5-7 years of experience in IT audit with a focus on compliance and control validation.
Expertise in NIST SP 800-171 or similar frameworks, adaptable to various regulatory environments.
Ability to research and summarize new regulatory requirements for leadership.
Strong communication skills for diverse audiences and organizational levels.
Self-motivated with a track record of delivering actionable results independently.
Skilled in implementing and managing security controls effectively.
Experience in collecting and interpreting audit evidence and artifacts.
Responsibilities
Conduct IT audits to assess compliance with regulatory and industry standards.
Evaluate and validate control evidence to ensure regulatory adherence.
Research and interpret new regulations, providing summaries to senior leadership.
Communicate findings and recommendations clearly across the organization.
Implement and manage security controls to mitigate risks.
Collect and analyze evidence for audits and assessments.
Collaborate with cross-functional teams to drive compliance initiatives.
Benefits
Flexible work arrangements to promote work-life balance.
Professional development opportunities to enhance skills and career growth.
Access to cutting-edge technology and tools in the cybersecurity field.
Supportive team environment that encourages innovation and collaboration.
Full Job Description
Qualifications:Required Qualifications:
Demonstrated experience in Information Technology audit, with the ability to identify, evaluate, and validate control evidence sufficient to support and demonstrate compliance with regulatory and industry requirements.
Deep understanding of NIST SP 800-171 or comparable control frameworks (e.g., NIST SP 800-53, NIST Cybersecurity Framework, ISO/IEC 27001/27002, FedRAMP, PCI DSS, or CIS Critical Security Controls), with the ability to rapidly apply control-based concepts across regulatory environments.
Ability to research and interpret new regulatory requirements, providing concise summaries to senior leadership
Strong written and verbal communication skills across multiple channels and organizational levels
Self-starter with the ability to work independently and deliver clear, actionable results
Proficient in identifying, implementing, and managing security controls
Knowledgeable in collecting and interpreting evidence and artifacts for audits and assessments
Solid grasp of IT domains including information security, network architecture, and cloud computing
Prior experience in Governance, Risk & Compliance (GRC) organization or comparable role
Preferred Qualifications:
Experience developing and maintaining System Security Plans (SSPs)
Project management experience and ability to drive action across functional areas
Foundational understanding of emerging AI tools and technologies, with the ability to evaluate their application for enhancing productivity and automation while identifying associated risks, potential misuse, and impacts to the organization's security and compliance posture
Experience in the aviation industry
Desired Certifications:
Certified Information Systems Security Professional (CISSP)
Certified Information Systems Auditor (CISA)
Certified in Risk and Information Systems Control (CRISC)