation and change management protocols are essential.
- Work schedule may involve managing overlapping audit engagements and coordinating with internal and external stakeholders.
- Flexibility to accommodate audit timelines and reporting deadlines is expected.
- Job Summary: The IT Security Audit Manager / Lead Auditor is responsible for leading and managing SEC530 security audits across multiple systems including Fairfax Quick Modules, PrintSafe, and Prisma Print. This role acts as the primary client contact and oversees all...Suggested
$134.5k - $265.1k
Position Summary Data Privacy ManagerAs a Manager in Deloitte’s Digital Trust & Privacy practice, you will lead the discovery, design... ...to inform future state architecture.Architect:Navigate complex IT architectures to incorporate privacy technology solutions....SuggestedLocal area$134.5k - $265.1k
...but also people, facilities, assets, and operations. Join our Physical Security consulting team to help clients address evolving threats through integrated security strategies, technologies, and managed services. By advising on how to strengthen risk management, security...SuggestedContract workLocal areaVisa sponsorship$148.2k - $292.3k
Position Summary As a Full Stack Engineer Manager in Deloitte Cyber’s Digital Trust & Privacy practice, you will operate at the... ...engineering teams, and communicate effectively with business, security, privacy, legal, and compliance stakeholders.Recruiting for this...SuggestedLocal areaVisa sponsorship$134.5k - $265.1k
...cybersecurity challenges and opportunities by delivering solutions and managed services that reduce complexity, strengthen resilience, and... ...development. You will design, implement, and optimize secure, outcome-focused solutions while collaborating across teams to...SuggestedLocal areaVisa sponsorship$163.4k - $322.1k
...advisory, and delivery efforts that help clients strengthen physical security programs, align security capabilities to enterprise priorities... ..., investigations, emergency communications, case and incident management, and physical security technology. The Physical Security...Local areaVisa sponsorship- ...SummaryThe Unisys Information Security Officer (ISO) provides dedicated... ...helping the client implement, manage, and govern information... ...ensure statewide compliance with IT security standards, perform risk... ...client and assigned agencies with audits, compliance reviews, and...Full timeContract workRemote work2 days per week1 day per week
$105.4k - $207.8k
...regulatory requirements, but also enable secure growth, strengthen trust, and improve operational... ..., Data Classification and Rights Management (DCRM, DRM, IRM), Data Access Governance... ...Experience working with multifunctional teams of IT professionals, legal/compliance teams,...Local area$105.4k - $207.8k
...navigate an evolving threat landscape through scalable, resilient security operations solutions. In this hands-on role, you will support... ...SecOps architectures for security information and event management (SIEM) and security orchestration, automation, and response (SOAR...Local areaVisa sponsorship- Title: Information Security Officer #00111 (State Employee only)State Role Title... ..., and compliance with statewide IT standards. This position is... ...components of application design, and manages agency participation in mandatory audits and risk assessments.The ISO leads...For contractors
$134.5k - $265.1k
...landscape. Through powerful solutions and managed services that simplify complexity, we enable... ...confidence, and proactively manage to secure success.Recruiting for this role ends on 1... ...processes, internal control risk management, IT controls and related standardsResponsible...Local areaVisa sponsorship$105.4k - $207.8k
...ownership in privacy-by-design initiatives, Consent & Preference Management, and AI governance efforts, and large-scale technology... ...technology to enable future state privacy goals and navigate complex IT architectures to incorporate privacy technology solutions.Lead working...Local area- ...Senior IT Auditor Location: Richmond, VA (Onsite, with potential... ...on executing risk-based audits of IT, operational, compliance... ...Demonstrated ability to independently manage and execute audits in a timely... ...Management, IT Operations, Security). Experience with...Contract workWork at office
- ...Job Summary: The Senior IT Security Auditor - PeopleSoft FSCM is responsible for leading... ...the SEC530 IT Security General Controls Audit of the Virginia Department of General... ..., security, fiscal, system-owner, and management stakeholders. Assess controls including...
