
IT Auditor
Posted Sep 8

Posted Sep 8
This is a fully remote position, open to applicants in United States.
β’ Take charge of daily compliance execution for PCI DSS, SOC 2 Type 2, and GovRAMP, encompassing audit preparation, evidence gathering, and remediation tracking.
β’ Perform internal audits and control evaluations; generate formal reports detailing findings and prioritized suggestions for enhancements.
β’ Carry out regular gap analyses and readiness evaluations prior to official audits or certification milestones.
β’ Evaluate and uphold controls in accordance with the NIST 800-53 control framework as it pertains to GovRAMP/FedRAMP authorization.
β’ Oversee and manage Brandt's GRC tool as the authoritative system for controls, policies, and evidence.
β’ Offer guidance on client contract governance, ensuring security and compliance terms are comprehensible and achievable before commitments are finalized.
β’ Collaborate with all departments to inform staff about compliance requirements, address inquiries, and provide training.
β’ Ensure department heads are accountable for their compliance responsibilities; escalate ongoing gaps to the CIO.
β’ Create, maintain, and enforce company security policies.
β’ Cultivate relationships with external compliance entities, third-party assessors, penetration testers, and compliance-related vendors.
β’ Track changes in regulatory and framework requirements and adjust Brandt's compliance program as necessary.
β’ Work alongside Security Engineers and IT/Hosting teams to convert audit findings into actionable, implementable controls.
β’ Balance thoroughness with practicality by collaborating with stakeholders to identify compliant solutions.
β’ Must be a US Citizen or Green Card holder.
β’ 4β6 years of experience in IT audit, information security compliance, or GRC, ideally across multiple frameworks (PCI DSS, SOC 2, GovRAMP/FedRAMP, or similar).
β’ Experience with GovRAMP or FedRAMP is highly preferred.
β’ Familiarity with NIST 800-53 controls and their relevance to GovRAMP/FedRAMP authorization.
β’ Security certification such as CISA, CISSP, or CISM (CISA is preferred).
β’ Practical experience with a GRC platform (e.g., Vanta, Drata, Secureframe, OneTrust, or equivalent).
β’ Working knowledge of IT general controls (ITGCs), risk assessment methodologies, and control testing.
β’ Proven experience collaborating cross-functionally with a positive, solutions-focused attitude.
β’ Exceptional written and verbal communication skills; capable of translating technical findings for non-technical audiences.
β’ Bachelorβs degree in Information Systems, Computer Science, Business, or a related field, or equivalent experience.
β’ Health insurance, with several plans fully covered for you and discounted coverage for family members.
β’ Vision insurance fully covered for you, with discounted coverage available for family members; dental insurance available for purchase.
β’ A flexible, open PTO policy available after 30 days of continuous service, plus nine paid holidays.
β’ A 401(k) plan with company matching contributions, plus eligibility for an annual year-end performance bonus targeted at 7% of base salary.
β’ Up to eight weeks of paid parental leave.
β’ Life insurance and long-term disability insurance, both fully covered by the company.
β’ A free Udemy account for ongoing professional development.
St. Charles Health System
ExamWorks
ExamWorks
Get handpicked remote jobs straight to your inbox weekly.