IT Systems Engineers / Compliance Audit Technicians are responsible for monitoring our compliance programs for Infrastructure Services. This includes overseeing and evaluating government and commercial product and program regulations and requirements to promote and sustain organization integrity. The position is also responsible for identifying, defining, communicating, and managing the compliance program requirements and key performance indicators for government and commercial business.
Top Three Required Skills:
1. Experience implementing and supporting the following Cybersecurity Frameworks: NIST 800-53, DISA, CIS, CMS ARS requirements.
2. Familiarity with basic enterprise audits, including SOC2, MARS-E, FISMA, Cyber Security Readiness Inspection (CCRI) etc.
3. Experience interfacing with internal and external auditors.
• IT Systems Engineers / Compliance Audit Technicians are responsible for maturing Audit Program.
• Resource will interface with various audit and security personnel, providing policies, procedures, and device evidence required for specific platforms.
• Interpret policies and procedures for accuracy and technical sensibility.
• Manage documentation and evidence repositories for access during audit events (Automated Scans, Manual Scripting, etc.).
• Develop policies and procedures and ensure that the current procedures are updated with current information and available for review for compliance with CMS, ARS, & DISA policies, procedures, and standards.
• Ability to navigate the DOD DISA public-facing site to include the STIGS Document Library & the STIG Viewer application (xccdf).
• Participate in discussions with all levels of leadership to articulate current state of the program.
• Advise on mitigation and remediation strategies for any variances or ensure they are documented in a Corrective Action Plan (CAP).
• Perform hardware and software evaluations to maintain established baseline integrity.
• Provide evidence to assist with internal and external audits.
• Ensure self-inspection checklists are completed against policies, procedures, and evidence for compliance audits.
• Ensure self-inspection checklists are completed against defined infrastructure platform baselines.
• Gather evidentiary documentation to support audit findings from compliance audits periodically throughout the year.
• Ability to navigate a SQL relational database: clauses, expressions, predicates, queries, and statements.
• Other duties as assigned.
• Four or more years demonstrated proficiency and experience in design, implementation, monitoring and troubleshooting technology.
• Competent working in one or more environments highly integrated with an operating system.
• Extensive experience implementing and administering/managing technical solutions in major, large-scale system implementations.
• High critical thinking skills to evaluate alternatives and present solutions that are consistent with business objectives and strategy.
• Ability to manage tasks independently and take ownership of responsibilities.
• Ability to learn from mistakes and apply constructive feedback to improve performance.
• Ability to communicate technical information clearly and articulately.
• Ability to adapt to a rapidly changing environment.
• Proficient working with various audit infrastructure tools/technologies such as Nessus, ACAS, and Nexpose.
1. Experience as a primary liaison between Infrastructure Service organizations and Audit organizations.
2. Managed requirements within two-three audits.
3. This position has some accountability to consult independently with operational areas and senior leadership across the Enterprise.
4. Identifying, defining, communicating, and managing the compliance audit program requirements and performance indicators.
5. Bachelor’s degree in an IT related field or equivalent work experience.
6. Certifications: Comptia Security Plus or CISSP.
3-5 years of related work experience or equivalent combination of transferable experience demonstrating proficiency and experience in design, implementation, monitoring and troubleshooting technology
Related Bachelor's degree in an IT related field or relevant work experience