Information System Auditor

Travis County, TX

$95K — $115K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Systems, Business Administration, or a related field.
  • At least 5 years of experience in IT auditing or related technology roles with an emphasis on internal controls and risk assessments.
  • Experience in cybersecurity, risk management, or compliance is preferred.
  • Industry-recognized certification (e.g., CISA, CRISC, CGRC) is desirable.
  • Valid Texas Driver's License required.

Responsibilities

  • Develops and implements a risk-based annual IT audit plan.
  • Conducts comprehensive enterprise technology risk assessments.
  • Evaluates governance and internal control processes using recognized frameworks.
  • Assesses organizational cybersecurity governance and risk management practices.
  • Performs audits of cybersecurity controls, including identity management and incident response.
  • Evaluates compliance with federal, state, and industry requirements.
  • Provides advisory services on technological initiatives while maintaining audit independence.

Benefits

  • Comprehensive health insurance and access to a no-cost on-site Health and Wellness clinic.
  • Paid vacation, sick time, personal holidays, and longevity pay.
  • Membership in the Travis County Credit Union with various financial benefits.
  • Access to an Employee Assistance Program for confidential services.
  • Tax-free sheltered investment plans through payroll deduction.
Full Job Description
Salary: Depends on Qualifications
Location : 700 Lavaca Street, Austin, TX
Job Type: Full Time
Remote Employment: Flexible/Hybrid
Job Number: 26-10752
Department: Information Security
Opening Date: 07/29/2026
Closing Date: 8/12/2026 11:59 PM Central

Job Summary
This class is in the Enterprise Risk Management series of job classifications. The Information Systems Auditor position offers an exciting opportunity to join a collaborative, diverse Information Assurance team and make a meaningful impact by helping protect the technology, information assets, and public trust that support County operations and essential community services. Under limited supervision, the Information Systems Auditor performs complex information technology and cybersecurity audit work involving governance, risk management, regulatory compliance, privacy, operational technology, cloud services, and enterprise security controls. Responsibilities include developing risk-based audit plans, evaluating compliance with federal, state, and industry security frameworks, conducting technical and operational assessments, and providing recommendations that improve the County's cybersecurity posture, resilience, and overall governance. The position serves as a trusted advisor to County leadership on information technology risks, emerging threats, and strategic control improvements, partnering with departments across the organization to enhance security, compliance, and operational effectiveness. This role offers the opportunity to work with a wide variety of technologies and business functions, influence enterprise-wide risk management decisions, and help shape the County's cybersecurity and governance strategy in a dynamic and collaborative environment dedicated to public service.
Distinguishing Characteristics:

The Information Systems Auditor is a highly analytical and self-directed professional who combines technical expertise with sound audit judgment to independently evaluate information technology, cybersecurity, privacy, and governance risks. The successful candidate demonstrates the ability to assess complex technical environments, identify control weaknesses, and provide practical, risk-based recommendations that strengthen the County's security posture while supporting operational objectives.
This position requires the ability to understand and evaluate emerging technologies, evolving cybersecurity threats, cloud computing environments, artificial intelligence, identity and access management, third-party services, and regulatory compliance requirements. The ideal candidate is a trusted advisor who communicates technical risks clearly to both technical and non-technical audiences, builds collaborative relationships across departments while maintaining audit independence, and exercises sound professional judgment when balancing risk, compliance, and business needs.

Distinguished from lower-level classifications by the complexity of assignments, level of independence, responsibility for leading enterprise-wide audit engagements, and ability to provide strategic guidance to County leadership on technology governance, cybersecurity, and risk management.
Duties and Responsibilities

