• Dauphin County- PA, PA
    3 days ago

    Job Description

    • Job Title: OA-EISO-Audit Liaison
    • Implementation partner: VDart
    • Job Type: long term contract 
    • Visa Type: No sponsor available for this job (Only local candidate or someone willing to relocate are accepted for this role)
    • Location: Dauphin County- PA
    • Shift Timing: Days (8 hrs a day and 5 days a week)
    This role shall:JD: Position Summary: Under the direction of the IT Governance, Risk and Compliance Manager, this position serves as an IT Audit Liaison within the Enterprise Information Security Office (EISO), supporting the Commonwealth's Governance, Risk, and Compliance (GRC) Department. The GRC function provides governance, risk evaluation, and compliance oversight to support informed decision-making and the responsible adoption of technology across the Commonwealth.The IT Audit Liaison provides technical audit and compliance support for the organization's Governance, Risk, and Compliance (GRC) program. The employee participates in internal and external audit activities, evaluates the effectiveness of information technology controls, identifies compliance gaps, and supports remediation efforts to strengthen the organization's cybersecurity and regulatory compliance posture.Description of Major Duties: • Coordinates and supports information technology audits conducted by internal and external oversight organizations, including GAAP/Single Audit, the Pennsylvania Auditor General, Attorney General, Bureau of Audits, and other regulatory entities. • Reviews documentation and technical evidence to determine compliance with applicable laws, regulations, policies, and security standards. • Evaluates information security and technology controls against established frameworks, including NIST Cybersecurity Framework (CSF), NIST Special Publication 800-53, ISO 27001, and Commonwealth security policies. • Identifies control deficiencies, documents findings, and recommends corrective actions to reduce organizational risk. • Assists business and technical stakeholders in preparing audit responses and collecting supporting evidence. • Tracks audit findings, validates corrective actions and reports remediation status and residual risk to management.• Supports development and maintenance of automated workstreams for audit management, compliance tracking, and evidence collection. • Develops dashboards, metrics and executive reports regarding audit trends, compliance posture and remediation progress. • Performs risk-based assessments to prioritize audit activities and evaluate control effectiveness.• Assists in developing audit procedures, compliance documentation, metrics, and management reports. • Participates in continuous improvement initiatives related to governance, risk management, and internal controls. • Performs related work as assigned. Knowledge, Abilities and Preferred QualificationsKnowledge of:• Information technology auditing principles and practices • Cybersecurity governance and risk management • Internal controls and compliance concepts • NIST CSF, NIST 800-53, ISO 27001, and related frameworks • IT infrastructure, applications, cloud technologies, and security controls Ability to:• Analyze technical and audit documentation • Evaluate compliance with policies and standards • Prepare clear reports and recommendations • Communicate effectively with technical and non-technical staff • Organize multiple audit activities simultaneouslyPreferred Qualifications:• Professional certification such as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manager (CISM) or equivalent• Experience supporting IT audits, regulatory examinations or compliance assessments

    Powered by JazzHR

    Numbers & Facts

    LocationDauphin County- PA, PA

    Skills

    • Attorneyunmatched
    • Auditingunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • CISM - Certified Information Security Managerunmatched
    • Cloud Applicationsunmatched
    • Communication Skillsunmatched
    • Continuous Improvementunmatched
    • Corrective Actionunmatched
    • Decision Supportunmatched
    • Document Managementunmatched
    • Documentationunmatched
    • Documentation Reviewunmatched
    • Enterprise Protectionunmatched
    • Establish Prioritiesunmatched
    • External Auditunmatched
    • Generally Accepted Accounting Principles (GAAP)unmatched
    • Government Organizationsunmatched
    • ISO (International Organization for Standardization)unmatched
    • IT Governanceunmatched
    • Information Technology & Information Systemsunmatched
    • Information Technology/Systems Auditunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internal Auditunmatched
    • Internet Securityunmatched
    • Maintain Complianceunmatched
    • Metricsunmatched
    • Policy Evaluationunmatched
    • Procedure Developmentunmatched
    • Publicationsunmatched
    • Regulationsunmatched
    • Regulatory Complianceunmatched
    • Reporting Dashboardsunmatched
    • Reporting Skillsunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Status Reportsunmatched
    • Technical Analysisunmatched
    • Technical Supportunmatched
    • Technical Writingunmatched
    • Trend Analysisunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder