Senior IT Auditor (FedRAMP)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior IT Auditor (FedRAMP): Performing cybersecurity audits and compliance assessments for cloud service providers with an accent on NIST 800-53 controls. Focus on reviewing cloud infrastructure architectures, validating encryption configurations, and analyzing vulnerability reports.
Location: Remote (USA) - Must be authorized to work in the US (E-Verify used)
Company
A Top 50 CPA firm and leading provider of cybersecurity attestation and compliance services, specializing in FedRAMP and CMMC assessments.
What you will do
- Execute hands-on project tasks for FedRAMP compliance assessments.
- Interview Cloud Service Provider (CSP) Subject Matter Experts across HR, SecDevOps, and SOC/NOC domains.
- Perform technical walkthroughs of cloud architectures including AWS, Azure, and OCI.
- Review system security configurations against NIST 800-53 security control baselines.
- Analyze vulnerability reports and validate encryption configurations.
- Draft project deliverables and manage client expectations to ensure high-quality service delivery.
Requirements
- Bachelor's degree in accounting, finance, business, technology, or equivalent professional experience.
- At least one year of experience in professional services focusing on IT, financial, or operational auditing, or risk consulting.
- Must maintain at least one FedRAMP required R311 certification (e.g., CISA, CISSP, CCNA Security, CySA+, etc.).
- Must be authorized to work in the US ( uses E-Verify).
- Ability to travel annually for internal training, team meet-ups, and client-specific needs.
Culture & Benefits
- Flexible and balanced remote work environment.
- Culture centered on the core value "People Come First".
- Support for continuing education and pursuing industry-accepted certifications.
- Certified "Great Place to Work" and recognized as a "Best Firm to Work For".
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →