Vaco LLC logo

IT Auditor

Vaco LLC
  • Columbus, OH
  • Remote
    1 day ago
    Vaco LLC

    Job Description

    Contract IT Auditor / Risk Assessor

    Location: Remote — must work during Eastern Standard Time business hours

    Engagement: Contract, initial term of 3-5 months with potential extension

    Start: As soon as possible

    Reports to: IT Risk, Compliance, or Internal Audit Leadership

    About the Role

    We are seeking a technically capable Contract IT Auditor / Risk Assessor to help relaunch and execute our IT risk and controls assessment methodology.

    Our business risk program has been operating successfully for more than a year. However, we have determined that our approach to IT risk and control assessments needs to be rebuilt. We are starting fresh with a revised methodology based on the organization’s top 20 IT risk areas and business functions.

    The methodology, control requirements, and recommended testing procedures will be provided. Your responsibility will be to execute the assessment process: identify the appropriate Control Owner, explain the control and testing expectations, request and evaluate evidence, document the results, identify gaps, and help move approved risks and controls into our GRC platform.

    This is a hands-on role for someone who combines IT audit and GRC experience with enough technical depth to engage credibly with infrastructure, cybersecurity, application, and operations teams. The ideal candidate is broad technically—“an inch deep and a mile wide”—and can ask informed questions across a wide range of IT environments.

    Key Responsibilities

    • Execute risk and control assessments across the organization’s prioritized IT risk areas.
    • Review provided control descriptions and recommended test procedures, then translate them into practical assessment activities.
    • Identify and engage the appropriate Control Owner or technical subject-matter expert.
    • Explain the purpose of each control, the associated risk, and the evidence required to demonstrate that the control is operating.
    • Request, collect, organize, and evaluate appropriate evidence, such as:
      • Policies and procedures.
      • System reports and configuration exports.
      • Access reviews and approval records.
      • Change tickets and release documentation.
      • Vulnerability and patch-management reports.
      • Security monitoring records and logs.
      • Backup, recovery, and operational reports.
      • Screenshots or other system-generated evidence.
    • Assess whether controls are properly designed and operating effectively.
    • Distinguish between complete, incomplete, insufficient, and unsupported evidence.
    • Challenge unclear, inconsistent, or unsupported responses professionally and constructively.
    • Identify control gaps, exceptions, deficiencies, and potential risks.
    • Document testing procedures, evidence reviewed, results, conclusions, and recommended remediation.
    • Follow up with Control Owners to resolve open questions and obtain missing evidence.
    • Coordinate approval of assessed risks and control results with appropriate stakeholders.
    • Work with Amber to upload approved risks, controls, evidence, and assessment results into the GRC platform.
    • Help establish consistent, audit-ready documentation standards within the GRC system.
    • Train and coach Control Owners so they can perform future assessments and maintain their controls independently.
    • Educate Control Owners on:
      • The business and technology risks addressed by each control.
      • Their control responsibilities.
      • Acceptable evidence.
      • Testing frequency and procedures.
      • How to document and upload evidence in the GRC platform.
    • Support current PCI audit activities and FDIC-related requests as needed.
    • Track outstanding requests, findings, action items, and remediation commitments through completion.
    • Escalate unresponsive Control Owners, unsupported assertions, or material control concerns appropriately.

    Technical Scope

    The successful candidate does not need to be the deepest expert in every technology. However, they must have sufficient practical knowledge to understand how controls operate and to determine whether evidence is credible.

    Relevant experience may include:

    • IT general controls.
    • Identity and access management.
    • Privileged access and segregation of duties.
    • Patch and vulnerability management.
    • Endpoint management, including tools such as Microsoft Intune or SCCM.
    • Change and release management.
    • Configuration and security baselines.
    • Network and infrastructure operations.
    • Cloud platforms and SaaS applications.
    • Backup, disaster recovery, and business continuity.
    • Security operations, logging, and monitoring.
    • Incident response.
    • Third-party and vendor risk.
    • Data protection and encryption.
    • Application controls and system interfaces.
    • Asset and configuration management.
    • IT operations and service management.

    For example, when assessing a Patch Management control, you should be able to understand how patch compliance is measured, what systems are in scope, how exceptions are handled, and whether reports from Intune, SCCM, vulnerability-management platforms, or related tools sufficiently support the control conclusion.

    Required Qualifications

    • 5+ years of experience in IT audit, technology risk, cybersecurity compliance, GRC, controls assurance, or a closely related field.
    • Experience executing IT control assessments from evidence request through documented conclusion.
    • Strong understanding of IT general controls and cybersecurity control environments.
    • Experience working directly with technical Control Owners, engineers, system administrators, and IT leadership.
    • Ability to understand a broad range of technologies and operational processes without requiring deep specialization in a single platform.
    • Experience evaluating whether evidence is relevant, sufficient, reliable, and complete.
    • Strong written documentation and workpaper skills.
    • Experience identifying control deficiencies and explaining risk in clear business language.
    • Experience using a GRC platform or structured risk-and-control repository.
    • Ability to manage multiple assessments, evidence requests, deadlines, and stakeholders independently.
    • Strong interpersonal skills and the confidence to respectfully challenge incomplete or questionable responses.
    • Ability to work remotely and maintain consistent availability during Eastern Time business hours.

