IT Audit Liaison - Hybrid (3 Days/Week) - Long Term Contract - Harrisburg, PA - B4193B

Hybrid in Harrisburg, PA, US • Posted 1 hour ago • Updated 1 hour ago
Contract W2
Contract Corp To Corp
Contract Independent
1 Year
No Travel Required
Hybrid
Depends on Experience
Company Branding Image
Fitment

Dice Job Match Score™

👤 Reviewing your profile...

Job Details

Skills

  • IT Audit
  • Audit Management
  • Information Security
  • NIST 800-53
  • Cyber Security
  • Regulatory Compliance
  • IT Governance
  • Security Controls
  • ISO 27001
  • NIST CSF

Summary

Our direct client is looking for an IT Audit Liaison for a Hybrid (3 Days/Week) Long Term Contract in Harrisburg, PA

Note:
- Hybrid - 3 days in the office/2 days remote at Forum Building | 607 South Drive | Harrisburg, PA 17120
- Interview type:  Virtual interview

J0B DESCRIPTION:
-  Under the direction of the IT Governance, Risk and Compliance Manager, this position serves as an IT Audit Liaison within the Enterprise Information Security Office (EISO), supporting the Commonwealth''''''''s Governance, Risk, and Compliance (GRC) Department. 
- The GRC function provides governance, risk evaluation, and compliance oversight to support informed decision-making and the responsible adoption of technology across the Commonwealth.
- The IT Audit Liaison provides technical audit and compliance support for the organization''''''''s Governance, Risk, and Compliance (GRC) program. 
- The employee participates in internal and external audit activities, evaluates the effectiveness of information technology controls, identifies compliance gaps, and supports remediation efforts to strengthen the organization''''''''s cybersecurity and regulatory compliance posture.

Description of Major Duties: 
- Coordinates and supports information technology audits conducted by internal and external oversight organizations, including GAAP/Single Audit, the Pennsylvania Auditor General, Attorney General, Bureau of Audits, and other regulatory entities. 
- Reviews documentation and technical evidence to determine compliance with applicable laws, regulations, policies, and security standards. 
- Evaluates information security and technology controls against established frameworks, including NIST Cybersecurity Framework (CSF), NIST Special Publication 800-53, ISO 27001, and Commonwealth security policies. 
- Identifies control deficiencies, documents findings, and recommends corrective actions to reduce organizational risk. 
- Assists business and technical stakeholders in preparing audit responses and collecting supporting evidence. 
- Tracks audit findings, validates corrective actions and reports remediation status and residual risk to management.
- Supports development and maintenance of automated workstreams for audit management, compliance tracking, and evidence collection. 
- Develops dashboards, metrics and executive reports regarding audit trends, compliance posture and remediation progress. 
- Performs risk-based assessments to prioritize audit activities and evaluate control effectiveness.
- Assists in developing audit procedures, compliance documentation, metrics, and management reports. 
- Participates in continuous improvement initiatives related to governance, risk management, and internal controls. 
- Performs related work as assigned. 

Knowledge, Abilities and Preferred Qualifications:
Knowledge of:
- Information technology auditing principles and practices 
- Cybersecurity governance and risk management 
- Internal controls and compliance concepts 
- NIST CSF, NIST 800-53, ISO 27001, and related frameworks 
- IT infrastructure, applications, cloud technologies, and security controls 

Ability to:
- Analyze technical and audit documentation 
- Evaluate compliance with policies and standards 
- Prepare clear reports and recommendations 
- Communicate effectively with technical and non-technical staff 
- Organize multiple audit activities simultaneously

Preferred Qualifications:
- Professional certification such as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manager (CISM) or equivalent
- Experience supporting IT audits, regulatory examinations or compliance assessments

SKILL MATRIX:
- Evaluates information security and technology controls against established frameworks, including NIST Cybersecurity Framework (CSF), NIST Special Pu - Required
- Identifies control deficiencies, documents findings, and recommends corrective actions to reduce organizational risk - Required
- Assists business and technical stakeholders in preparing audit responses and collecting supporting evidence - Required
- Tracks audit findings, validates corrective actions and reports remediation status and residual risk to management - Required
- Supports development and maintenance of automated workstreams for audit management, compliance tracking, and evidence collection - Required
- Develops dashboards, metrics and executive reports regarding audit trends, compliance posture and remediation progress - Required
- Performs risk-based assessments to prioritize audit activities and evaluate control effectiveness - Required
- Reviews documentation and technical evidence to determine compliance with applicable laws, regulations, policies, and security standards - Required
- Cybersecurity governance and risk management - Strong Plus to have
- NIST CSF, NIST 800-53, ISO 27001, and related frameworks - Strong Plus to have

Question 1: All consultants are prohibited from taking or using government-issued equipment outside the United States. Violation of this policy may result in serious consequences, as the equipment is government property. Do you understand and agree to abide by this provision?
Question 2: This is a Hybrid (3 Days/Week Onsite) position. Are you fine with this?

Location: Hybrid (3 Days/Week), Harrisburg, PA
Type: Long Term Contract

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: tecvis
  • Position Id: 4193
  • Posted 1 hour ago

Company Info

About Technovision, Inc.

Technovision's methodology helps its expert professionals work closely with customers to understand and map the concept/ problem, detail the requirements, architect the system and further develop, deploy and support the applications on a continuous basis. Technovision takes complete responsibility for the application. For maintenance and support, Technovision's has developed a phased methodology that ensures smooth transition of resources (including customer employees, where applicable) and steady support.

TechnoVision's IT Services approach the customer with a 50-45-5 percent rule. We develop and offer 50 percent of our services by drawing upon our extensive industry experience and knowledge of trends we have tracked over time.

The next 45 percent of the solution is tailored to your precise needs. This level of importance is generated based on the aspect of customer differentiation. Every customer of ours is unique and extremely important. Hence we consider your organizational culture, your distinct business processes and operations, the needs of your customers, your risk tolerance, your competitors, and the dynamics of your markets. We concentrate on your organization's unique characteristics, such as tasks, workflow, business processes, finances and technology.

The last 5 percent is allocated to Contingency, and attributed to your anticipated needs or the uncertainties you face. This 5 percent solution enables your enterprise in change management, keeping your options open in case of contingency, and bracing yourself as changes occur around you.


Career Website
http://www.etechnovision.com

Careers
About_Company_OneAbout_Company_Two
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Hybrid in Harrisburg, Pennsylvania

Today

Easy Apply

Third Party, Contract

Depends on Experience

Hybrid in Harrisburg, Pennsylvania

Today

Easy Apply

Third Party, Contract

Depends on Experience

Hybrid in Harrisburg, Pennsylvania

Today

Easy Apply

Contract, Third Party

Depends on Experience

Hybrid in Newark, New Jersey

Today

Easy Apply

Contract, Third Party

Depends on Experience

Search all similar jobs