IT GRC Auditor / IT Compliance Auditor
Minimum 10+ years of experience in IT Audit, Cybersecurity GRC, IT Risk Management, Regulatory Compliance, Privacy, and Information Security controls.
Strong hands-on experience conducting end-to-end audits and compliance assessments for PCI DSS, HIPAA, HITECH, ISO 27001, SOC 2 Type 2, GDPR, CCPA, Privacy regulations, and Third-Party/Vendor Risk Management.
Demonstrated expertise in audit planning, risk assessments, control design and operating-effectiveness testing, evidence validation, gap analysis, audit findings, remediation tracking, and audit closure.
Strong knowledge of cybersecurity and IT controls covering IAM/PAM, network and cloud security, vulnerability management, encryption, data protection/DLP, logging/SIEM, incident response, change management, backup/DR, and secure SDLC.
Experience performing Third-Party/Vendor Risk Assessments, including due diligence, security questionnaires, SOC 1/SOC 2 report reviews, vendor risk scoring, contract/control reviews, remediation, and continuous monitoring.
Strong understanding of NIST CSF, NIST 800-53, COBIT, CIS Controls and ISO 27001, including control mapping across multiple regulatory and compliance frameworks.
Experience with GRC/audit platforms such as ServiceNow GRC/IRM, Archer, OneTrust, AuditBoard, MetricStream or equivalent, with strong reporting and documentation capabilities.
Ability to develop and maintain Risk & Control Matrices (RCMs), audit workpapers, policies, procedures, risk registers, compliance dashboards, remediation plans, and executive-level audit reports.
Proven ability to work directly with CISO/CIO organizations, IT teams, Legal, Privacy, Risk, Compliance, internal/external auditors, vendors, and senior management to resolve audit and compliance issues.
Excellent communication and analytical skills with the ability to translate technical control deficiencies into business risk, regulatory impact, and actionable remediation recommendations.
Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Accounting, Risk Management, or related discipline; relevant advanced degree is preferred.
Professional certifications such as CISA, CISM, CRISC, CISSP, ISO 27001 Lead Auditor/Implementer, CIPP, CCSK/CCSP, or PCI-related credentials are highly preferred.
...