EI
External Audit Consultant - Intermediate Level
Expert In Recruitment Solutions
🇺🇸 United States
Remote
Mid level
4 weeks ago
- FISMA
- NIST
- CISSP
- CISA
- FedRAMP
4 weeks ago
When submitting a candidate, please provide two available 15-20-minute time slots for a quick call with me today or tomorrow.
BACKGROUND: The Information Security & Privacy Branch of the Division of Information
Technology proposes to engage two to three contractors to provide compliance and information
security support to in preparation for annual FISMA audits, provide support in conducting an
independent verification and validation of current policies and procedures, and assist with
remediation of process improvements. This will also include assisting with ongoing IV&V
assessments and audit support.
REQUIREMENTS: The candidate shall possess the knowledge and skills set forth in the Technical Services Client, Section 3.6.2.1 Intermediate External Auditor Consultant. In addition, the candidate shall have demonstrated experience in the following:
Experience with cloud and on-premis applications desirable.
• Simultaneously works on several complex assignments requiring analysis of intricately
related complex variables.
• Experience with leading and successfully developing audit and security related system
documentation and requirements desired.
• Must have at least ten years of progressively responsible experience in the information
technology arena as an IT auditor, IT security analyst, IT manager, business analyst,
system administrator or a combination of these.
• Possess clear, concise, and effective verbal and written communication and project
management skills needed for functioning in an unstructured matrix management
environment.
• Experience with assessing financial systems leveraging NIST 800 series, or FISMA
Compliance .
• CISSP or CISA certification will be given priority.
KEY RESPONSIBILITIES:
Participates in the process to evaluate, develop, maintain, and update the technology
compliance program. Advises the technology support officer and technology managers
on compliance, information security, and internal controls.
• Prepares the technology departments for the yearly FISMA audits.
• Assist in developing required documents in support of internal FISMA reviews.
• Develop solutions with team members to minimize vulnerabilities.
• Advises the technology officer of compliance issues and recommends solutions
• Provides a weekly status report to the COR documenting concerns, issues, risks, and
progress.
• Recommends and helps implement automated solutions in the areas of compliance,
auditing, and vulnerability detection for the branch.
• Designs, tests, and implements audit mechanisms to detect non-compliance and to
support evaluations of evidentiary materials. Ensures proper audit trails are recorded.
• Creates audit and monitoring reports used by the team, as directed.
The External Auditor Consultant shall deliver, but not limited to, the following:
• Thoroughly assess and validate the audit findings for identified systems of record against
Board policies. Document findings and recommendations.
• Crosswalk the evidence and latest Board Information Security Program (BISP) against
the CISA and FedRamp standards and procedures and document the results.
• Provide recommendations, develop action plans, and help implement capabilities to
improve compliance and security practices.
• Document updates to compliance related policies, processes, procedures, and/or standards
as directed.
External Audit Consultant - Intermediate Level · Expert In Recruitment Solutions