$78.68k - $157.88k
Position Summary Audit and Assurance Information Technology Auditor... ...1,2,3)System ImplementationsCyber Security AuditsInternal Control AssessmentsDigital... ...services, external audit, or IT auditDemonstrated ability to plan and manage engagements along with ensuring...Work experience placementWork at officeLocal areaVisa sponsorship- Job Summary: The Senior IT Security Auditor / Technical Security SME is responsible for performing... ...walkthroughs, sampling, preparing audit work papers, and developing initial... ...with security standards and effective risk management. Responsibilities: Execute system...
- ...clients. By combining advanced business and security practitioner knowledge, the Principal AI... ...colleagues to determine scope, proposal management, and follow through to closureParticipate... ..., and pipeline management activities as it pertains to growing Optiv pipeline, closed...Full timeLocal areaRemote workWork from home
- Job Summary: The Senior IT Security Auditor / Technical Security SME is responsible for performing hands-on security control testing... ...and Verint environments. This role supports the IT Security Audit Manager by conducting technical walkthroughs, sampling, and findings...For contractorsRemote work
$134.5k - $265.1k
Position Summary Cyber Network Security Architecture - Manager / Manager, Strategy, Growth, and Transformation Are you interested in improving the cyber and organizational risk profiles of leading companies? Do you want to be involved in delivering Cyber services...Local areaVisa sponsorship- ...Exchange division is seeking an experienced IT auditor to support our transition to a new security standard and strengthen our third‑party risk management program. This role will help interpret... ...security requirements, conduct audits and assessments of both internal processes...
$105.4k - $207.8k
Position Summary As a Physical Security Senior Consultant in Deloitte’s Cyber Defense & Resilience team, you will help clients... ...physical security, emergency preparedness, and enterprise risk management intersect.Recruiting for this role ends on 12/31/2026.Work you...Local areaVisa sponsorship- ...current experience across Cisco enterprise networking and network security and helps clients translate business requirements, cyber risk,... ...capabilities with Splunk, ThousandEyes, identity, cloud, managed services, and other relevant parts of the Optiv portfolio.Create...Full timeLocal areaRemote workWork from home
$155.6k - $306.8k
...landscape. We simplify complexity, and enable businesses to operate with resilience, grow with confidence, and proactively manage their security posture.Recruiting for this role ends on 12/31/2026.Work you will do:As a Cyber Forward Deployed Engineer (FDE) Manager, you...Local areaVisa sponsorship$109k - $169k
...pm EST.YOUR ROLEThe Enterprise Manager, Technology and Cybersecurity... ...related to system availability, security, resilience, and data... ...the design and effectiveness of IT general controls (ITGCs) and application... ...efforts.Support regulatory, audit, and compliance activities by...Full timeWork at officeLocal areaRemote work$171.6k - $338.3k
...landscape. We simplify complexity, and enable businesses to operate with resilience, grow with confidence, and proactively manage their security posture.Recruiting for this role ends on 12/31/2026.The Team:Deloitte’s Cyber Engineering is a new team that is spearheading...Local area- ...IT Security Specialist Client is currently looking for a contractor to fill in temporarily for a vacant Information Security position within the Office of Information Management - Information Security Office. Review and create information security documentation, including...For contractorsWork at office
- ...Security Vulnerability Management Specialist This role involves providing guidance and triaging issues related to security vulnerability management. The successful candidate will serve as a point of contact for application teams and collaborate with operations, engineering...Work experience placement
- ...Sr. IT Auditor 12 months contract with high potential to extend... ...Auditor to execute risk-based audits of IT, operational, compliance... .... ~ Excellent project management, organizational, and prioritization... ...Certified Information Systems Security Professional (CISSP), or...Full timeContract workWork at office
- ...Senior IT Auditor FedTec is seeking a Senior IT Auditor to support audit, compliance, and risk management initiatives for the Virginia Housing Development Authority (VHDA). This... ...Accountant (CPA), Certified Information Systems Security Professional (CISSP) or Certified in...Temporary workWork experience placementWork at office
$134.5k - $265.1k
...relationshipsAbility to lead projects or workstreamsAbility to manage and prioritize multiple tasks in a fast-paced and dynamic environmentStrong... ....Familiarity with cybersecurity concepts (e.g., application security, cloud security, identity, detection engineering).Experience...Local areaVisa sponsorship
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Security Audit Manager. Be the first to apply!


