FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

IT Auditing, Governance and Compliance
3Core Systems, Inc. Report to the Governance, Risk and Compliance Manager .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in IT governance, compliance management, and security frameworks, with a strong focus on regulatory requirements and risk management. Proficient in developing policies, conducting audits, and fostering relationships with stakeholders to ensure effective compliance initiatives.
Highest-signal resume keywords
Governance And ComplianceIT Audits And AssessmentsControls FrameworksRegulatory Compliance MandatesProject Management
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
GovernanceCompliance Program ManagementControl Framework Maturity EvaluationSecurity Control FrameworksRisk ManagementGap AnalysisLogical Access ControlApplication SecurityVendor Risk ManagementNetwork Security
Soft Skills
Organizational SkillsWritten And Verbal CommunicationAnalytical SkillsProblem-Solving SkillsSelf-Directed Work Habits
Tools & Technologies
GRC Platform
Certifications & Qualifications
CISSPCISACISMCIPPGIAC
Industry Keywords
NISTCIS CSCCOBITCCPAHIPAAGLBASOC 1 Type 2MAR
About the role
Key responsibilities & impact- Report to the Governance, Risk and Compliance Manager
- Support the Information Security department in providing an assurance program to customers
- Perform IT governance and compliance as a service, including assessments, compliance program management and assurance, and control framework maturity evaluations
- Manage, measure, operationalize, and communicate compliance initiatives across the enterprise
- Facilitate IT audits and assessments, including remediation of findings
- Ensure compliance with regulatory requirements and internal controls through proactive control validation
- Review IT regulatory and compliance matters and perform gap analyses
- Implement and maintain information technology, security, and privacy controls frameworks
- Develop and maintain IT policies, standards, and procedures
- Advocate for information security practices
- Execute security control framework maturity evaluation tasks, including stakeholder interviews, documentation reviews, and maturity quantification
- Engage control owners and stakeholders to collect and test evidence and assess compliance with external, contractual, and internal requirements
- Maintain relationships and trust with key company partners
- Maintain compliance and risk management initiatives in a GRC platform
- Interpret third-party contractual security requirements from an information security perspective
- Monitor government and industry information for new security standards and governance practices
- Establish disaster recovery governance and collaborate with business and IT leaders on security and disaster recovery standards and action plans
- Conduct periodic internal security risk and compliance assessments
- Perform other essential duties as assigned
Requirements
What you’ll need- Working knowledge of governance and compliance, including policy, process, governance, controls frameworks, and regulatory environments
- Knowledge to evaluate, build and optimize security program elements, including logical access control, application security, vendor risk management, network security, and privacy
- Experience working with auditors
- Strong organizational skills and ability to thrive in a sense-of-urgency environment
- Strong written and verbal communication skills and ability to interface with all levels of business and executive leadership
- Excellent analytical, problem-solving, and decision-making skills
- Strong self-directed work habits, initiative, drive, creativity, maturity, self-assurance, and professionalism
- Project management skills for managing multiple complex activities
- Knowledge of controls frameworks and applicable regulatory compliance mandates, including NIST, CIS CSC, COBIT, CCPA, HIPAA, GLBA, SOC 1 Type 2, and MAR
- Ability to conduct research on the latest security issues, third-party vendors, and applications
- CISSP, CISA, CISM, CIPP, or GIAC certification is a plus
Benefits
Comp & perks- Contract duration of 12 months +