Serve as the lead advisor and subject matter expert on IT audit and cybersecurity compliance initiatives across U.S. Army programs and systems.
Direct the planning, execution, and reporting of complex IT audits and assessments under GAGAS and DoW guidance.
Oversee evaluations of IT general and application controls, system security configurations, and risk management activities in compliance with NIST SP 800-53, DoDI 8510.01 (RMF), and Army policy (e.g., AR 25-2).
Lead readiness assessments and audits for Army systems supporting financial statements audits, cybersecurity compliance, and operational effectiveness.
Provide high-level recommendations to mitigate risks and close internal control gaps, including development and review of POA&Ms and mitigation strategies.
Engage with Army stakeholders, system owners, cybersecurity personnel, and external auditors to communicate findings, develop action plans, and track remediation.
Monitor emerging audit, cybersecurity, and federal compliance requirements impacting Army IT systems, including CMMC, DFARS 7012, and FISMA.
Support Army Audit Readiness efforts and contribute to enterprise-level IT risk management strategy and continuous monitoring improvements.
Requirements
Security Clearance – active Secret required
Bachelor’s degree in Information Systems, Accounting, Cybersecurity, Computer Science, or a related discipline.
10+ years of relevant experience in IT auditing, cybersecurity, compliance, or risk management.
3+ years of relevant experience supporting audits conducted by DoDIG, GAO, Army Audit Agency, or external auditors.
Demonstrated experience leading or managing IT audits for U.S. Army systems or programs.
Strong understanding of federal internal control frameworks, including OMB A-123, FISCAM, NIST SP 800-53/800-37, and RMF.
Proficiency in evaluating and implementing cybersecurity controls and audit strategies across complex IT environments.
Experience auditing SAP Systems like SAP or PeopleSoft
Excellent leadership, communication, and stakeholder engagement skills.
Professional certifications such as: CISA, CISSP, CPA, CIA, or CRISC