Job Summary:
The IT Audit Liaison will support the Enterprise Information Security Office (EISO) and Governance, Risk & Compliance (GRC) Department with internal and external IT audits, compliance assessments, control evaluations, and remediation activities.
The IT Audit Liaison will support the Enterprise Information Security Office (EISO) and Governance, Risk & Compliance (GRC) Department with internal and external IT audits, compliance assessments, control evaluations, and remediation activities.
Key Responsibilities:
- Support IT audits and regulatory reviews, including GAAP/Single Audit, PA Auditor General, Attorney General, and Bureau of Audits.
- Review technical evidence and documentation for compliance with laws, policies, regulations, and security standards.
- Evaluate IT controls using NIST CSF, NIST 800-53, ISO 27001, and Commonwealth security policies.
- Identify control gaps, document findings, and recommend corrective actions.
- Support audit responses, evidence collection, remediation tracking, and risk reporting.
- Develop/maintain automated compliance and audit workstreams.
- Create dashboards, metrics, and executive reports on audit and compliance status.
- Perform risk-based assessments and support governance, risk management, and internal control initiatives.
Required/Desired Skills:
- IT auditing and cybersecurity governance/risk management
- NIST CSF, NIST 800-53, ISO 27001
- IT controls, compliance, and risk assessments
- Audit documentation, evidence collection, and remediation
- Dashboards, metrics, and executive reporting
- Strong analytical and communication skills
Preferred: CISA, CRISC, CISM, or equivalent certification; experience with IT audits, regulatory examinations, or compliance assessments.
Learn more about this Employer on their Career Site
