Title:- Cybersecurity Audit Analyst
Location:- Boston, MA 02108 (5 Days Onsite)
Duration: Long-Term Contract
Timing:- Monday through Friday, 9:00 AM – 5:00 PM EST
JD:-
The Enterprise Risk Management (ERM) program is seeking a qualified Cybersecurity Audit Analyst with a minimum of five (5) years of relevant experience.
The selected candidate will play a key role in executing and enhancing the client's cybersecurity audit program, including both internal audit activities and coordination of external audit responses.
This position requires strong knowledge of cybersecurity frameworks, auditing methodologies, and risk management practices, along with the ability to work collaboratively across agencies and organizational levels.
Responsibilities include:
Internal audit review
- Assist deputy chief risk officer, continue to formalize and automate the ERM audit program
- Conduct regularly scheduled reviews of EOTSS internal processes to ensure recommended risk mitigating controls are fully implemented, followed, documented and effective.
- Coordinate with ERM risk analysts to ensure internal reviews include current mitigating control recommendations
Required ERM Knowledge, Skills & Abilities:
- At least five (5) years of experience in cybersecurity audit, IT audit, risk management, or compliance
- Strong knowledge of cybersecurity and control frameworks (e.g., NIST, CIS Controls)
- Experience performing audits, risk assessments, program evaluations, and conducting research using quantitative and qualitative methods in a government or highly regulated environment.
- Demonstrate ability to multitask, prioritize, and meet deliverables for various and fluid responsibilities and initiatives.
- Exceptional organizational skills include acute attention to detail especially involving the gathering, updating, tracking, and reporting of data from multiple sources.
- Ability to maintain a consistent and timely follow-through of all requests requiring a response from various members and all levels of the organization.
- A working knowledge of IT, Network infrastructure, software application and software vendor disciplines desired.