IT Auditor
Listed on 2026-08-11
-
IT/Tech
Cybersecurity, IT Business Analyst, Information Security & Data Protection
Founded in 1998 and headquartered in Farmington Hills, MI, Kyyba has a global presence delivering high-quality resources and top-notch recruiting services, enabling businesses to effectively respond to organizational changes and technological advances.
At Kyyba, the overall well-being of our employees and their families is important to us. We are proud of our work culture which embodies our core values; incorporating value, passion, excellence, empowerment, and happiness creates a vibrant and productive atmosphere. We empower our employees with the resources, incentives, and flexibility that they need to support a healthy, balanced, and fulfilling career by providing many valuable benefits and a balanced compensation structure combined with career development.
Job Title:IT Auditor
Location:
Detroit, MI (Onsite – Hybrid) Duration: 12 Months (C2H) This is a Hybrid position. Resource will be required to come into the office once a week. Engagement Description
The EIS Compliance/Governance Analyst will be responsible for assisting in the execution of security framework compliance and governance activities for a major healthcare payer. The role includes documenting adherence to governance requirements across policies, standards, procedures, controls, compliance, training and awareness programs, and preparing metrics, KPIs, and reporting materials.
Key Responsibilities- Evaluate the design and operational effectiveness of Business/IT operations against the HITRUST CSF and identify areas for improvement.
- Interview SMEs, examine evidence documentation, analyze findings, and perform testing.
- Learn company functions and processes through process walkthroughs.
- Analyze root causes of issues and provide recommendations for process improvements and risk mitigation based on assessment findings.
- Collaborate with cross-functional teams to mitigate risks and ensure compliance with HITRUST CSF.
- Deliver effective and concise documentation that meets HITRUST quality standards.
- Prepare and provide dashboards, metrics, and reports on performance, issue analysis, and assessment status.
- Utilize GRC tools to manage assessment remediation plans and documentation.
- Serve as a HITRUST subject matter expert.
- Participate in and support audits, assessments, and third‑party reviews.
- Support initiatives and projects.
- Build internal relationships to foster teamwork and collaboration.
- 4–5 years of experience in IT Compliance, IT Assessments, and/or IT Audit, with knowledge of Governance, Risk, and Compliance (GRC).
- Knowledge of security and risk frameworks, standards, and best practices, including HITRUST CSF, NIST CSF, ISO/IEC 27001, and COBIT.
- Strong written and verbal communication skills, critical thinking ability, and a self‑starter mindset.
- Ability to tailor communication style to different audiences.
- Experience coordinating and executing the audit lifecycle, including evidence collection, review, observation tracking, management response collection, and auditor communications.
- Strong problem‑solving and decision‑making abilities.
- Experience testing IT controls across systems, databases, applications, and operating systems.
- Ability to effectively frame and deliver messages based on audience experience and knowledge level.
- Strong critical thinking skills with the ability to develop and implement solutions to workplace challenges.
- Ability to solve problems, handle conflict, and make effective decisions under pressure while maintaining professionalism.
- Strong organizational skills.
- Ability to manage changing priorities and multitask effectively.
- Self‑directed with minimal supervision and proactive in seeking guidance when needed.
- Knowledge of Information Technology GCC and Governance, Risk & Compliance principles.
- Experience performing audits and assessments.
- Knowledge of security and risk frameworks such as HITRUST CSF and NIST CSF.
- Strong communication and critical thinking skills with a self‑starter approach.
- Bachelor's degree preferred but not required.
- Master's degree (MBA, MSIS, MIS, etc.) preferred but not required.
- Five (5) years of combined…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).