Senior IT Security Auditor
Company: Guidehouse
Location: Chantilly
Posted on: March 18, 2023
|
|
Job Description:
Job Description:
Job Family:IT Risk & Controls Consulting Travel Required:None
Clearance Required:Active Top Secret SCI with Polygraph What You
Will Do: Responsibilities for this role include some or all of the
following: Performing rigorous assessments of IT controls using
industry-standard guidance and leading practices Performing
walkthrough interviews and maintaining communication with a variety
of client stakeholders, including system personnel such as system
and database administrators Requesting, obtaining, reviewing, and
analyzing a variety of artifacts to assist in executing IT controls
testing such as security plans, SOPs, system screenshots, and
system configuration settings Evaluate the design and operating
effectiveness of IT controls using provided artifacts,
industry-standard guidance, leading practices, and professional
judgement Professionally documenting the results of IT controls
test work in a consistent and high-quality manner that would allow
a reviewer to repeat the test and reach the same conclusion
Summarizing and communicating IT controls assessment results to a
variety of client stakeholders, including senior leadership
personnel Planning and executing day-to-day activities of IT
controls assessments individually and for the team Working with
client personnel to understand and analyze known IT control
weaknesses, identify root causes, and develop detailed, robust
remediation plans Providing subject matter expertise to client
personnel on all matters relating to IT controls and responding to
ad-hoc IT controls requests from client personnel What You Will
Need: A CURRENT and ACTIVE TOP SECRET/SCI clearance and
COUNTERINTELLIGENE polygraph. Bachelor degree in Information
Systems, Accounting, general business or other technical degree
Excellent communication skills Experience with consulting
Experience with supporting senior government clients Experience
with federal government What Would Be Nice To Have: Demonstrated
knowledge and experience in IT risk and controls through the
following: IT audits IT control assessments IT security reviews
Relevant certification such as the Certified Information Systems
Auditor (CISA) or is eligible to attain certification. Demonstrated
ability and working knowledge of: FISMA NIST SP 800 series FISCAM
other relevant Federal information assurance laws, regulations, and
guidance. Experience performing: FISMA OMB Circular A-123 similar
internal control assessments is preferred Experience in access and
account management, including authorization, provisioning,
recertification, and separation Experience in segregation of
duties, including: identifying and defining segregation of duties
risks and conflicts preventive and detective segregation of duties
controls understanding the difference between segregation of duties
and least privilege Experience with technical account management
controls, such as password length, complexity, and expiration
Experience with audit logging and monitoring, including: generation
of audit logs use of audit log aggregation and analysis tools audit
log monitoring and review Configuration management experience,
including: configuration baseline concepts baseline deviations
baseline maintenance monitoring for ongoing compliance with a
baseline industry-accepted baselines such as: DISA STIGs CIS
benchmarks Change management experience, including: authorization
development testing deployment of changes Contingency planning
experience, including: backups testing of backups alternate sites
What We Offer: Guidehouse offers a comprehensive, total rewards
package that includes competitive compensation and a flexible
benefits package that reflects our commitment to creating a diverse
and supportive workplace. Benefits include: Medical, Rx, Dental &
Vision Insurance Personal and Family Sick Time & Company Paid
Holidays Position may be eligible for a discretionary variable
incentive bonus Parental Leave and Adoption Assistance 401(k)
Retirement Plan Basic Life & Supplemental Life Health Savings
Account, Dental/Vision & Dependent Care Flexible Spending Accounts
Short-Term & Long-Term Disability Student Loan PayDown Tuition
Reimbursement, Personal Development & Learning Opportunities Skills
Development & Certifications Employee Referral Program Corporate
Sponsored Events & Community Outreach Emergency Back-Up Childcare
Program Mobility Stipend About GuidehouseGuidehouse is an Equal
Employment Opportunity / Affirmative Action employer. All qualified
applicants will receive consideration for employment without regard
to race, color, national origin, ancestry, citizenship status,
military status, protected veteran status, religion, creed,
physical or mental disability, medical condition, marital status,
sex, sexual orientation, gender, gender identity or expression,
age, genetic information, or any other basis protected by law,
ordinance, or regulation. Guidehouse will consider for employment
qualified applicants with criminal histories in a manner consistent
with the requirements of applicable law or ordinance including the
Fair Chance Ordinance of Los Angeles and San Francisco. If you have
visited our website for information about employment opportunities,
or to apply for a position, and you require an accommodation,
please contact Guidehouse Recruiting at 1-571-633-1711 or via email
at RecruitingAccommodation@guidehouse.com. All information you
provide will be kept confidential and will be used only to the
extent required to provide needed reasonable accommodation.
Guidehouse does not accept unsolicited resumes through or from
search firms or staffing agencies. All unsolicited resumes will be
considered the property of Guidehouse and Guidehouse will not be
obligated to pay a placement fee.
Keywords: Guidehouse, Chantilly , Senior IT Security Auditor, Accounting, Auditing , Chantilly, Virginia
Click
here to apply!
|