Jobgether

Jobgether

·Today

It auditor

Apply now

Location

remote, United States

Salary

$107k – $120k/yr

Commitment

Full Time

Level

Middle (2-4 years)

Required skills

IT AuditInformation Security ComplianceGRCPCI DSSSOC 2 Type 2GovRAMPFedRAMPNIST 800-53Risk AssessmentControl TestingGap AnalysisRemediation ManagementITGCsStakeholder EngagementSecurity Policies

Job Description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an IT Auditor based in the United States.

This role is responsible for strengthening and maintaining an organization’s information security compliance and governance posture across critical industry frameworks. You will oversee day-to-day compliance activities spanning PCI DSS, SOC 2 Type 2, and GovRAMP/FedRAMP, ensuring controls and policies meet regulatory and contractual expectations.

The position combines internal auditing, control testing, gap analysis, remediation management, and cross-functional stakeholder engagement. You will work closely with technical and business teams to turn audit findings into practical, sustainable security controls. The role also provides visibility into client contract governance, external assessments, security policies, regulatory changes, and compliance training.

Success requires a rigorous and standards-driven approach balanced with pragmatism, collaboration, and the ability to find workable paths to compliance. This is a fully remote opportunity for a seasoned IT audit or GRC professional who enjoys operating across teams and making a measurable impact on security and compliance.

Accountabilities:

  • Own day-to-day compliance execution across PCI DSS, SOC 2 Type 2, and GovRAMP/FedRAMP, including audit preparation, evidence collection, control reviews, and remediation tracking.
  • Conduct internal IT audits and control assessments, documenting findings and producing formal reports with clear, prioritized recommendations for improvement.
  • Perform periodic gap analyses and readiness assessments to identify compliance weaknesses and prepare the organization for formal audits, assessments, and certification milestones.
  • Assess, maintain, and monitor controls aligned with the NIST 800-53 framework as applicable to GovRAMP/FedRAMP authorization requirements.
  • Administer the organization’s Governance, Risk, and Compliance (GRC) platform as the central system of record for controls, policies, evidence, and compliance activities.
  • Provide guidance on client contract governance, evaluating security and compliance requirements to ensure contractual commitments are understood, achievable, and appropriately supported.
  • Partner with departments across the organization—not only IT and Security—to educate employees, answer compliance questions, communicate requirements, and deliver relevant training.
  • Hold department leaders accountable for their assigned compliance obligations, escalating persistent gaps and risks to senior leadership when appropriate.
  • Draft, maintain, communicate, and enforce security policies and procedures across Security, IT, and other business functions.
  • Manage relationships with external compliance organizations, third-party assessors, penetration testers, auditors, and compliance-related vendors.
  • Monitor changes to PCI DSS, SOC 2, GovRAMP/FedRAMP, NIST 800-53, and other applicable regulatory or framework requirements, updating the compliance program as needed.
  • Collaborate with Security Engineers and IT/Hosting teams to translate audit findings and compliance requirements into practical, implementable controls.
  • Apply consistent standards while working collaboratively with stakeholders to identify compliant solutions rather than simply blocking business activities.

Requirements

  • 4–6 years of professional experience in IT audit, information security compliance, Governance, Risk, and Compliance (GRC), or a closely related field.
  • Demonstrated experience working across multiple security and compliance frameworks, ideally including PCI DSS, SOC 2, GovRAMP/FedRAMP, or comparable standards.
  • Hands-on GovRAMP or FedRAMP experience is strongly preferred.
  • Working knowledge of NIST 800-53 controls and their application within GovRAMP/FedRAMP authorization environments.
  • Professional security certification such as CISA, CISSP, or CISM; CISA is preferred.
  • Hands-on experience with a GRC platform such as Vanta, Drata, Secureframe, OneTrust, or an equivalent solution.
  • Strong understanding of IT general controls (ITGCs), risk assessment methodologies, control testing, audit evidence, and remediation processes.
  • Bachelor’s degree in Information Systems, Computer Science, Business, or a related discipline, or equivalent professional experience.
  • Excellent written and verbal communication skills, with the ability to translate technical audit findings and compliance requirements into clear guidance for non-technical stakeholders.
  • Strong cross-functional collaboration skills and a positive, solutions-oriented approach to compliance and risk management.
  • Highly organized and capable of prioritizing multiple compliance activities, deadlines, assessments, and stakeholder requests.
  • Demonstrated ability to work independently, exercise sound judgment, and maintain rigor while operating with limited supervision.
  • Must be a U.S. citizen or Green Card holder and authorized to work in the United States without employment sponsorship.
  • Ability to satisfy applicable background screening and security requirements associated with work involving governmental agencies and regulated environments.

Benefits

  • Base salary of $107,000–$120,000 USD, with placement within the range based on experience, responsibilities, skills, and internal equity.
  • Fully remote work from anywhere within the continental United States.
  • Health insurance, with several plans fully covered for the employee and discounted coverage available for family members.
  • Vision insurance fully covered for the employee, with discounted family coverage available.
  • Dental insurance available for purchase.
  • Flexible, open PTO policy available after 30 days of continuous service, plus nine paid holidays.
  • 401(k) plan with company matching contributions to support long-term financial planning.
  • Eligibility for an annual year-end performance bonus targeted at 7% of base salary.
  • Up to eight weeks of paid parental leave.
  • Company-paid life insurance and long-term disability insurance.
  • Free Udemy access to support ongoing professional development and skills growth.
  • Opportunity to work across cybersecurity, information security compliance, GRC, audit, and government-related security frameworks.
  • High-impact role with significant cross-functional exposure and the opportunity to directly strengthen organizational security and compliance maturity.

How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best!

Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

Ready to join the team?

Apply now

Similar Jobs: