IT Auditor - Hybrid
MSys Inc.
Job summary:
Title:
IT Auditor - Hybrid
Location:
Richmond, VA, United States
Length and terms:
Long term - W2 or C2C
Position created on 07/24/2025 06:06 pm
Job description:
** **Long term***Hybrid***Both Web Cam and In Person Interview***
ON SITE REQUIRED: Tuesday AND Thursday each week
ABOUT THE ROLE
The SCC’s Health Benefit Exchange division is seeking an experienced IT auditor to support our transition to a new security standard and strengthen our third party risk management program. This role will help interpret and implement updated security requirements, conduct audits and assessments of both internal processes and external vendors and partners evaluating controls and recommending improvements.
Responsibilities Include:
+ Assess current security controls and processes against new CMS, IRS, and SCC security standards.
+ Identify gaps and recommend remediation steps to achieve and maintain compliance.
+ Plan, lead, and execute development and updates to policies, procedures, and documentation to reflect requirements.
+ Design, implement, and train on the process for assessing partners and vendors, ensuring alignment with security standards.
+ Develop assessment tools, workflows, and scoring model to evaluate and measure the effectiveness and compliance of vendor and partner security controls.
+ Evaluate the security posture of vendors and partners to ensure information security contractual, information sharing, and data sharing agreement requirements are met.
+ Test the effectiveness of operational and management controls using interviews, document reviews, and observation.
+ Analyze, assess, report, and present on audit findings, risk exposure, and recommendations.
+ Support information security continuous monitoring and incident response programs.
+ Perform related work as required.
Required Skills
+ Audit and compliance/information security/information technology experience or combination thereof 8 Years
+ Information Security control audit and assessment experience 4 Years
+ NIST 80053 or other security framework 4 Years
+ Perform testing, analysis, reporting, and develop remediation plans for compliance with operational and management controls 4 Years
+ Develop and update policies, procedures, and documentation 2 Years
Desired Skills
+ Healthcare, health insurance, or ACA 2 Years
+ Industry recognized certification – CISA, CIA, GSNA, CISSP, or equivalent 2 Years
Contact the recruiter working on this position:
The recruiter working on this position is Hima Teja(Shaji Team)
His/her contact number is +(1) (202) 6290353 His/her contact email is teja@msysinc.com
Our recruiters will be more than happy to help you to get this contract.
Por favor confirme su dirección de correo electrónico: Send Email