Internal Review Specialist II
Listed on 2026-08-05
-
IT/Tech
IT Consultant, IT Business Analyst, Information Security & Data Protection, Cybersecurity
Internal Review Specialist II
Pro Sidian seeks an internal Review Specialist II located in Arlington, VA (or surrounding area) to support an engagement for Business Analysis and Management Support Services (BAMSS) on behalf of a Federal Government Agency. The Pro Sidian Engagement includes but is not limited to Management & Operations Consulting related to non-personal service to: provide competent leadership, and highly specialized support and technical guidance for the planning, development and execution of the entire Internal Control Review lifecycle.
Serve as a technical expert for audit and internal control related activities with specialized experience in current audit and internal control benchmarks, practices and testing methods.
Perform internal reviews of controls surrounding The Client's Division of IT (DIT) policies, procedures, processes and industry benchmarks to determine efficient and effective operations and in such a manner as to provide a reasonable level of assurance of risk being mitigated. Ability to review documentation and perform assessments of current control and practices against policies and procedures. Develop test plans from current policies, circulars, procedures and industry standards.
Demonstrate ability to conduct and participate in formal and informal audits/reviews at pre-determined points throughout the project life cycle. Ability to identify best practices, effect re-engineering, change management, business management techniques, continuous process improvement, root cause analysis, IT-planning, develop/recommend IT performance-based metrics, and organizational development activity. Possesses the ability to assess and apply multiple organizational, and management improvement techniques in a government environment.
Ensures all work products are complete, accurate and conform to Federal Government Agency standard. Has the ability to create, assess performance measurements and maintains a comprehensive knowledge of the IT industry, business processes and procedures. Has extensive experience in project management and other disciplines as described in an actual TA proposal. Has the ability to conduct process mapping sessions and identify key control points to be tested.
Must be a Certified Information Technology Professional (CTP) and/or a Certified Information Systems Auditor (CISA) and/or Certified Internal Auditor (CIA).
The ideal Internal Review Specialist II has the appropriate skill sets, education, work experience and work quantity to successfully meet all the requirements of The Pro Sidian Client including all awarded TOs on behalf of The Pro Sidian Engagement Team.
A Master's Degree in either Management, Business Administration, Computer Science, Mathematics, Engineering or related discipline with five years of experience in management of enterprise projects similar in scope and or Bachelor's Degree in a related discipline with eight years of experience in the management of similar projects or programs. Minimum 10 Years of experience in IT Governance, Risk and Compliance (GRC), Policy and Standards development and implementation, IT and Information Security, Sarbanes-Oxley (SOX), compliance monitoring, internal control testing, operational risk management, GRC tools and internal/external auditing, strong customer relationship management and proven leadership skills.
Good understanding of COSO, COBIT, ITIL, NIST, FISMA, A123, ISO 27000, SOX 404 and CFOA.
Proven track record of leading and managing risk assessments, reviews and audits, risk mitigations/acceptance plans and reporting. Internal Review Specialist II shall have the ability to provide guidance and direction for multiple enterprise programs in implementing business process development, business re-engineering, and strategic business projects. Internal Review Specialist II shall have the capability to manage programs of high complexity and to direct the completion of multiple projects within estimated time frames and resource constraints.
Experience in GRC tool implementation of IT Controls, Risk Assessments, reviews, audits and third party management. Immense knowledge of designing, implementing and testing ITGC, application and Info Sec controls. Versatile team leader and team player with good communication, program/project management, Software Development Life Cycle, process/procedure, documentation and interpersonal skills.
Ability to identify best practices, effect re-engineering, change management, business management techniques, continuous process improvement, root cause analysis, IT-planning, develop/recommend IT performance-based metrics, and organizational development activity. Possesses the ability to assess and apply multiple organizational, and management improvement techniques in a government environment. Ensures all work products are complete, accurate and conform to FDIC standard.
Specialties: GRC Risk Assessments, Third party Management, SOX Testing, IT Audits, Control Self Assessments, Metrics,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).