IT Audit Remediation Analyst
Listed on 2026-08-08
-
IT/Tech
Cybersecurity, IT Business Analyst, Information Security & Data Protection
Assurit Cybersecurity
Assurit is an award winning, certified small business headquartered in Fairfax, VA. We offer a highly competitive compensation and benefits package inclusive of medical and dental coverage, as well as paid time off.
Founded in 2013, Assurit has become a trusted provider of cybersecurity expertise to customers across federal, state and local governments, as well as the commercial sector. We are an employee-centric organization that focuses on the growth and development of our greatest asset – our people. We believe that if our Team is trained and educated, we will always be able to deliver our promise of customer success.
If you enjoy work environments focused on continuous learning and growth, Assurit will be a great fit for you.
Remote (DC Metro Area Preferred)
Responsibilities- Tracking and supporting remediation of planned DAF IT Notices of Findings and Recommendations (NFR) closures for the current Fiscal Year (FY)
- Providing audit coaching to system teams to support the development of Corrective Action Plans (CAPs) and perform validation activities to support NFR closure and strengthen long-term control sustainment
- Planning and supporting off-site NFR system deep-dive workshops
- Documenting and managing memorandums of understanding (MOU) between the client and peer organizations roles and responsibilities across various audit support functions
- Developing and maintaining SOPs for Audit Liaison activities, A-123 support, NFR remediation, CAP tracking, and third-party service provider oversight
- Supporting metrics reporting and oversight for Air Force Audit Agency controls testing progress
- Managing FIAR system scoping forms and ICOFR system lists
- Assisting with data quality and interface control testing and validation
- Documenting and executing annual FISCAM, FFMIA, and CUEC assessments
- Tracking client self-identified deficiencies
- Documenting and validating compensating controls
- Supporting the development of the IT control rationalization playbook
- Supporting implementation playbooks for standardizing controls supported by enterprise capabilities
- Facilitating Financial Management (FM) overlay implementation guidance aligned to the DAF’s Risk Management Framework (RMF)
- Active Secret clearance
- 5 years of experience
- CISA, cyber security (e.g., IAT II or CISSP), or similar IT professional certification required
- 4 year degree in information systems management, computer science, or other relevant field, or 4 years relevant experience
- Demonstrated experience leading remediation efforts for audit findings, control deficiencies, or compliance gaps
- Working knowledge of FISCAM, NIST, and FFMIA requirements and their application to IT general controls and financial system environments
- Experience developing detailed remediation plans, including root cause analysis, corrective actions, owners, and target completion dates
- Ability to assess and validate the design and operating effectiveness of newly implemented or enhanced controls
- Experience coordinating with cross-functional stakeholders, including IT, security, finance, and external audit
- Strong understanding of IT control domains such as access management, change management, configuration management, segregation of duties, interface controls, and system operations
- Experience preparing status updates, dashboards, and reporting materials for leadership, auditors, and governance forums
- Ability to identify remediation risks, dependencies, and delays, and elevate issues appropriately
- Experience supporting external audits and coordinating with auditors
- Knowledge of control testing methodologies, evidence requirements, and auditor expectations
- Strong verbal and written communication skills, including the ability to translate technical issues into business and compliance impacts
- DAF or other DOW Agency Audit / Audit Remediation Support
- Experience working with and/or auditing technologies such as SailPoint, Cyber Ark, AWS, Azure, Splunk
- Familiarity with the DAF or DOW business process architecture (e.g., Business Enterprise Architecture (BEA) Framework)
- Active or Interim Secret Clearance Required
Assurit is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).