You'll personally execute SOC audits with a sharp focus on IT General Controls (ITGC/GITC) and Business Process Controls (BPCs), including designing, testing, continuously improving, and evidencing the operating effectiveness and quality of controls across access management, change management, computer operations, system development, cybersecurity, and the business processes that depend on them. You'll align governance programs to FISMA, NIST 800-53, NIST 800-37, RMF, and the NIST Cybersecurity Framework, author and mature System Security Plans, build evidence packages, and serve as the authoritative voice with external auditors, federal regulators, IG reviewers, and DoW client assessors.