IT Security Auditor - Vendor Risk & Compliance Lead

STI

Richmond (VA)

On-site

USD 90,000 - 120,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

SCC Health Benefit Exchange is seeking an experienced IT Auditor in Richmond, VA to support the transition to a new security standard and strengthen third-party risk management. This on-site role requires auditing and evaluating controls across vendors and partners to ensure compliance.

The position involves designing assessment tools, guiding policy updates, and leading audits to identify gaps and remediation steps, with interviews and document reviews forming part of the process.

Qualifications

  • Experience interpreting and implementing updated security requirements.
  • Assess current security controls and processes against CMS, IRS, and SCC security standards.
  • Identify gaps and recommend remediation steps to achieve and maintain compliance.
  • Plan, lead, and execute development and updates to policies, procedures, and documentation to reflect requirements.
  • Design, implement, and train on the process for assessing partners and vendors, ensuring alignment with security standards.
  • Develop assessment tools, workflows, and scoring model to evaluate and measure the effectiveness and compliance of vendor and partner security controls.
  • Evaluate the security posture of vendors and partners to ensure information security contractual, information sharing, and data sharing agreement requirements are met.
  • Test the effectiveness of operational and management controls using interviews, document reviews, and observation.
  • Analyze, assess, report, and present on audit findings, risk exposure, and recommendations.
  • Support information security continuous monitoring and incident response programs.
  • Perform related work as required.

Responsibilities

  • Assess current security controls and processes against CMS, IRS, and SCC security standards.
  • Identify gaps and recommend remediation steps to achieve and maintain compliance.
  • Plan, lead, and execute development and updates to policies, procedures, and documentation to reflect requirements.
  • Design, implement, and train on the process for assessing partners and vendors, ensuring alignment with security standards.
  • Develop assessment tools, workflows, and scoring model to evaluate and measure the effectiveness and compliance of vendor and partner security controls.
  • Evaluate the security posture of vendors and partners to ensure information security contractual, information sharing, and data sharing agreement requirements are met.
  • Test the effectiveness of operational and management controls using interviews, document reviews, and observation.
  • Analyze, assess, report, and present on audit findings, risk exposure, and recommendations.
  • Support information security continuous monitoring and incident response programs.
  • Perform related work as required.

Job description

SCC Health Benefit Exchange is seeking an experienced IT Auditor in Richmond, VA to support the transition to a new security standard and strengthen third-party risk management. This on-site role requires auditing and evaluating controls across vendors and partners to ensure compliance.

The position involves designing assessment tools, guiding policy updates, and leading audits to identify gaps and remediation steps, with interviews and document reviews forming part of the process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Auditor — Vendor Risk & Compliance
IT Security Auditor — Vendor Risk & Compliance

STI • Richmond (VA)

On-site
USD 90,000 - 120,000
IT Security Auditor - Richmond, VA/Hybrid
IT Security Auditor - Richmond, VA/Hybrid

STI • Richmond (VA)

On-site
USD 90,000 - 120,000
IT Security Auditor
IT Security Auditor

STI • Richmond (VA)

On-site
USD 90,000 - 120,000
Strategic IT Risk Assessor – Security & Compliance
Strategic IT Risk Assessor – Security & Compliance

rose international • Richmond (VA)

On-site
USD 70,000 - 90,000
IT Auditor - Remote
IT Auditor - Remote

PEOPLECORP AMERICA • Austin (TX)

Remote
USD 80,000 - 110,000
Senior IT Auditor - Governance, Risk & Controls Leader
Senior IT Auditor - Governance, Risk & Controls Leader

FedTec • Richmond (VA)

On-site
USD 110,000 - 140,000
Health & Wellness program
Paid time off
401(k) and disability coverage
+1
IT Auditor – Security & Risk Compliance Specialist
IT Auditor – Security & Risk Compliance Specialist

DGS Office of External Affairs • Chesterfield Court House (VA)

On-site
USD 90,000 - 120,000
Remote IT Auditor: Risk, Compliance & Controls
Remote IT Auditor: Risk, Compliance & Controls

Commonwealth of VA Careers • Chesterfield Court House (VA)

On-site
USD 90,000 - 105,000
Telework eligible
IT Auditor
IT Auditor

DGS Office of External Affairs • Chesterfield Court House (VA)

On-site
USD 90,000 - 120,000
Mid-Senior Onsite IT Security Analyst – Richmond
Mid-Senior Onsite IT Security Analyst – Richmond

Focused HR Solutions • Richmond (VA)

On-site
USD 80,000 - 120,000