IT Security Audit Manager / Lead Auditor
Work mode: Hybrid · Location: Washington D.C., United States · Schedule: Full Time.
Application Deadline
📅 Dec 23, 2026
Interested in this job?
Create your profile in 30 seconds and we'll apply for you automatically
Job Description
Job Summary:
Seeking an IT Security Audit Manager / Lead Auditor to lead and manage SEC530 security audits for Fairfax Quick Modules, PrintSafe, and Prisma Print. This role serves as the primary client contact and holds full accountability for audit planning, delivery, findings, reports, work papers, and overall quality.
Key Responsibilities:
- Develop the project plan, audit schedule, and SEC530 audit programs
- Manage entrance conferences, evidence requests, interviews, weekly reporting, findings reviews, and exit conferences
- Determine control applicability and approve sampling/testing procedures
- Review audit evidence and work papers for completeness and sufficiency
- Ensure inquiry is not the primary evidence source; validate timeliness of access termination testing
- Develop findings covering condition, criteria, cause, effect, and recommendation
- Prepare and finalize separate audit reports for each system
- Coordinate management corrective action plans and final deliverable acceptance
- Ensure compliance with GAGAS or IIA Global Internal Audit Standards
Required Skills & Certifications:
- 10+ years of IT audit, cybersecurity assurance, technology risk, or compliance experience
- 5+ years leading IT security or system compliance audits
- Experience with one or more Commonwealth of Virginia standards: SEC530 (Information Security), SEC502 (IT Security Audit), SEC520 (IT Risk Management)
- Experience auditing financial, tax, payment-processing, or revenue systems handling sensitive financial data
- Experience with NIST SP 800-53 control assessments
- Experience preparing audit programs, work papers, findings, corrective action plans, and final reports
- Government or regulated-industry audit experience
- Strong skills in evidence sufficiency, work-paper review, findings/report development, and third-party/SaaS risk assessment
- Project, schedule, risk, and stakeholder management skills
- CISA certification required or strongly preferred
Preferred Skills & Certifications:
- Commonwealth of Virginia IT audit experience
- PMP strongly preferred
- CIA, CISSP, or CRISC desirable
Scheduling:
- Duration: 3 Months
- Working: 40 hrs/week
About the Company
Company registered on Saplic.