Summary
Redwire Space, Inc. designs and deploys solutions that support humanity’s expansion into space. The IT Compliance Auditor will execute and manage IT controls supporting SOX and other regulatory compliance, document control effectiveness, coordinate internal and external audits, remediate control deficiencies, and advise stakeholders on IT governance, risk mitigation, and cybersecurity compliance.
Responsibilities
- Lead and manage the execution of IT controls – including but not limited to management review controls, IT application controls, and key report validations – in accordance with our established control framework, management directives, and industry best practices
- Create and maintain clear, comprehensive, high-quality documentation that meets audit requirements and proves our IT controls are suitably designed and operating effectively
- Assist in management of audit projects by serving as a primary point of contact for the internal and external audit teams, coordinating walkthroughs and touchpoints, fulfilling audit evidence requests, and responding to auditor inquiries
- Perform root cause and impact analysis of identified control deficiencies or gaps, and work with stakeholders to develop, execute, and monitor control remediation plans
- Provide guidance to IT control owners across the organization on the intended design, operation, and documentation of their assigned controls
- Make approved updates to IT control frameworks, control narratives, process flows, and other related compliance documentation as needed
- Develop a foundational understanding of our business processes and IT systems in order to provide insights and recommendations to management on enhancing IT controls, mitigating risks, and improving our overall IT governance and compliance posture
- Prepare accurate and insightful reporting for senior management and executive stakeholders
- Assist the Cybersecurity team with cybersecurity incident response as required and overall protection of information assets
- Stay current with emerging trends, technologies, and regulatory changes in the IT audit landscape
Skills
- Bachelor's degree in information technology, computer science, business administration, or related field, with a minimum of 3 years of relevant experience in IT SOX compliance, IT audit, internal audit, risk management, or related field, preferably in a professional services firm or corporate environment
- Experienced in conducting IT audit procedures, including risk assessment, control testing, and audit documentation, using industry-leading tools and techniques
- Experienced in managing multiple workstreams simultaneously while meeting deadlines and delivering high-quality work products in a time sensitive environment
- Exceptional interpersonal skills with the ability to collaborate effectively with management, team members, and stakeholders at all levels of the organization
- Must be a US Citizen due to access to controlled information systems and security vulnerability information
- Flexibility to travel to Redwire sites in North America and Europe as needed and provide remote support across time zones from US Pacific Time (UTC-8) to Eastern European Time (UTC+3)
- Experience with relevant IT audit and cybersecurity standards (e.g., CMMC, NIST, NIS2, ISO 27001, NASA, DOE or DHS Cybersecurity requirements)
- Experience in the aerospace or defense industry
- Experience working with US federal government contractors and associated requirements
- Experience working as an incident responder on an operational network
- Master's degree or professional certifications (CISA, CISSP, CIA, etc.) are preferred but not required
Qualifications
Must Haves
- Bachelor's degree in information technology, computer science, business administration, or related field, with a minimum of 3 years of relevant experience in IT SOX compliance, IT audit, internal audit, risk management, or related field, preferably in a professional services firm or corporate environment
- Experienced in conducting IT audit procedures, including risk assessment, control testing, and audit documentation, using industry-leading tools and techniques
- Experienced in managing multiple workstreams simultaneously while meeting deadlines and delivering high-quality work products in a time sensitive environment
- Exceptional interpersonal skills with the ability to collaborate effectively with management, team members, and stakeholders at all levels of the organization
- Must be a US Citizen due to access to controlled information systems and security vulnerability information
- Flexibility to travel to Redwire sites in North America and Europe as needed and provide remote support across time zones from US Pacific Time (UTC-8) to Eastern European Time (UTC+3)
Nice to Haves
- Experience with relevant IT audit and cybersecurity standards (e.g., CMMC, NIST, NIS2, ISO 27001, NASA, DOE or DHS Cybersecurity requirements)
- Experience in the aerospace or defense industry
- Experience working with US federal government contractors and associated requirements
- Experience working as an incident responder on an operational network
- Master's degree or professional certifications (CISA, CISSP, CIA, etc.) are preferred but not required
Benefits
- While the position is primarily remote
- Flexibility to travel to Redwire sites in North America and Europe as needed and provide remote support across time zones from US Pacific Time (UTC-8) to Eastern European Time (UTC+3)