External Audit Consultant (FISMA)

System One

Washington

On-site

USD 90,000 - 130,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

System One is seeking an experienced FISMA External Audit Consultant in Washington, DC. This contract role can be remote or hybrid, with a focus on compliance, policy development, and audit readiness for annual FISMA reviews.

The ideal candidate will bring 10+ years in IT auditing or security, CISSP or CISA certification, and practical experience with NIST 800-series controls and government-related auditing standards.

Qualifications

  • Ten plus years in IT auditing, security, or related fields.
  • Experience with cloud and on‑premise apps is desirable.
  • Strong documentation, policy development, and controls testing skills.
  • Familiarity with NIST 800 series and FISMA guidance.

Responsibilities

  • Develop and maintain technology compliance programs and policies.
  • Prepare documentation for annual FISMA audits and IV&V efforts.
  • Identify vulnerabilities and design remediation with the team.
  • Provide status updates, risk assessments, and audit findings.

Skills

IT audit
Information security
Verbal & written communication
Project management

Education

CISSP
CISA

Tools

NIST 800 series
FISMA framework

Job description

FISMA External Audit Consultant

Washington, DC -- Remote or Hybrid
Per Federal contract U.S. citizenship is required
Must be able to obtain PASS federal background check for Public Trust clearance


Long Term W2 or C2C Contract

Project Description

FISMA Compliance Support


Background

The Information Security & Privacy Branch of the Division of Information Technology propose to engage two to three contractors to provide compliance and information security support to in preparation for annual FISMA audits, provide support in conducting an independent verification and validation of current policies and procedures, and assist with remediation of process improvements. This will also include assisting with ongoing IV&V assessments and OIG audit support.


Requirements


  • Experience with cloud and on-premise applications desirable.

  • Simultaneously works on several complex assignments requiring analysis of intricately related complex variables.

  • Experience with leading and successfully developing audit and security related system documentation and requirements desired.

  • Must have at least ten years of progressively responsible experience in the information technology arena as an IT auditor, IT security analyst, IT manager, business analyst, system administrator or a combination of these.

  • Possess clear, concise, and effective verbal and written communication and project management skills needed for functioning in an unstructured matrix management environment.

  • Experience with assessing financial systems leveraging NIST 800 series, or FISMA Compliance strongly desired.

  • CISSP or CISA certification strongly desired.


Key Responsibilities


  • Participates in the process to evaluate, develop, maintain, and update the technology compliance program. Advises the technology support officer and technology managers on compliance, information security, and internal controls.

  • Prepares the technology departments for the yearly FISMA audits.

  • Assist in developing required documents in support of internal FISMA reviews.

  • Develop solutions with team members to minimize vulnerabilities.

  • Advises the technology officer of compliance issues and recommends solutions

  • Provides a weekly status report to the COR documenting concerns, issues, risks, and progress.

  • Recommends and helps implement automated solutions in the areas of compliance, auditing, and vulnerability detection for the branch.

  • Designs, tests, and implements audit mechanisms to detect non-compliance and to support evaluations of evidentiary materials. Ensures proper audit trails are recorded.

  • Creates audit and monitoring reports used by the team, as directed.

  • Thoroughly assess and validate the audit findings for identified systems of record against Board policies. Document findings and recommendations.

  • Crosswalk the evidence and latest Board Information Security Program (BISP) against the CISA and FedRamp standards and procedures and document the results.

  • Provide recommendations, develop action plans, and help implement capabilities to improve compliance and security practices.

  • Document updates to compliance related policies, processes, procedures, and/or standards as directed.


Anticipated Period of Performance

START DATE: September 14, 2026
END DATE: December 31, 2027


Place of Performance

100% Remote or option to periodically work on-site at FRB locations, Washington, DC


Citizen Status

NOTE: ship required per federal contract

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

FISMA Compliance Audit Consultant — Remote/Hybrid
FISMA Compliance Audit Consultant — Remote/Hybrid

System One • Washington

On-site
USD 90,000 - 130,000
Remote External IT Audit Consultant for FISMA & Security
Remote External IT Audit Consultant for FISMA & Security

Isys Technologies • Washington

Remote
USD 120,000 - 170,000
External Audit Consultant
External Audit Consultant

Ampcus, Inc • Washington

On-site
USD 90,000 - 130,000
IT Compliance Manager
IT Compliance Manager

MANTECH • Quantico (VA)

On-site
USD 110,000 - 160,000
IT Audit Advisory Consultant/FISCAM SME
IT Audit Advisory Consultant/FISCAM SME

Peraton • Washington

On-site
USD 135,000 - 216,000
25 days PTO
Bonus plan
Subsidized benefits
IT Audit Advisory Consultant/FISCAM SME
IT Audit Advisory Consultant/FISCAM SME

Peraton • Riverdale Park (MD)

On-site
USD 135,000 - 216,000
Generous PTO
Annual bonus plan
Subsidized benefits coverage
External Audit Consultant - Remote
External Audit Consultant - Remote

I2X/ISYS Technologies • Washington

Hybrid
USD 110,000 - 117,000
Competitive compensation
Comprehensive benefits package
IT Audit Advisory Consultant/FISCAM SME
IT Audit Advisory Consultant/FISCAM SME

Peraton • Herndon (VA)

On-site
USD 135,000 - 216,000
25 days PTO
Bonus plan
External Auditor Consultant
External Auditor Consultant

Ampcus, Inc • Washington

On-site
USD 90,000 - 140,000
Compliance & Audit Support (Mid)
Compliance & Audit Support (Mid)

Koniag Services, Inc. • Washington, Northern (KY)

On-site
USD 70,000 - 110,000
Health insurance
Dental insurance
Vision insurance
+2