External Audit Consultant

Ampcus, Inc

Washington (District of Columbia)

On-site

USD 90,000 - 130,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ampcus Inc. seeks a highly skilled IT compliance professional to support the Information Security & Privacy efforts for annual FISMA audits. The contractor will validate current policies, assist with remediation, and support ongoing IV&V assessments and audit activities.

Ideal candidates will have ten+ years in IT roles (auditing/security), strong communication and project management skills, and familiarity with NIST 800-series or FISMA standards. CISSP or CISA certification is highly desirable.

Qualifications

  • Ten+ years of progressively responsible IT experience (auditing/security/management).
  • Experience leading and developing audit and security documentation.
  • Experience with cloud and on‑premise applications is desirable.
  • CISSP or CISA certification strongly desired.
  • Experience with NIST 800-series or FISMA compliance is preferred.

Responsibilities

  • Evaluate, develop, maintain, and update the technology compliance program.
  • Advise technology managers on compliance, information security, and internal controls.
  • Prepare technology departments for yearly FISMA audits.
  • Develop documents for internal FISMA reviews.
  • Design and implement audit mechanisms to detect non‑compliance.
  • Provide weekly status reports documenting concerns, risks, and progress.
  • Crosswalk evidence against CISA and FedRAMP standards and document results.
  • Propose action plans to improve compliance and security practices.

Skills

IT auditing
Information security
Project management
Written communication
Analysis

Job description

Ampcus Inc. is a certified global provider of a broad range of Technology and Business consulting services. We are in search of a highly motivated candidate to join our talented Team.

Background

The Information Security & Privacy Branch of the Division of Information Technology proposes to engage two to three contractors to provide compliance and information security support in preparation for annual FISMA audits. The contractors will provide support in conducting an independent verification and validation of current policies and procedures and assist with remediation of process improvements. This will also include assisting with ongoing IV&V assessments and audit support.

Requirements
  • Experience with cloud and on-premise applications desirable.
  • Ability to simultaneously work on several complex assignments requiring analysis of intricately related complex variables.
  • Experience with leading and successfully developing audit and security-related system documentation and requirements desired.
  • At least ten years of progressively responsible experience in the information technology arena as an IT auditor, IT security analyst, IT manager, business analyst, system administrator, or a combination of these.
  • Possess clear, concise, and effective verbal and written communication and project management skills needed for functioning in an unstructured matrix management environment.
  • Experience with assessing financial systems leveraging NIST 800 series, or FISMA Compliance strongly desired.
  • CISSP or CISA certification strongly desired.
Key Responsibilities
  • Participate in the process to evaluate, develop, maintain, and update the technology compliance program.
  • Advise the technology support officer and technology managers on compliance, information security, and internal controls.
  • Prepare the technology departments for the yearly FISMA audits.
  • Assist in developing required documents in support of internal FISMA reviews.
  • Develop solutions with team members to minimize vulnerabilities.
  • Advise the technology officer of compliance issues and recommend solutions.
  • Provide a weekly status report to the COR documenting concerns, issues, risks, and progress.
  • Recommend and help implement automated solutions in the areas of compliance, auditing, and vulnerability detection for the branch.
  • Design, test, and implement audit mechanisms to detect non-compliance and to support evaluations of evidentiary materials. Ensure proper audit trails are recorded.
  • Create audit and monitoring reports used by the team, as directed.
  • Thoroughly assess and validate the audit findings for identified systems of record against Board policies. Document findings and recommendations.
  • Crosswalk the evidence and latest Board Information Security Program (BISP) against the CISA and FedRamp standards and procedures and document the results.
  • Provide recommendations, develop action plans, and help implement capabilities to improve compliance and security practices.
  • Document updates to compliance-related policies, processes, procedures, and/or standards as directed.

Ampcus is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veterans or individuals with disabilities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

FISMA & IT Compliance Audit Consultant
FISMA & IT Compliance Audit Consultant

Ampcus, Inc • Washington

On-site
USD 90,000 - 130,000
Sr. Staff Audit Support Specialist
Sr. Staff Audit Support Specialist

Ampcus Inc • Washington

On-site
USD 80,000 - 100,000
Senior Staff Audit Support Specialist
Senior Staff Audit Support Specialist

Ampcus Inc • Washington

On-site
USD 60,000 - 80,000
Information Technology - Analyst, Cyber Security
Information Technology - Analyst, Cyber Security

Ampcus, Inc • Reston (VA)

On-site
USD 85,000 - 110,000
Information Technology - Engineer, Cyber Security Sr
Information Technology - Engineer, Cyber Security Sr

Ampcus, Inc • Washington

Hybrid
USD 83,000 - 124,000
Information Technology - Analyst, Cyber Security
Information Technology - Analyst, Cyber Security

Ampcus, Inc • Baltimore (MD)

On-site
USD 80,000 - 120,000
Audit Specialist – Cyber Security (Mid-Level)
Audit Specialist – Cyber Security (Mid-Level)

ASSYST, Inc. • Baltimore (MD)

On-site
USD 80,000 - 110,000
IT Audit Advisory Consultant/FISCAM SME
IT Audit Advisory Consultant/FISCAM SME

Peraton • Herndon (VA)

On-site
USD 135,000 - 216,000
25 days PTO
Bonus plan
IT Audit Advisory Consultant/FISCAM SME
IT Audit Advisory Consultant/FISCAM SME

Peraton • Washington

On-site
USD 135,000 - 216,000
25 days PTO
Bonus plan
Subsidized benefits
IT Audit Advisory Consultant/FISCAM SME
IT Audit Advisory Consultant/FISCAM SME

Peraton • Riverdale Park (MD)

On-site
USD 135,000 - 216,000
Generous PTO
Annual bonus plan
Subsidized benefits coverage