  • Develops and executes a risk-based annual information technology audit plan aligned with organizational priorities.
  • Conducts enterprise technology risk assessments to identify areas requiring audit or management attention.
  • Evaluates governance, risk management, and internal control processes using recognized frameworks.
  • Assesses the effectiveness of organizational cybersecurity governance and risk management practices.
  • Performs technical and operational audits of cybersecurity controls including identity and access management, endpoint security, network security, vulnerability management, logging and monitoring, data protection, and incident response.
  • Evaluates compliance with applicable federal, state, and industry requirements including but not limited to the NIST Cybersecurity Framework, NIST SP 800-53, CJIS Security Policy, HIPAA, PCI DSS.
  • Evaluates risks associated with artificial intelligence, automation, cloud computing, SaaS platforms, and emerging technologies.
  • Reviews implementation of AI governance controls, data protection, model oversight, and responsible AI practices where applicable.
  • Evaluates third-party technology providers and outsourced services to determine adequacy of security controls and contractual compliance.
  • Reviews independent assurance reports including SOC reports, FedRAMP authorizations, penetration tests, and security assessments.
  • Presents audit findings and recommendations to executive leadership, elected officials, and Commissioners Court.
  • Tracks remediation efforts and validates implementation of corrective actions.
  • Provides advisory services on technology initiatives without impairing audit independence.
  • Collaborates within Technology and Operations and with external County departments to improve governance and control maturity.
  • Coordinates activities with external auditors and regulatory agencies.
  • Performs other job-related duties as assigned.

Minimum Requirements

Education and Experience:
Bachelor's degree in Computer Science, Information Systems, Business Administration or a directly related field AND five (5) years of relevant work experience in either IT auditing or an information technology role with significant exposure to internal controls and risk assessment practices;
OR,
Any combination of education and experience that has been achieved and is equivalent to the stated education and experience and required knowledge, skills, and abilities sufficient to successfully perform the duties and responsibilities of this job.

Licenses, Registrations, Certifications, or Special Requirements:
Valid Texas Driver's License.

Preferred:
• Progressively responsible experience in information systems auditing, cybersecurity, risk management, information security, compliance, or related information technology disciplines.
• Industry-recognized certification such as CompTIA Security+, Certified Information Systems Auditor (CISA), Certified Risk and Information Systems Control (CRISC), or Certified Governance Risk & Compliance (CGRC).
Knowledge, Skills, and Abilities:
Knowledge of:
  • Risk-based auditing methodologies
  • Information security principles
  • Cybersecurity governance
  • Regulatory and Security Frameworks such as NIST CSF 2.0, NIST 800-53, NIST AI RMF, HIPAA, PCI-DSS, CJIS
  • Texas cybersecurity statutes
  • Cloud security architectures
  • Identity and Access Management
  • Third-party risk management
  • Artificial intelligence governance
  • Secure software development lifecycle
  • Data analytics techniques
Skill in:
  • Risk analysis
  • AI risk analysis
  • Technical writing
  • Data analytics
  • Cloud security review
  • Interviewing stakeholders
  • Ability to coordinate and perform multiple tasks/projects simultaneously, balancing priorities and deliverables.
  • Competent interpersonal skills, demonstrating the ability to lead projects and mentor others.
  • Ability to evaluate business processes and IT technology, identify risks and evaluate controls.
  • Both verbal and written communication.
Ability to:
  • Perform independent risk-based IT and cybersecurity audits.
  • Analyze complex technical environments.
  • Interpret regulatory requirements.
  • Evaluate security architectures.
  • Assess effectiveness of cybersecurity controls.
  • Review major technology projects for governance and control considerations.
  • Develop practical, risk-based recommendations.
  • Facilitate organizational compliance with federal, state, and local security regulatory requirements by studying existing and new security legislation; interpreting organizational impact, and; advising management on needed actions.
  • Communicate technical concepts to non-technical audiences.
  • Exercise sound professional judgment and independence.
  • Maintain confidentiality of sensitive information.
  • Maintain professional and technical knowledge by attending educational workshops; reviewing professional publications; establishing personal networks; participating in professional societies.
  • Ability to work collaboratively in a team environment, foster positive working relationships, share knowledge, and mentor less experienced staff to promote professional growth and organizational success.

