Search jobs > Springfield, MA > Temporary > It auditor

IT Program Auditor

CALIBRE
Springfield, US
Full-time

CALIBRE Systems Inc., an employee-owned Management Consulting and Digital Transformation Company is seeking a IT Program Auditor (Advanced) to support our Cybersecurity Division / NGA Defender in the NCE-Springfield, VA.

area. Conducts evaluations of an IT program or its individual components, to determine compliance with published standards.

The IT Program Auditor's responsibilities include, but are not limited to, the following :

  • Develop methods to monitor and measure risk, compliance, and assurance efforts.
  • Provide ongoing optimization and problem-solving support.
  • Provide recommendations for possible improvements and upgrades.
  • Review or conduct audits of information technology (IT) programs and projects.
  • Evaluate the effectiveness of procurement function in addressing information security requirements and supply chain risks through procurement activities and recommend improvements.
  • Review service performance reports identifying any significant issues and variances, initiating, where necessary, corrective actions and ensuring that all outstanding issues are followed up.
  • Conduct import / export reviews for acquiring systems and software.
  • Ensure that supply chain, system, network, performance, and cybersecurity requirements are included in contract language and delivered.

Required Skills

  • Knowledge of computer networking concepts and protocols, and network security methodologies.
  • Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).
  • Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
  • Knowledge of cybersecurity and privacy principles.
  • Knowledge of cyber threats and vulnerabilities. Knowledge of specific operational impacts of cybersecurity lapses.
  • Knowledge of industry-standard and organizationally accepted analysis principles and methods.
  • Knowledge of information technology (IT) architectural concepts and frameworks.
  • Knowledge of Risk Management Framework (RMF) requirements.
  • Knowledge of resource management principles and techniques. Knowledge of system life cycle management principles, including software security and usability.
  • Knowledge of how information needs and collection requirements are translated, tracked, and prioritized across the extended enterprise.
  • Knowledge of Supply Chain Risk Management Practices (NIST SP 800-161). Knowledge of import / export control regulations and responsible agencies for the purposes of reducing supply chain risk.
  • Knowledge of supply chain risk management standards, processes, and practices.
  • Knowledge of risk threat assessment.
  • Knowledge of information technology (IT) supply chain security and supply chain risk management policies, requirements, and procedures.
  • Knowledge of organizational process improvement concepts and process maturity models (e.g., Capability Maturity Model Integration (CMMI) for Development, CMMI for Services, and CMMI for Acquisitions).
  • Knowledge of service management concepts for networks and related standards (e.g., Information Technology Infrastructure Library, current version ITIL ).
  • Knowledge of how to leverage research and development centers, think tanks, academic research, and industry systems.
  • Knowledge of information technology (IT) acquisition / procurement requirements.
  • Knowledge of the acquisition / procurement life cycle process.

Required Experience

Bachelor degree or higher from an accredited college or university (Recommend an accredited Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, or Computer Engineering degree;

or a degree in a Mathematics or Engineering field.)

