We connect our employees with some of the best opportunities around.
Time and again, our employees tell us that the most important thing we offer is respect. Federal Staffing Solutions puts people to work in all types of jobs. When you work with us, you build a relationship with a team of employment professionals in your community who have, in turn, built professional relationships with the businesses that are hiring.
We are looking for a External Audit Consultant to work Remotely supporting our client.
Location:Â Remote (Candidate must reside in the United States)
Clearance: US Citizen
Salary Rate: $105,000
MUST HAVE EXPERIENCE WORKING FOR A FINANCIAL SERVICES GOVERNMENT AGENCY
BACKGROUND: The Information Security & Privacy Branch of the Division of InformationÂ
Technology propose to engage two to three contractors to provide compliance and informationÂ
security support to in preparation for annual FISMA audits, provide support in conducting anÂ
independent verification and validation of current policies and procedures, and assist withÂ
remediation of process improvements. This will also include assisting with ongoing IV&VÂ
assessments and audit support.Â
Technology propose to engage two to three contractors to provide compliance and informationÂ
security support to in preparation for annual FISMA audits, provide support in conducting anÂ
independent verification and validation of current policies and procedures, and assist withÂ
remediation of process improvements. This will also include assisting with ongoing IV&VÂ
assessments and audit support.Â
REQUIREMENTS:Â
• Experience with cloud and on-premis applications desirable.Â
• Simultaneously works on several complex assignments requiring analysis of intricatelyÂ
related complex variables.Â
• Experience with leading and successfully developing audit and security related systemÂ
documentation and requirements desired.Â
• Must have at least ten years of progressively responsible experience in the informationÂ
technology arena as an IT auditor, IT security analyst, IT manager, business analyst,Â
system administrator or a combination of these.Â
• Possess clear, concise, and effective verbal and written communication and projectÂ
management skills needed for functioning in an unstructured matrix managementÂ
environment.Â
• Experience with assessing financial systems leveraging NIST 800 series, or FISMAÂ
Compliance strongly desired.Â
• CISSP or CISA certification strongly desired.Â
• Experience with cloud and on-premis applications desirable.Â
• Simultaneously works on several complex assignments requiring analysis of intricatelyÂ
related complex variables.Â
• Experience with leading and successfully developing audit and security related systemÂ
documentation and requirements desired.Â
• Must have at least ten years of progressively responsible experience in the informationÂ
technology arena as an IT auditor, IT security analyst, IT manager, business analyst,Â
system administrator or a combination of these.Â
• Possess clear, concise, and effective verbal and written communication and projectÂ
management skills needed for functioning in an unstructured matrix managementÂ
environment.Â
• Experience with assessing financial systems leveraging NIST 800 series, or FISMAÂ
Compliance strongly desired.Â
• CISSP or CISA certification strongly desired.Â
KEY RESPONSIBILITIESÂ :
• Participates in the process to evaluate, develop, maintain, and update the technologyÂ
compliance program. Advises the technology support officer and technology managersÂ
on compliance, information security, and internal controls.Â
• Prepares the technology departments for the yearly FISMA audits.Â
• Assist in developing required documents in support of internal FISMA reviews.Â
• Develop solutions with team members to minimize vulnerabilities.Â
• Advises the technology officer of compliance issues and recommends solutionsÂ
• Provides a weekly status report to the COR documenting concerns, issues, risks, andÂ
progress.Â
• Recommends and helps implement automated solutions in the areas of compliance,Â
auditing, and vulnerability detection for the branch.Â
• Designs, tests, and implements audit mechanisms to detect non-compliance and toÂ
support evaluations of evidentiary materials. Ensures proper audit trails are recorded.Â
• Creates audit and monitoring reports used by the team, as directed.Â
The External Auditor Consultant shall deliver, but not limited to, the following:Â
• Thoroughly assess and validate the audit findings for identified systems of record againstÂ
Board policies. Document findings and recommendations.Â
• Crosswalk the evidence and latest Board Information Security Program (BISP) againstÂ
the CISA and FedRamp standards and procedures and document the results.Â
• Provide recommendations, develop action plans, and help implement capabilities toÂ
improve compliance and security practices.Â
• Document updates to compliance related policies, processes, procedures, and/or standardsÂ
as directed.
compliance program. Advises the technology support officer and technology managersÂ
on compliance, information security, and internal controls.Â
• Prepares the technology departments for the yearly FISMA audits.Â
• Assist in developing required documents in support of internal FISMA reviews.Â
• Develop solutions with team members to minimize vulnerabilities.Â
• Advises the technology officer of compliance issues and recommends solutionsÂ
• Provides a weekly status report to the COR documenting concerns, issues, risks, andÂ
progress.Â
• Recommends and helps implement automated solutions in the areas of compliance,Â
auditing, and vulnerability detection for the branch.Â
• Designs, tests, and implements audit mechanisms to detect non-compliance and toÂ
support evaluations of evidentiary materials. Ensures proper audit trails are recorded.Â
• Creates audit and monitoring reports used by the team, as directed.Â
The External Auditor Consultant shall deliver, but not limited to, the following:Â
• Thoroughly assess and validate the audit findings for identified systems of record againstÂ
Board policies. Document findings and recommendations.Â
• Crosswalk the evidence and latest Board Information Security Program (BISP) againstÂ
the CISA and FedRamp standards and procedures and document the results.Â
• Provide recommendations, develop action plans, and help implement capabilities toÂ
improve compliance and security practices.Â
• Document updates to compliance related policies, processes, procedures, and/or standardsÂ
as directed.
Equal Opportunity Employer
Learn more about this Employer on their Career Site