Work Environment & Other Information

Work primarily performed in office setting, either on-site or in a secure hybrid/telework environment. May involve occasional visits to data centers, agency offices, or vendor locations for security inspections, audits, or meetings. Must adhere to strict security protocols and procedures, including physical access controls, fingerprint-based background checks, and secure area clearances. May occasionally work outside normal business hours to respond to security incidents or meet project deadlines.
Physical requirements include extended periods of sitting, using a computer and other standard office equipment. Subject to visual acuity, speech and hearing, hand and eye coordination and manual dexterity necessary to operate a computer and office equipment. Occasional lifting or carrying of equipment or materials (typically less than 25 pounds) may be required. Must be able to remain focused and alert while working on detailed technical tasks, especially during incident response or time-sensitive audits.

Work Hours: 8 am - 5 pm, Monday-Friday.
Works some holidays, some nights, and some weekends

Location: 700 Lavaca Street Austin, Texas 78701

Department: Information Security

For updates or questions on this position, contact:

This job description is intended to be generic in nature. It is not necessarily an exhaustive list of all duties and responsibilities. The essential duties, functions and responsibilities and overtime eligibility may vary based on the specific tasks assigned to the position.
Benefits
Employment at Travis County comes with a full array of benefits. We offer comprehensive health insurance, a no-cost, on-site Health and Wellness clinic, longevity pay, paid vacations, sick time and personal holidays, not to mention an industry competitive salary structure and a friendly, stable work environment.
FY2026 Travis County Benefit Guide

In this valuable you will find benefit summaries, eligibility requirements, costs, contact numbers and addresses as well as other general information on the benefits available to Travis County Employees and Retirees.

Credit Union
Employees may join the Travis County Credit Union which offers low-interest loans, savings plans through payroll deduction, safe deposit boxes and other benefits.

Deferred Compensation
Employees may enroll in a tax- free sheltered investment plan through payroll deduction.

Direct Deposit
Employees may sign up for direct bank deposit.

Employee Assistance Program
Travis County provides a confidential counseling and referral service free of charge to county employees and their family.

Employee Organizations
Membership in the American Federation of State, County, and Municipal Employees Union is available through payroll deduction.

Employee Health & Wellness Clinic
Employees may access the clinic for a variety of wellness program and health care services with no co-pay, no deductible and no co-insurance costs.

Holidays
An average of eleven paid holidays are designated by the Travis County Commissioners Court at the beginning of each fiscal year.

Insurance
Employees may select from four plans: an Exclusive Physician Organization (EPO), Choice Plus Preferred Physician Organization (PPO), Consumer Choice or a High Deductible Health Plan (HDHP) with a Health Savings Account (HSA). All four options include a Pharmacy Plan. Travis County's current policy is to pay 100% of the employee's health insurance premium for the Consumer Choice and HDHP. Employees will pay a premium for both the EPO and PPO. Other insurance benefits include $50,000 Basic Life and AD&D paid by the County.

The following benefits are employee paid:
  • Dental
  • Vision
  • Supplemental Life, AD&D
  • Dependent Life
  • Short Term Disability
  • Long Term Disability
  • Long Term Care

New employees are covered on the first day of the month following 28 calendar days of employment.

Longevity
Longevity pay is paid for each year completed after three years of continuous service. Peace Officers in a law enforcement activity, whose job requires state peace officer certification, receive pay after one year of certification.

On the regular payday on or after the employee's fourth and subsequent adjusted service dates, he or she receives a single payment for the previous year.

Parking
A limited number of assigned parking spaces are available to employees in the Courthouse Complex.

Personal Holidays
Regular, full-time employees are eligible for up to three paid personal holidays each calendar year. Part-time employees shall be granted personal holidays on a prorated basis. New employees earn personal holidays for the calendar year in which he/she begins employment, based on the month in which employment begins:

January - March

3 personal holidays
April - June

2 personal holidays

Ju

Similar Jobs

More Jobs at Travis County, TX

More Information Technology Jobs

Find similar Information System Auditor jobs: