Job Description
Job Description
We are looking for a skilled IT Auditor to lead audits and risk assessments focused on ensuring compliance with Ohio cybersecurity laws and regulations. This position plays a vital role in protecting public assets, monitoring incident response protocols, and aligning IT systems with industry-standard frameworks. The role requires a proactive approach to identifying vulnerabilities, recommending solutions, and maintaining robust cybersecurity practices.
Responsibilities :
- Conduct internal audits to evaluate IT systems and cybersecurity controls for compliance.
- Oversee incident response protocols, ensuring documentation, testing, and adherence to reporting requirements within established timelines.
- Analyze logs and records to validate the accuracy and timeliness of incident reporting, including breaches and unauthorized access.
- Perform risk assessments to identify vulnerabilities and recommend actionable strategies to mitigate cybersecurity risks.
- Monitor the implementation of remediation measures and ensure alignment with industry frameworks such as NIST.
- Review and update IT policies, procedures, and documentation to maintain compliance and improve system security.
- Audit annual cybersecurity training programs for city employees, ensuring participation and relevance to job-specific roles.
- Prepare detailed audit reports and presentations for leadership teams and external regulatory bodies.
- Collaborate with state-sponsored initiatives like the Ohio Persistent Cyber Initiative to enhance cybersecurity awareness.
- Provide guidance on improving cybersecurity frameworks and controls to safeguard public assets.
- Bachelor’s degree in Information Systems, Cybersecurity, Accounting, or a related field.
- A minimum of 3 years of experience in IT auditing, cybersecurity, or risk management.
- Certifications such as Certified Information Systems Auditor (CISA) or Certified Internal Auditor (CIA) are preferred.
- Strong knowledge of Ohio HB 96, NIST Cybersecurity Framework, CIS Controls, and ITGC.
- Proven ability to analyze complex systems and identify vulnerabilities.
- Excellent communication and documentation skills to convey findings and recommendations effectively.
- Familiarity with incident response protocols and cybersecurity training programs.
- Experience in preparing audit reports and working with regulatory bodies.