Senior Security Auditor @nexus IT group
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1mth ago

[Hiring] Senior Security Auditor @nexus IT group

1mth ago - nexus IT group is hiring a remote Senior Security Auditor. πŸ’Έ Salary: unspecified πŸ“Location: USA

Role Description

We are seeking a Senior Security Auditor to join our cybersecurity assurance team and take ownership of complex, high-impact audits across cloud infrastructure, software development, identity and access management, and enterprise technology environments. This is a highly technical audit role for someone who can go beyond reviewing documentation and actually evaluate how security controls operate within modern technology environments.

  • Lead audit engagements from planning through final reporting.
  • Work directly with technical control owners.
  • Provide an independent perspective on security risks and control effectiveness.
  • Partner closely with engineering, infrastructure, security, and compliance teams while maintaining independence and professional skepticism.
  • Mentor less-experienced auditors and help improve the team's overall audit methodology, automation, and continuous monitoring capabilities.

Qualifications

  • 8+ years of progressive experience in security audit, IT audit, cybersecurity, technology risk, or a related discipline.
  • Demonstrated experience independently leading security or technology audits from planning through reporting and remediation follow-up.
  • Strong technical understanding of cloud security, with significant experience in AWS environments.
  • Ability to evaluate cloud architecture, identity and access controls, security configurations, logging/monitoring, encryption, network controls, and infrastructure-as-code.
  • Strong knowledge of commonly used cybersecurity and compliance frameworks, including NIST CSF, NIST SP 800-53, PCI DSS, and applicable data/security regulations.
  • Experience evaluating software development and application security controls, including SDLC processes, code review, source-control protections, secrets management, CI/CD security, and vulnerability management.
  • Experience auditing identity and access management platforms and controls, including SSO, MFA, user lifecycle management, privileged access, and access reviews.
  • Strong analytical and written communication skills, with the ability to turn complex technical observations into concise, business-focused audit findings.
  • Ability to work independently, exercise sound professional judgment, and manage multiple audit activities with limited day-to-day oversight.
  • Demonstrated ability to coach and develop less-experienced auditors.
  • Strong interpersonal skills and the ability to build productive relationships with engineering, security, infrastructure, and compliance teams while maintaining audit independence.
  • Relevant certifications such as CISA, CISSP, CCSP, AWS Security Specialty, or QSA are highly preferred.
  • Experience working within highly regulated, security-sensitive, or technology-intensive industries is a plus.

Requirements

  • Lead complex security and technology audits spanning cloud environments, on-premises infrastructure, application development, identity and access management, and third-party technology platforms.
  • Develop audit scopes, risk assessments, testing strategies, sampling methodologies, and detailed audit procedures based on applicable security and regulatory requirements.
  • Evaluate the design and operating effectiveness of security controls through technical walkthroughs, configuration reviews, log analysis, access reviews, and examination of supporting evidence.
  • Assess cloud security configurations, identity controls, change management processes, vulnerability management practices, and software development security controls.
  • Translate security frameworks and regulatory requirements into practical, technology-focused testing procedures.
  • Identify control deficiencies and develop clear audit findings that articulate the underlying risk, root cause, business impact, and recommended remediation.
  • Participate in organizational security maturity assessments and help identify gaps between current capabilities and desired control maturity.
  • Coordinate with external auditors and assessors during security assessments, customer reviews, and regulatory examinations.
  • Serve as a key point of contact for evidence collection, walkthroughs, testing requests, and follow-up questions throughout external assessments.
  • Monitor remediation activities and perform follow-up testing to determine whether identified issues have been appropriately addressed.
  • Provide constructive challenge to control owners when proposed remediation does not adequately mitigate the underlying risk.
  • Mentor junior and mid-level auditors on audit methodology, testing techniques, evidence standards, documentation, and professional judgment.
  • Help improve audit processes through better workpaper standards, testing automation, data analytics, and continuous monitoring.
  • Communicate audit results effectively to both technical stakeholders and leadership.

Benefits

  • This is an opportunity to have meaningful influence over an organization's security posture while working directly with technical teams and leadership.
  • The role combines hands-on technical auditing with ownership of complex engagements.
  • Strong fit for an experienced auditor who wants to operate at a senior level and help shape the organization's broader security assurance program.
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Security Auditor @nexus IT group
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1mth ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,869+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later