waypointjobs

Victory

SOC2 & CMMC Internal Auditor Liaison

Remote — United States (see country and timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

You will work with our engineers, support representatives, and external auditors to:

Perform complex, senior-level auditing and advisory work to develop a new audit program and processes for SOC2 and Department of Defense (DOD) Cybersecurity Maturity Model Certification (CMMC) / FedRAMP.

Conduct research, benchmarking, examining and reviewing records & financial statements.

Perform data & risk analyses, identify appropriate controls, assess business processes, and evaluate management processes.

Manage the development of an appropriate audit scope, selection of an external auditor, and successful completion of audits annually.

Continuously collect operational documentation and data samples in order to close process gaps or to document accepted risk before a gap becomes a finding.

Maintain relationships with our external auditors to anticipate changes to audit focuses and prepare the organization for them.

Educate the organization about audit requirements, risk analysis and controls, and assist us with integrating best practices into our existing operational framework.

Identify and document corrective actions that need to be taken based on audit reports.

Respond to client requests for documentation of our processes and audit reports.

Understand and follow changes to CUECs from our partners and vendors.

Requirements

You have experience with:

Auditing in accordance with generally accepted auditing standards and risk-based internal auditing.

Basic information technology controls in a cloud environment.

Analyzing, interpreting, and summarizing data, policies, and procedures for effective performance of audit work.

Establishing and maintaining trust-based relationships with internal and external stakeholders.

You should...

Have advanced writing and communication skills.

Be willing to apply your skills across our small organization, from the low level (e.g. writing process documentation) to high level (e.g. developing organizational audit plans).

Help us maintain the culture and values of our organization.

It would be a plus if you have...

Some experience with DOD cybersecurity requirements and contracts, e.g. NIST 800-171.

Some experience with FedRAMP requirements.

Originally posted on Himalayas

Who can apply

Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

Integra Partners

Himalayas

Compliance Analyst

Remote — United States (see country and timezone requirements)

$85,000.00 – $85,001.00 per yearfull timeRemote

The Legal team at Integra Partners works cross-functionally to help achieve our mission of reducing friction in healthcare.

Listing expires 2026-12-06View job

Tenna

Himalayas

Regional Account Executive - Richmond, VA

Remote — United States (see country and timezone requirements)

Salary not specifiedfull timeRemote

Position DescriptionTenna is searching for a highly motivated and ambitious Regional Account Executive based in Richmond, VA.

Listing expires 2026-12-06View job

12twenty

Himalayas

Enterprise Account Executive

Remote — United States (see country and timezone requirements)

$180,000.00 – $180,000.00 per yearfull timeRemote

12twenty is the leading platform for employers to connect with elite early career professionals.

Listing expires 2026-12-06View job