    Preferred Qualifications

    • Experience in a regulated financial-services environment.
    • Experience supporting PCI DSS, FDIC, FFIEC, GLBA, SOX, NIST, CIS, or similar requirements.
    • Experience with GRC platforms such as ServiceNow GRC, Archer, AuditBoard, OneTrust, LogicGate, or comparable systems.
    • CISA, CISSP, CRISC, CIA, CISM, or comparable certification.
    • Experience creating Control Owner training or control self-assessment materials.
    • Experience supporting external audits, regulatory examinations, or remediation programs.
    • Familiarity with Microsoft security and endpoint-management technologies, including Intune, SCCM, Entra ID, and related reporting.

    Success Measures

    Success in this role will be measured by the ability to:

    • Complete assessments across the prioritized risk areas using the new methodology.
    • Obtain timely and appropriate evidence from Control Owners.
    • Produce clear, defensible, audit-ready testing documentation.
    • Identify unsupported claims, control gaps, and meaningful risk issues.
    • Move approved risks and controls into the GRC platform accurately.
    • Reduce the amount of follow-up required from internal IT risk and compliance staff.
    • Enable Control Owners to perform future testing and evidence submissions independently.
    • Support timely responses to PCI and FDIC-related requirements.
    • Establish a repeatable, sustainable assessment process rather than simply completing one-time requests.


    By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions.

    EEO Notice

    Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law.

    Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact

    HR@vaco.com

    .

    Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal.

    Representation Notice

    By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal.

    For residents of Ontario, Canada: Based on Highspring’s discussions with its Client, Highspring’s understanding is that this position for employment is a current vacancy (either through Highspring as a contractor or with the client directly).

    Privacy Notice

    Vaco by Highspring and its parents, affiliates, and subsidiaries (“we,” “our,” or “Vaco by Highspring”) respects your privacy and are committed to providing transparent notice of our policies.

    • California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here.
    • Virginia residents may access our state specific policies here.
    • Residents of all other states may access our policies here.
    • Canadian residents may access our policies in English here and in French here.
    • Residents of countries governed by GDPR may access our policies here.

    Additionally, submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. More details about Vaco by Highspring’s use of AI can be found here (https://www.highspring.com/ai-use-notices/). Further assessment of candidates beyond this initial phase will be conducted by recruiters and hiring managers. Vaco by Highspring does not know and cannot opine on if its client’s use of AI products in hiring.

    Pay Transparency Notice

    Determining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to:

    • the individual’s skill sets, experience and training;
    • licensure and certification requirements;
    • office location and other geographic considerations;
    • other business and organizational needs.

    With that said, as required by local law, Vaco by Highspring believes that the following salary range referenced above reasonably estimates the base compensation for an individual hired into this position in geographies that require salary range disclosure. The individual may also be eligible for discretionary bonuses.

    Numbers & Facts

    LocationColumbus, OH (
    Remote
    )
    IndustryStaffing/Employment Agencies
    Company Size2,500 to 4,999 employees
    Year Founded2002
    Websitehttp://www.vaco.com/

    About Company

    Vaco provides expert consulting, permanent placement, executive search and strategic staffing for companies around the world, in the areas of accounting, finance, technology, healthcare, operations, administration and more. As a premier talent solutions firm, Vaco connects people to their dream jobs and helps leading companies find talent to grow their business. Since its founding in 2002, Vaco has grown to more than 35 offices across the globe, 700+ employees, more than 3,000 consultants and $450M in revenue. Vaco has been named to Inc. magazine’s list of the fastest-growing private companies for past 11 years and is dedicated to developing long-term relationships, life-long careers and creative client solutions.

    Skills

    • Artificial Intelligence (AI)unmatched
    • Asset Managementunmatched
    • Coachingunmatched
    • Computer Securityunmatched
    • Configuration Managementunmatched
    • Data Recoveryunmatched
    • Documentationunmatched
    • Documentation Standardsunmatched
    • Endpoint Securityunmatched
    • English Languageunmatched
    • Error Handlingunmatched
    • Establish Prioritiesunmatched
    • External Auditunmatched
    • Federal Deposit Insurance Corp (FDIC)unmatched
    • Financial Servicesunmatched
    • Hair Stylingunmatched
    • IT Service Management (ITSM)unmatched
    • Identity Data Managementunmatched
    • Incident Responseunmatched
    • Information Systems/Technology IS/IT Administrationunmatched
    • Information Technology & Information Systemsunmatched
    • Information Technology/Systems Auditunmatched
    • Internal Auditunmatched
    • Internet Securityunmatched
    • Interpersonal Skillsunmatched
    • Leadershipunmatched
    • Microsoft Product Familyunmatched
    • Needs Assessmentunmatched
    • Operations Managementunmatched
    • Operations Processesunmatched
    • PCIunmatched
    • PCI-DSSunmatched
    • Regulationsunmatched
    • Release Management/Engineeringunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Sarbanes-Oxley Act (SOX)unmatched
    • Security Monitoringunmatched
    • ServiceNowunmatched
    • Software Patchesunmatched
    • State Laws and Regulationsunmatched
    • System Center Configuration Manager (SCCM)unmatched
    • Systems Administration/Managementunmatched
    • Technical Leadershipunmatched
    • Test Requirementsunmatched
    • Testingunmatched
    • Time Managementunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Work From Homeunmatched
    • Writing Skillsunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder