Audit Liason

Mbi Llc

Harrisburg, Northern (Dauphin County, KY)

Hybrid

USD 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Mbi Llc in Harrisburg, PA is seeking an IT Audit Liaison to support the Enterprise Information Security Office within the GRC program. You will participate in audits, assess IT controls, and help strengthen cybersecurity and regulatory compliance posture.

The role requires coordinating with internal and external auditors, evaluating CSF/ISO controls, and reporting findings with remediation actions to management. A professional certification in IT auditing is preferred.

Qualifications

  • Experience supporting IT audits and compliance assessments.
  • Familiarity with governance, risk and compliance concepts.
  • Knowledge of NIST CSF, NIST 800-53, ISO 27001.
  • Ability to prepare reports and communicate findings clearly.

Responsibilities

  • Coordinate IT audits with internal and external bodies.
  • Review evidence to verify compliance with laws and standards.
  • Evaluate controls and identify deficiencies with remediation guidance.
  • Develop dashboards and metrics on audit trends and remediation.
  • Support audit procedures, evidence collection and responses.
  • Track findings and report status to management.

Skills

IT auditing
GRC knowledge
Regulatory compliance
NIST CSF
ISO 27001
Risk assessment
Reporting & dashboards
Communication

Job description

- Under the direction of the IT Governance, Risk and Compliance Manager, this position serves as an IT Audit Liaison within the Enterprise Information Security Office (EISO), supporting the Commonwealth's Governance, Risk, and Compliance (GRC) Department.

- The GRC function provides governance, risk evaluation, and compliance oversight to support informed decision-making and the responsible adoption of technology across the Commonwealth.

- The IT Audit Liaison provides technical audit and compliance support for the organization's Governance, Risk, and Compliance (GRC) program.

- The employee participates in internal and external audit activities, evaluates the effectiveness of information technology controls, identifies compliance gaps, and supports remediation efforts to strengthen the organization's cybersecurity and regulatory compliance posture.

Description of Major Duties:
  • Coordinates and supports information technology audits conducted by internal and external oversight organizations, including GAAP/Single Audit, the Pennsylvania Auditor General, Attorney General, Bureau of Audits, and other regulatory entities.
  • Reviews documentation and technical evidence to determine compliance with applicable laws, regulations, policies, and security standards.
  • Evaluates information security and technology controls against established frameworks, including NIST Cybersecurity Framework (CSF), NIST Special Publication 800-53, ISO 27001, and Commonwealth security policies.
  • Identifies control deficiencies, documents findings, and recommends corrective actions to reduce organizational risk.
  • Assists business and technical stakeholders in preparing audit responses and collecting supporting evidence.
  • Tracks audit findings, validates corrective actions and reports remediation status and residual risk to management.
  • Supports development and maintenance of automated workstreams for audit management, compliance tracking, and evidence collection.
  • Develops dashboards, metrics and executive reports regarding audit trends, compliance posture and remediation progress.
  • Performs risk-based assessments to prioritize audit activities and evaluate control effectiveness.
  • Assists in developing audit procedures, compliance documentation, metrics, and management reports.
  • Participates in continuous improvement initiatives related to governance, risk management, and internal controls.
  • Performs related work as assigned.
Knowledge, Abilities and Preferred Qualifications
Knowledge of:
  • Information technology auditing principles and practices
  • Cybersecurity governance and risk management
  • Internal controls and compliance concepts
  • NIST CSF, NIST 800-53, ISO 27001, and related frameworks
  • IT infrastructure, applications, cloud technologies, and security controls
Ability to:
  • Analyze technical and audit documentation
  • Evaluate compliance with policies and standards
  • Prepare clear reports and recommendations
  • Communicate effectively with technical and non-technical staff
  • Organize multiple audit activities simultaneously
Preferred Qualifications:
  • Professional certification such as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manager (CISM) or equivalent
  • Experience supporting IT audits, regulatory examinations or compliance assessments
Fill the skill matrix below:

Skill

Amount

Candidate's No. of years of experience

  • Evaluates information security and technology controls against established frameworks, including NIST Cybersecurity Framework (CSF), NIST Special Pu
  • Identifies control deficiencies, documents findings, and recommends corrective actions to reduce organizational risk
  • Assists business and technical stakeholders in preparing audit responses and collecting evidence.
  • Tracks audit findings, validates corrective actions and reports remediation status and residual risk to management.
  • Supports development and maintenance of automated workstreams for audit management, compliance tracking, and evidence collection.
  • Develops dashboards, metrics and executive reports regarding audit trends, compliance posture and remediation progress.
  • Performs risk-based assessments to prioritize audit activities and evaluate control effectiveness.
  • Reviews documentation and technical evidence to determine compliance with applicable laws, regulations, policies, and security standards.
  • Cybersecurity governance and risk management
  • NIST CSF, NIST 800-53, ISO 27001, and related frameworks
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Internal Auditor
Staff Internal Auditor

Community Health Systems • Franklin (TN)

On-site
USD 60,000 - 80,000
IT Audit Liaison | GRC & Cybersecurity Controls
IT Audit Liaison | GRC & Cybersecurity Controls

Mbi Llc • Harrisburg, Northern (KY)

Hybrid
USD 90,000 - 120,000
Governance, Risk & Compliance Analyst I
Governance, Risk & Compliance Analyst I

Geographic Solutions, Inc. • Dunedin (FL)

On-site
USD 60,000 - 100,000
Associate IT Auditor
Associate IT Auditor

Lkq • Seattle (WA)

On-site
USD 70,000 - 95,000
Health Insurance
Paid Time Off
401k with Company Match
Governance Risk and Compliance Analyst Intermediate
Governance Risk and Compliance Analyst Intermediate

Cone Health • Greensboro (NC)

On-site
USD 110,000 - 140,000
Compliance Analyst
Compliance Analyst

Creative Solutions Services, LLC • Harrisburg

Hybrid
USD 70,000 - 95,000
Auditor Grade 11 7005440 9809280 12611040
Auditor Grade 11 7005440 9809280 12611040

Delaware River Port Authority • Camden (NJ)

On-site
USD 90,000 - 130,000
IT Auditor
IT Auditor

KPRS Construction • Pittsburgh

Hybrid
USD 65,000 - 85,000
Senior IT Audit Manager
Senior IT Audit Manager

The Sherwin-Williams Company • Cleveland (OH)

On-site
USD 120,000 - 190,000
Associate, Internal Audit – IT
Associate, Internal Audit – IT

Confidential • Jacksonville (FL)

On-site
USD 70,000 - 100,000