Coordinate and drive the execution of remediation activities to address audit findings and control gaps across technology processes. This includes developing remediation plans, validating control effectiveness, and providing audit coaching to system teams.
About the Role:
We are seeking an IT Audit / Business Transformation professional as part of the IT Audit Remediation staff responsible for coordinating and driving the execution of remediation activities to address audit findings and control gaps across technology processes and systems. The ideal candidate can independently drive assigned workstreams, manage competing priorities, and proactively manage upward by surfacing risks, recommendations, and decision points to leadership. This individual should be comfortable coordinating across control owners, auditors, and system teams, while requiring limited day-to-day oversight.
This Role Will:
Support the development of practical remediation plans
Work with control owners and stakeholders to track actions to completion
Validate that newly implemented controls are designed appropriately and operating effectively
Prepare clear status updates for leadership and reporting purposes
Highlight risks or delays
Support issue prioritization and escalation
Help maintain overall governance and documentation throughout the remediation lifecycle
Location: Remote (DC Metro Area Preferred)
Responsibilities:
Tracking and supporting remediation of planned DAF IT Notices of Findings and Recommendations (NFR) closures for the current Fiscal Year (FY)
Providing audit coaching to system teams to support the development of Corrective Action Plans (CAPs) and perform validation activities to support NFR closure and strengthen long-term control sustainment
Planning and supporting off-site NFR system deep-dive workshops
Documenting and managing memorandums of understanding (MOU) between the client and peer organizations roles and responsibilities across various audit support functions
Developing and maintaining SOPs for Audit Liaison activities, A-123 support, NFR remediation, CAP tracking, and third-party service provider oversight
Supporting metrics reporting and oversight for Air Force Audit Agency controls testing progress
Managing FIAR system scoping forms and ICOFR system lists
Assisting with data quality and interface control testing and validation
Documenting and executing annual FISCAM, FFMIA, and CUEC assessments
Tracking client self-identified deficiencies
Documenting and validating compensating controls
Supporting the development of the IT control rationalization playbook
Supporting implementation playbooks for standardizing controls supported by enterprise capabilities
Facilitating Financial Management (FM) overlay implementation guidance aligned to the DAF’s Risk Management Framework (RMF)
Required Qualifications:
Active Secret clearance
5 years of experience
CISA, cyber security (e.g., IAT II or CISSP), or similar IT professional certification required
4 year degree in information systems management, computer science, or other relevant field, or 4 years relevant experience
Demonstrated experience leading remediation efforts for audit findings, control deficiencies, or compliance gaps
Working knowledge of FISCAM, NIST, and FFMIA requirements and their application to IT general controls and financial system environments
Experience developing detailed remediation plans, including root cause analysis, corrective actions, owners, and target completion dates
Ability to assess and validate the design and operating effectiveness of newly implemented or enhanced controls
Experience coordinating with cross-functional stakeholders, including IT, security, finance, and external audit
Strong understanding of IT control domains such as access management, change management, configuration management, segregation of duties, interface controls, and system operations
Experience preparing status updates, dashboards, and reporting materials for leadership, auditors, and governance forums
Ability to identify remediation risks, dependencies, and delays, and escalate issues appropriately
Experience supporting external audits and coordinating with auditors
Knowledge of control testing methodologies, evidence requirements, and auditor expectations
Strong verbal and written communication skills, including the ability to translate technical issues into business and compliance impacts
Preferred Qualifications:
DAF or other DOW Agency Audit / Audit Remediation Support
Experience working with and/or auditing technologies such as SailPoint, CyberArk, AWS, Azure, Splunk
Familiarity with the DAF or DOW business process architecture (e.g., Business Enterprise Architecture (BEA) Framework)
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”