Role summary
Bridge the cybersecurity technical requirements with professional government/internal auditing practices.
Provides expert guidance, audit enablement, and compliance assessment support for enterprise cybersecurity audits aligned with NIST CSF, Rule 60GG2, F.
A.
C., and GAO Yellow Book standards.
Serves as a senior advisor to OCIG and agency OIGs.
Key Responsibilities
- Advise on cybersecurity audit planning, testing, evidence, documentation, and reporting.
- Develop audit programs, audit steps, risk/control matrices, testing procedures, and sampling guidance.
- Ensure tools and methodologies align with applicable professional auditing standards.
- Help agency OIG staff assess the sufficiency and appropriateness of cybersecurity audit evidence.
- Support development of consistent audit approaches across participating agencies.
Minimum/Preferred Qualifications
- 5+ years supporting or conducting audits/compliance reviews in government.
- Working knowledge of GAO Government Auditing Standards (Yellow Book) and Global Internal Audit Standards.
- Cybersecurity/IT audit and controls-assessment experience.
- CISA strongly preferred; CISSP or similar certifications beneficial.
- Public-sector internal audit/OIG experience preferred.
Educational Qualification
- Bachelor s degree in Information Systems, Cybersecurity, Accounting, Auditing, or related field.
- Master s degree preferred.
Mandatory Certifications
CISA, CISSP, CompTIA Security+, or equivalent (RFQ requires >50% of staff certified)