IT Audit Analyst
Job description
About the role
At Significance, we believe the best results come from investing in great people. As a woman-owned consulting firm supporting federal civilian and Department of Defense customers, we bring together talented professionals who are passionate about solving complex challenges and making a meaningful impact. We are seeking an IT Audit Analyst to join our program in support of USTRANSCOM at Scott AFB. Work will be performed on a hybrid basis with onsite work expected 3 days per week. In this role you will conduct rigorous system reviews and provide objective analysis that strengthens the integrity of federal information environments. The selected professional will evaluate controls, verify compliance, and contribute to transparent reporting that stakeholders can rely on. You will work closely with program teams to translate audit findings into actionable improvements that support mission readiness. This position offers the opportunity to grow your technical expertise while supporting critical defense logistics and transportation missions.
Key facts
What you'll do
Perform comprehensive evaluations of designated critical feeder and core accounting systems to confirm adherence to established frameworks and regulatory requirements.
Execute detailed test plans that examine both design and operational effectiveness of IT controls within the federal enterprise environment.
Review and interpret the Statement on Standards for Attestation Engagements 18 reports with careful attention to Complimentary User Entity Controls.
Analyze test outcomes for CUEC components and document findings in a clear, accurate, and professionally appropriate manner.
Collaborate with program personnel to develop and refine Corrective Action Plans based on audit observations and identified deficiencies.
Assist in the remediation testing process for implemented CAPs to verify that control weaknesses have been addressed appropriately.
Map system processes and configurations against requirements such as DoD Instruction 8510.01, NIST 800-53 RMF, FMFIA, and FISCAM guidance.
Provide subject matter expertise by supporting FISCAM training sessions tailored to the specific needs of program managers.
Synthesize audit evidence to produce concise reports that communicate risk, control performance, and recommended improvements.
Maintain detailed working papers that support audit conclusions and facilitate review by oversight personnel.
Monitor regulatory updates and emerging standards to ensure that audit procedures remain current and relevant.
Apply professional skepticism and analytical rigor when assessing control design and identifying potential gaps or weaknesses.
Document all testing procedures, observations, and conclusions in accordance with firm quality standards and client expectations.
Serve as a reliable resource for stakeholders seeking clarification on audit processes, findings, and remediation strategies.
Requirements
Candidates must possess a Bachelor's degree or equivalent combination of education and experience.
You must have a foundational understanding of information technology controls and audit methodologies.
Demonstrated knowledge of federal information security regulations and compliance frameworks is required.
You should be able to read and interpret complex regulatory documents such as DoD Instruction 8510.01, NIST 800-53, FMFIA, and FISCAM.
Strong written and verbal communication skills are essential for conveying technical findings to diverse audiences.
The ability to work independently and as part of a collaborative team is necessary for success in this role.
You must be comfortable working in a hybrid environment with a commitment to onsite work three days per week.
Reliability, attention to detail, and a proactive approach to problem-solving are expected at all times.
Candidates must be authorized to work in the United States and not require sponsorship for employment authorization at this time.
A background in government contracting, defense logistics, or transportation sectors is considered valuable but not mandatory.
Nice to have
Preferred knowledge of systems common to federal transportation and logistics missions.
Experience with audit tools and techniques specific to federal civilian and Department of Defense environments.
Understanding of Complementary User Entity Controls and related testing methodologies.
Familiarity with the development and implementation of Corrective Action Plans in federal settings.
Experience delivering training or guidance on FISCAM and related control frameworks.
Practical notes
Work is performed on a hybrid schedule with a requirement to be onsite three days per week.
This role is conducted in support of USTRANSCOM at Scott AFB.
Employment authorization must be current and unrestricted.
No sponsorship is available for this position.