ABA Testing Analyst - IT & Information Security Controls
Position Title: ABA Testing Analyst - IT & Information Security Controls
Location: Vienna, VA - Hybrid (3 days onsite per week)
Clearance Requirements: None specified
Position Status: Contract
Pay Rate: $40.00-$43.00/hour
Position Description
Seneca Resources is seeking an ABA Testing Analyst to support Asset-Based Assessment (ABA) and testing activities across IT and Information Security controls. This role is ideal for an early-to-mid-career professional with experience in IT audit, cybersecurity risk, controls testing, information security assessments, or governance, risk, and compliance (GRC).
The analyst will support the full assessment lifecycle, including planning and scoping, control walkthroughs, test strategy development, evidence review, issue documentation, reporting, and communication with business partners and leadership. The successful candidate will be comfortable working in an Agile environment and collaborating with stakeholders across multiple levels of an organization.
Key Responsibilities
Plan and scope Asset-Based Assessments, including developing communications, risk and control matrices, scope documents, and supporting assessment materials.
Conduct control walkthroughs with business partners to identify actual versus expected control activities.
Develop and execute control testing strategies to evaluate the effectiveness of IT and Information Security controls.
Review and document testing evidence and work performed in accordance with applicable Internal Audit reperformance standards.
Identify, document, and communicate control deficiencies, issues, risks, and observations.
Prepare clear and concise assessment reports and supporting documentation.
Present assessment results, findings, and conclusions to leadership and key stakeholders.
Collaborate with business partners, management, control owners, third parties, and other stakeholders throughout the assessment lifecycle.
Conduct research and analysis related to information security controls, regulatory requirements, and industry frameworks.
Support additional testing, risk, compliance, and information security initiatives as assigned.
Required Skills/Education
1-5 years of experience in IT controls testing, IT audit, information security risk, cybersecurity assessments, GRC, or a related field.
Experience with control testing and/or one or more areas of the Three Lines of Defense, including Internal Audit, Enterprise Risk Management (ERM), or First Line functions.
Experience supporting IT audits, information security risk assessments, or cybersecurity control assessments.
Knowledge of information security regulations, standards, and frameworks, including:
NIST Cybersecurity Framework and NIST 800 Series
FFIEC
NCUA
GLBA
ISO 27001/27002
CIS/SANS controls
PCI DSS
Strong understanding of IT and Information Security controls, risk management, compliance, and control assessment principles.
Ability to work effectively with employees, management, business stakeholders, control owners, and third parties.
Strong analytical, research, problem-solving, planning, and organizational skills.
Excellent verbal and written communication skills, including technical writing and assessment reporting.
Ability to present findings and recommendations clearly and concisely to leadership.
Strong relationship-building skills, including the ability to establish trust, demonstrate diplomacy, and collaborate effectively.
Proficiency with Microsoft Word, Excel, and other standard productivity tools.
Bachelor's degree in Business, Information Systems, Cybersecurity, Information Technology, or a related field, or equivalent work/military experience.
Relevant certifications such as CISA, CISSP, CCSP, CRISC, or other Information Security/GRC certifications are preferred.
Additional Requirement
Work Authorization
Candidates must be authorized to work in the United States. Sponsorship is not available for this position.
Why This Opportunity?
This role offers an opportunity to build deeper expertise across IT controls testing, cybersecurity risk, information security compliance, audit, and GRC while working directly with business and technology stakeholders. Candidates who enjoy analyzing controls, identifying risks, communicating findings, and contributing to continuous improvement will be well positioned for success.
About Seneca Resources
At Seneca Resources, we are more than just a staffing and consulting firm, we are a trusted career partner. With offices across the U.S. and clients ranging from Fortune 500 companies to government organizations, we provide opportunities that help professionals grow their careers while making an impact.
When you work with Seneca, you're choosing a company that invests in your success, celebrates your achievements, and connects you to meaningful work with leading organizations nationwide. We take the time to understand your goals and match you with roles that align with your skills and career path.
Our consultants and contractors enjoy competitive pay, comprehensive health, dental, and vision coverage, 401(k) retirement plans, and the support of a dedicated team who will advocate for you every step of the way.
Seneca Resources is proud to be an Equal Opportunity Employer, committed to fostering a diverse and inclusive workplace where all qualified individuals are encouraged to apply.
| Location | Vienna, VA |
| Industry | Staffing/Employment Agencies |
| Salary | $40–$43 Per Hour |
| Company Size | 50 to 99 employees |
| Year Founded | 1993 |
| Website | http://www.qednational.com/ |
QED National is a certified Women-Owned Business Enterprise with WBE certification in New York City, New York State, New Jersey and Delaware. A trusted IT advisor to both public and private sector customers, QED National is headquartered in New York City with offices in Albany, NY. Driven by 24 years of industry expertise and guided by strong, ethical practices, QED National helps clients achieve their business objectives by providing innovative IT consulting, reliable staff augmentation and scalable technology solutions that are custom tailored for their needs. Our outstanding service has earned us an extraordinary client retention rate of ninety-five percent.
PRACTICE AREAS
Cyber / Information Security
IT Management Consulting
IT Staff Augmentation
Technology Solutions
QED National is led by a strong management team, under the direction of founder and president, Colleen Molter. Working with selected organizations, chosen for their outstanding products and support services, QED National delivers expert solutions ranging from IT assessments and governance to intelligent data storage and staff augmentation. It all adds up to comprehensive, customized IT business solutions.
A New York City and New York State Certified Women-Owned Business Enterprise, QED National is a privately held company in continuous operation since 1993. Recipient of New York City, New York State, Florida, California and Fortune 500 contracts, QED National is proud to have sustained success and growth, including “Inc. Magazine’s 5000 Fastest Growing Firms in America” for nine consecutive years —2009 through 2017. View our full roster of awards.
QED National humbly, yet firmly, acknowledges its reputation among its clients as a partner that responds diligently—and expeditiously—to provide the highest quality services. The QED National team ambitiously looks forward to all future opportunities to provide such services.
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder