Redwire logo
Redwire
Posted 16 days agoVerified live 1d ago

IT Compliance Auditor (Internal Controls Auditor)

Brief overview

Remote
UndergradOr in progress
3+ yrsMinimum
IT SOX ComplianceIT AuditingIT Risk ManagementRisk AssessmentIT Control TestingAudit DocumentationCybersecurity Standards CMMCCybersecurity Standards NISTCybersecurity Standards NIS2Cybersecurity Standards ISO 27001Cybersecurity Incident ResponseInternal ControlsControl RemediationStakeholder CollaborationProject Management

Job description

Summary

Redwire Space, Inc. designs and deploys solutions that support humanity’s expansion into space. The IT Compliance Auditor will execute and manage IT controls supporting SOX and other regulatory compliance, document control effectiveness, coordinate internal and external audits, remediate control deficiencies, and advise stakeholders on IT governance, risk mitigation, and cybersecurity compliance.

Responsibilities

  • Lead and manage the execution of IT controls – including but not limited to management review controls, IT application controls, and key report validations – in accordance with our established control framework, management directives, and industry best practices
  • Create and maintain clear, comprehensive, high-quality documentation that meets audit requirements and proves our IT controls are suitably designed and operating effectively
  • Assist in management of audit projects by serving as a primary point of contact for the internal and external audit teams, coordinating walkthroughs and touchpoints, fulfilling audit evidence requests, and responding to auditor inquiries
  • Perform root cause and impact analysis of identified control deficiencies or gaps, and work with stakeholders to develop, execute, and monitor control remediation plans
  • Provide guidance to IT control owners across the organization on the intended design, operation, and documentation of their assigned controls
  • Make approved updates to IT control frameworks, control narratives, process flows, and other related compliance documentation as needed
  • Develop a foundational understanding of our business processes and IT systems in order to provide insights and recommendations to management on enhancing IT controls, mitigating risks, and improving our overall IT governance and compliance posture
  • Prepare accurate and insightful reporting for senior management and executive stakeholders
  • Assist the Cybersecurity team with cybersecurity incident response as required and overall protection of information assets
  • Stay current with emerging trends, technologies, and regulatory changes in the IT audit landscape

Skills

  • Bachelor's degree in information technology, computer science, business administration, or related field, with a minimum of 3 years of relevant experience in IT SOX compliance, IT audit, internal audit, risk management, or related field, preferably in a professional services firm or corporate environment
  • Experienced in conducting IT audit procedures, including risk assessment, control testing, and audit documentation, using industry-leading tools and techniques
  • Experienced in managing multiple workstreams simultaneously while meeting deadlines and delivering high-quality work products in a time sensitive environment
  • Exceptional interpersonal skills with the ability to collaborate effectively with management, team members, and stakeholders at all levels of the organization
  • Must be a US Citizen due to access to controlled information systems and security vulnerability information
  • Flexibility to travel to Redwire sites in North America and Europe as needed and provide remote support across time zones from US Pacific Time (UTC-8) to Eastern European Time (UTC+3)
  • Experience with relevant IT audit and cybersecurity standards (e.g., CMMC, NIST, NIS2, ISO 27001, NASA, DOE or DHS Cybersecurity requirements)
  • Experience in the aerospace or defense industry
  • Experience working with US federal government contractors and associated requirements
  • Experience working as an incident responder on an operational network
  • Master's degree or professional certifications (CISA, CISSP, CIA, etc.) are preferred but not required

Qualifications

Must Haves

  • Bachelor's degree in information technology, computer science, business administration, or related field, with a minimum of 3 years of relevant experience in IT SOX compliance, IT audit, internal audit, risk management, or related field, preferably in a professional services firm or corporate environment
  • Experienced in conducting IT audit procedures, including risk assessment, control testing, and audit documentation, using industry-leading tools and techniques
  • Experienced in managing multiple workstreams simultaneously while meeting deadlines and delivering high-quality work products in a time sensitive environment
  • Exceptional interpersonal skills with the ability to collaborate effectively with management, team members, and stakeholders at all levels of the organization
  • Must be a US Citizen due to access to controlled information systems and security vulnerability information
  • Flexibility to travel to Redwire sites in North America and Europe as needed and provide remote support across time zones from US Pacific Time (UTC-8) to Eastern European Time (UTC+3)

Nice to Haves

  • Experience with relevant IT audit and cybersecurity standards (e.g., CMMC, NIST, NIS2, ISO 27001, NASA, DOE or DHS Cybersecurity requirements)
  • Experience in the aerospace or defense industry
  • Experience working with US federal government contractors and associated requirements
  • Experience working as an incident responder on an operational network
  • Master's degree or professional certifications (CISA, CISSP, CIA, etc.) are preferred but not required

Benefits

  • While the position is primarily remote
  • Flexibility to travel to Redwire sites in North America and Europe as needed and provide remote support across time zones from US Pacific Time (UTC-8) to Eastern European Time (UTC+3)

More jobs like this