user avatar

Information Systems Auditor | 3+ Yrs | Shiloh IL

Silverthorne Advisory Group, LLC

Posted today

Job Requirements

Shiloh, IL
Top Secret/SCI Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries

Job Description

Silverthorne Advisory Group is seeking an Information Systems Auditor (CISA Preferred) to join an exciting and growing opportunity supporting clients across the Defense sector. This role is responsible for evaluating the effectiveness of information technology controls, cybersecurity safeguards, governance processes, and enterprise risk management programs while supporting federal financial management, audit readiness, and digital modernization initiatives. The successful candidate will perform risk-based IT audits, assess the design and operating effectiveness of IT General Controls (ITGCs), application controls, and cybersecurity controls, and provide recommendations to strengthen security, compliance, and operational efficiency. Day-to-day responsibilities will emphasize foundational knowledge of federal financial management while expanding expertise beyond traditional system audit disciplines through the use of modern data, analytics, and artificial intelligence technologies. The role partners closely with business leaders, information technology teams, cybersecurity professionals, finance organizations, and external auditors to identify and mitigate technology risks while ensuring compliance with federal regulations, industry standards, and evolving cybersecurity frameworks. This position offers an exceptional opportunity to combine information systems auditing, cybersecurity, data analytics, and emerging AI capabilities in support of high-impact defense and federal missions.

Responsibilities:

- Plan, execute, and document risk-based information systems audits.

- Evaluate IT General Controls (ITGCs), application controls, and automated business processes.

- Assess the effectiveness of cybersecurity, identity and access management, and data protection controls.

- Perform technology risk assessments and identify control gaps, vulnerabilities, and compliance risks.

- Conduct testing of security, operational, and financial system controls.

- Develop audit workpapers, findings, recommendations, and executive-level reports.

- Validate corrective actions and monitor remediation efforts through completion.

- Support compliance with NIST, COBIT, ISO 27001, FISMA, CMMC, SOX, FedRAMP, and other regulatory frameworks.

- Participate in internal and external audits, assessments, and regulatory examinations.

- Evaluate cloud environments, enterprise applications, databases, and infrastructure security controls.

- Assess change management, configuration management, backup, disaster recovery, and business continuity processes.

- Review logging, monitoring, incident response, vulnerability management, and privileged access management practices.

- Analyze technology risks associated with emerging technologies, cloud computing, automation, and artificial intelligence.

- Collaborate with cybersecurity, engineering, finance, and business stakeholders to improve governance and internal controls.

- Identify opportunities to improve audit methodologies, automate testing procedures, and enhance operational efficiency.

- Stay current on evolving cybersecurity threats, regulatory requirements, and industry best practices.



- 3+ years of experience in IT audit, information security, cybersecurity, risk management, internal audit, or technology consulting.

- Bachelor's degree in Information Systems, Computer Science, Cybersecurity, Accounting, Information Technology, or a related discipline.

- Experience performing IT General Controls (ITGC) testing and technology risk assessments.

- Knowledge of NIST Cybersecurity Framework, NIST SP 800-53, NIST SP 800-171, COBIT, COSO, and FISCAM.

- Experience evaluating identity and access management, change management, logical access, backup and recovery, and configuration management controls.

- Strong understanding of cybersecurity principles, security controls, and enterprise risk management.

- Experience developing audit reports, documenting findings, and communicating recommendations to stakeholders.

- Excellent analytical, problem-solving, organizational, and written communication skills.

- Ability to manage multiple projects and work independently in a fast-paced environment.



- Certified Information Systems Auditor (CISA) certification.

- Experience supporting federal civilian, Department of War, or Intelligence Community clients.

- Knowledge of FISMA, FedRAMP, RMF, CMMC 2.0, GAO Green Book, and OMB Circular A-123.

- Experience with cloud platforms including Microsoft Azure, Amazon Web Services (AWS), or Google Cloud Platform (GCP).

- Familiarity with Microsoft Defender, Microsoft Sentinel, Microsoft Entra ID, Microsoft Intune, ServiceNow, SAP, Oracle, or Workday.

- Experience with data analytics, SQL, Power BI, Python, PowerShell, or audit automation tools.

- Professional certifications such as CISSP, CISM, CRISC, CIA, CPA, CGFM, Security+, or PMP.

- Experience supporting SOC 1, SOC 2, ISO 27001, PCI DSS, HIPAA, or SOX compliance initiatives.

- Active Secret or Top Secret security clearance, or the ability to obtain and maintain one.

- Experience leading audit engagements, mentoring junior staff, and presenting to executive leadership.

- Strong consulting, stakeholder management, and client relationship skills.



- Compensation - We carefully consider a wide range of compensation factors, including but not limited to prior experience, skills, expertise, location, and other considerations permitted by law.

- Healthcare - We offer Health, Vision, and Dental Plans for our employees and their families.

- Retirement Plan - We invest in your future with a competitive 401(k) plan, where we match 100% of your contributions up to your first 6% and give you access to Vanguard Admiral funds.

- Paid Time Off - Based on length of service, we offer a generous amount of paid leave.

- Bonus System - As you invest in us, we invest in you. We offer bonuses to all employees who meet and exceed goals throughout the year.

- Professional Development - Support for career growth through training programs and certifications.

- Company Retreats & Team Events - Sponsored trips, team-building activities, and annual conferences related to your skillset.
group id: 91173963