  • Active TS / SCI Clearance REQUIRED
  • 8140 Certification : CCISO or CCSP or CISA or CISM or CISSP or GSLC
  • Skill in identifying measures or indicators of system performance and the actions needed to improve or correct performance, relative to the goals of the system.
  • Skill in conducting audits or reviews of technical systems
  • Skill to translate, track, and prioritize information needs and intelligence collection requirements across the extended enterprise.
  • Ability to ensure security practices are followed throughout the acquisition process
  • Knowledge of computer networking concepts and protocols, and network security methodologies.
  • Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).
  • Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
  • Knowledge of cybersecurity and privacy principles.
  • Knowledge of cyber threats and vulnerabilities. Knowledge of specific operational impacts of cybersecurity lapses.
  • Knowledge of industry-standard and organizationally accepted analysis principles and methods.
  • Knowledge of information technology (IT) architectural concepts and frameworks.
  • Knowledge of Risk Management Framework (RMF) requirements.
  • Knowledge of resource management principles and techniques. Knowledge of system life cycle management principles, including software security and usability.
  • Knowledge of how information needs and collection requirements are translated, tracked, and prioritized across the extended enterprise.
  • Knowledge of Supply Chain Risk Management Practices (NIST SP 800-161). Knowledge of import / export control regulations and responsible agencies for the purposes of reducing supply chain risk.
  • Knowledge of supply chain risk management standards, processes, and practices.
  • Knowledge of risk threat assessment.
  • Knowledge of information technology (IT) supply chain security and supply chain risk management policies, requirements, and procedures.
  • Knowledge of organizational process improvement concepts and process maturity models (e.g., Capability Maturity Model Integration (CMMI) for Development, CMMI for Services, and CMMI for Acquisitions).
  • Knowledge of service management concepts for networks and related standards (e.g., Information Technology Infrastructure Library, current version ITIL ).
  • Knowledge of how to leverage research and development centers, think tanks, academic research, and industry systems.
  • Knowledge of information technology (IT) acquisition / procurement requirements.
  • Knowledge of the acquisition / procurement life cycle process.
  • 10 days ago
Related jobs
CALIBRE
Springfield, Massachusetts

Management Consulting and Digital Transformation Company is seeking a IT Program Auditor (Advanced)  to support our Cybersecurity Division/NGA Defender in the NCE-Springfield, VA. The IT Program Auditor's responsibilities include, but are not limited to, the following:. Conducts evaluations of ...

Promoted
HORST ENGINEERING & MANUFACTURING CO
Agawam, Massachusetts

As the Manufacturing Operations Manager, you will lead the people and processes associated with the production of contract manufactured precision machined aerospace components. Direct and oversee the day-to-day operations of the workforce that does CNC Swiss screw machining, turning, milling, thread...

Promoted
The Computer Merchant, LTD.
Springfield, Massachusetts

PMP certification or similar; Fluent wit. ...

Promoted
Health New England
Springfield, Massachusetts

IT Core Applications Manager IT Application Development ManagerIT Data Management ManagerBusiness Manager and Directors (As needed). Develop business cases with a cost-benefit analysis for new initiatives and provides leadership by liaising with business stakeholders, technology support, and IT seni...

Promoted
Multicultural Community Services Of The Pioneer Valley
Springfield, Massachusetts

Case Manager for the Agency with Choice/Alternative Day Program. The Agency with Choice/Alternative Day Program is seeking to add a key team member to partner with families and consumers. The goal of this partnership is to create and implement innovative and individualized day program models for peo...

Westinghouse Electric Company LLC.
MA, US

We are searching for a Senior Business Analyst on behalf of our client. Analyzing the design of technical systems, business models, and business needs. Work with business stakeholders, IT solution architects, and developers on tax technology projects. This professional will have several key responsi...

GForce Life Sciences
Massachusetts, US

As a member of our Drug Development Program Management practice, we will rely on your ability to lead, implement and deliver projects to our clients in the life sciences field. Ability to communicate (written and verbal) with impact to provide appropriate context, articulate views, drive clarity, an...

Impact Fire Services
Massachusetts, USA

The Regional Operations Manager for the Northeast Region will drive operations performance for the Region to include building top performing district teams, driving business growth and meeting & exceeding financial performance goals. Northeast Regional Operations Manager. Exceptional guidance and su...

ALTERYX
Massachusetts, USA, Remote
Remote

The Project Manager, Professional Servicesis responsible for supporting the successful execution of Professional Services delivery with our customers through project management. The Project Manager will define success metrics and document timelines, status, and results for each project under their d...

Rose International
Springfield, Massachusetts

As a Business Systems Analyst, you'll have the opportunity to be part of a dynamic work group, and be responsible for performing gap analyses, business capabilities assessments, business and technical requirements, understanding of technical dependencies, and helping to envision creative solutions t...