
Senior IT Security Auditor
- 🇺🇸 United States
- Remote
- Senior
- 4 hours ago
- $115,000 – $140,000
- CIS Benchmarks
- STIGs
- NIST
- Risk Management Framework
- FIPS
- Windows
- Linux
- Unix
- MacOS
- VMware
- Hyper-V
- Docker
- Kubernetes
- OpenShift
- VoIP
- AWS
- Azure
- Salesforce
- FedRAMP
- TLS
- Tenable
- Nessus
- Technical Writing
- Excel
- VBA
- CISA
- CySA+
Clearance:
Ability to obtain and maintain a Minimum Background Investigation (MBI) for our Department of Treasury customer.Candidates must reside in, and perform all work from, the continental United States or its outlying territories.
Location:
Remote (United States)
Work Schedule:
Full-time, remote. Must be available during core business hours (Eastern Time) to support scheduled audit activities. Travel to audited organization sites may be required on occasion, with advance notice.
Salary Range:
$115,000 to $140,000 annually, commensurate with experience
Position Overview:
AptNexus is seeking a Senior IT Security Auditor to perform cybersecurity compliance audits for our Department of Treasury customer. The program audits federal, state, and local government organizations that receive sensitive federal data, evaluating their information systems against security requirements tailored from NIST SP 800-53. In this role, you will plan and conduct audits of technical and management controls, perform hands-on configuration testing across operating systems, databases, network devices, cloud services, and mainframe platforms, and deliver clear, defensible findings to customer personnel and the audited organizations. The ideal candidate is a detail-oriented self-starter who combines disciplined audit practice with genuine technical depth.
Duties/Responsibilities:
- Plan and conduct cybersecurity compliance audits of government partner organizations, establishing audit scope based on in-scope systems, data flows, and technologies.
- Conduct pre-audit scoping calls to validate system inventories and data flows, and prepare scoping documentation identifying in-scope technologies, versions, support status, shared systems, applicable test procedures, and estimated level of effort.
- Develop audit schedules and recommend auditor assignments that cover every in-scope technology while minimizing conflicts.
- Perform hands-on technical control testing using automated scanning tools and manual configuration review against NIST SP 800-53 controls, CIS Benchmarks, and DISA STIGs.
- Evaluate management controls through interviews with system administrators and examination of policies, procedures, and system artifacts.
- Present audit scope and data flows at opening conferences, and present technical findings at closing conferences.
- Provide daily written status updates during audits, including progress, outstanding work, potential critical findings, scope changes, and concerns.
- Document test results and prepare preliminary findings, final audit report sections, and corrective action recommendations with risk-based remediation timelines.
- Prepare after action reports capturing lessons learned and recommendations for process improvement.
- Review the work of other auditors for accuracy and consistency, and provide technical guidance on complex testing and findings.
- Educate audited organizations on applicable security requirements and recommended approaches to remediation.
- Comply with all customer security, privacy, and records management requirements, using only Government-furnished equipment and approved systems.
Required Skills
- Minimum of seven (7) years of cybersecurity experience, including at least five (5) years conducting federal cybersecurity audits or security control assessments.
- Expert working knowledge of NIST SP 800-53 (moderate and high baselines), the NIST Risk Management Framework, NIST SP 800-30, and FIPS, including the ability to audit against control sets tailored from NIST.
- Hands-on experience testing and validating security configurations on Windows, Linux, UNIX, and macOS systems; virtualization and container platforms (VMware, Hyper-V, Docker, Kubernetes, OpenShift); databases; and network devices such as firewalls, routers, switches, VPN, wireless, VoIP, and SAN/NAS storage.
- Experience assessing cloud environments (AWS, Microsoft Azure and Microsoft 365, Google, Salesforce, and other FedRAMP-authorized services) across SaaS, IaaS, and PaaS service models.
- Experience auditing mainframe security, including IBM RACF or ACF2, is strongly preferred.
- Working knowledge of encryption technologies and standards, including TLS, VPN, and FIPS 140 validated cryptography.
- Proficiency with automated scanning and compliance tools such as Tenable Nessus and SCAP, and with CIS Benchmarks and DISA STIGs.
- Exceptional technical writing skills, with the ability to produce clear, well-supported, and defensible audit findings.
- Advanced Microsoft Excel and Word skills; experience developing or using VBA macros is preferred.
- Detail-oriented self-starter who takes ownership of assignments, manages competing priorities, and drives work to completion with minimal supervision.
- Certification:
- Must have at least one of the following certifications:
- Certified Information Systems Auditor (CISA) (preferred)
- CompTIA Cybersecurity Analyst (CySA+)
- GIAC Systems and Network Auditor (GSNA)
- Polished written and verbal communication skills, with the confidence to present findings to senior officials at audited organizations.
- Sound professional judgment, objectivity, and integrity in handling sensitive information and audit results.
- Must meet federal eligibility requirements for a position of public trust, including U.S. citizenship or lawful permanent residency, federal tax compliance, Selective Service registration (if applicable), a credit check, and fingerprinting.
- Must complete customer-required security awareness training upon onboarding and annually thereafter.
Education Requirement:
High school diploma required. Bachelor’s degree in information technology, cybersecurity, information systems, accounting, or a related field preferred.
AptNexus is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status.
About APTNEXUS
Since our founding 2012, APTNEXUS has empowered federal agencies and commercial enterprises to navigate the complexities of the digital landscape. As a quality-driven small business, we specialize in the seamless delivery of IT modernization and elite cybersecurity solutions. We help our clients modernize and fortify their technology stacks —ensuring their most critical data and assets remain resilient, optimized, and secure in an evolving threat environment.
Senior IT Security Auditor · APTNEXUS