Certified Information Systems Auditor (CISA) – Levels I & II
Eskaton Consulting · Arlington, VA
Apply & track with Apply EdgeBy focusing on personal and business potential, we deliver best-in-class services across Cybersecurity, Technology, Process, and People consulting. Our values Trust, Excellence, Accountability, and Making Moments That Matter drive everything we do, ensuring impactful and purpose-driven solutions. Role Summary We are seeking information systems audit professionals to support federal clients. In this role, you will review general and application controls across computer information systems, evaluate IT General Controls and Key Risk Indicators, track remediation of audit findings, and help clients keep their systems secure and compliant with government standards. This posting covers two hiring levels. Candidates may be considered at Level I as a developing professional working under supervision, or at Level II as an experienced professional working with appreciable independence. Both levels perform the same core work; the difference lies in the complexity of assignments, the degree of autonomy, and the depth of prior federal audit experience. Duties/Responsibilities: Information Systems Audit & Control Evaluation Perform general and application control reviews for simple and complex computer information systems, covering backup and disaster recovery, system development standards, system security, programming and communication controls, operating procedures, and system maintenance. Audit computer information systems and perform detailed evaluations of internal controls. Develop and maintain computerized audit software. Verify that information technology systems and infrastructure are secure and appropriately support the applications that depend on them. Key Risk Indicators & IT General Controls Assess the design and operational effectiveness of Key Risk Indicators (KRIs) and IT General Controls (ITGCs). Provide guidance on KRI and ITGC testing methodology, validation processes, procedures, policy adherence, and documentation. Design, develop, and publish materials that support adherence to established KRI and ITGC validation processes. Findings, Remediation & Compliance Follow up on audit findings to confirm that corrective actions have been taken. Work closely with Risk, IT, Information Security, and other teams to report, track, and follow up on remediation plans. Follow up with clients to confirm implementation of remediation actions. Advise clients on maintaining compliance with applicable government standards. Client Advisory & Communication Guide and assist clients through a wide range of improvement and modernization initiatives. Create and deliver presentations to management, discussing audit findings and conclusions and recommending remediation actions. Consult with clients on information systems operational issues. Prepare background papers, briefings, and speeches, and create web and portal content and similar organizational messaging. Support clients in the development, implementation, and maintenance of strategy, doctrine, standards, policies, and procedures.
Qualifications
Bachelor's degree in a technical discipline. An Active Secret security clearance, or eligibility to obtain one. Experience supporting Department of Defense (DoD) / Department of War (DoW) clients or programs. An Active Certified Information Systems Auditor (CISA) certification. Experience — Level I 3+ years of general information systems audit experience, including at least 1 year auditing the financial systems of federal government agencies or preparing federal agencies for audit. Applies fundamental concepts, processes, practices, and procedures to work assignments. Performs work requiring practical experience and training, under supervision. Experience — Level II 5+ years of general information systems audit experience, including at least 2 years auditing the financial systems of federal government agencies or preparing federal agencies for audit. Applies expertise across multiple complex work assignments. Handles broad assignments that may require originality and innovation in determining how to accomplish tasks. Operates with appreciable latitude in developing methodology and presenting solutions to problems. Contributes to deliverables and performance metrics as applicable.
Preferred Qualifications
Experience auditing federal financial systems or supporting federal agencies through audit readiness. Experience testing or validating IT General Controls and Key Risk Indicators. Experience reviewing disaster recovery, system security, change management, or system development controls. Experience developing or maintaining computerized audit tools and testing scripts. Experience coordinating remediation tracking across Risk, IT, and Information Security stakeholders. Experience preparing audit documentation, briefings, or guidance materials for client audiences. Required Skills/Abilities: Working knowledge of information systems audit practices, IT general and application controls, and IT risk and security concepts. Familiarity with federal financial systems and the standards governing federal audits. Strong analytical skills, with the ability to evaluate control design and operating effectiveness and document conclusions clearly. Attention to detail and a commitment to accurate, well-supported audit workpapers and findings. Strong written and verbal communication skills, including the ability to present findings and recommendations to client management. Ability to work collaboratively across technical and non-technical teams. Sound judgment and problem-solving ability; at Level II, the ability to determine methodology and approach with limited direction. Organizational skills sufficient to manage multiple assignments and deadlines. Physical Requirements: Ability to work extended periods at a computer and participate in virtual and in-person client engagements. Why Join Eskaton Consulting? At Eskaton Consulting, we offer more than a role—we provide the opportunity to: Work in a purpose-driven, inclusive environment aligned with your values Support visionary leadership and help shape the culture and direction of the firm Be part of a growing company that values Trust, Excellence, Accountability, and Making Moments That Matter To Apply: Please submit your resume, cover letter, and a brief overview of your experience to us at HR@eskatonconsulting.com with the subject line: “Certified Information Systems Auditor (CISA) – Levels I & II – [Your Name]” Eskaton Consulting is an Equal Opportunity Employer We value diversity and inclusion in our workforce and do not discriminate based on race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or any other protected characteristic. We are committed to creating a welcoming and supportive environment for all employees!