Information System Auditor

Travis CountyAustin, TX
Hybrid

About The Position

Travis County Technology & Operations is seeking an Information System Auditor to join the Enterprise Risk Management Division. This role is part of the Enterprise Risk Management series. The Information Systems Auditor position offers an exciting opportunity to join a collaborative, diverse Information Assurance team and make a meaningful impact by helping protect the technology, information assets, and public trust that support County operations and essential community services. Under limited supervision, the Information Systems Auditor performs complex information technology and cybersecurity audit work involving governance, risk management, regulatory compliance, privacy, operational technology, cloud services, and enterprise security controls. Responsibilities include developing risk-based audit plans, evaluating compliance with federal, state, and industry security frameworks, conducting technical and operational assessments, and providing recommendations that improve the County's cybersecurity posture, resilience, and overall governance. The position serves as a trusted advisor to County leadership on information technology risks, emerging threats, and strategic control improvements, partnering with departments across the organization to enhance security, compliance, and operational effectiveness. This role offers the opportunity to work with a wide variety of technologies and business functions, influence enterprise-wide risk management decisions, and help shape the County's cybersecurity and governance strategy in a dynamic and collaborative environment dedicated to public service. The Information Systems Auditor is a highly analytical and self-directed professional who combines technical expertise with sound audit judgment to independently evaluate information technology, cybersecurity, privacy, and governance risks. The successful candidate demonstrates the ability to assess complex technical environments, identify control weaknesses, and provide practical, risk-based recommendations that strengthen the County's security posture while supporting operational objectives. This position requires the ability to understand and evaluate emerging technologies, evolving cybersecurity threats, cloud computing environments, artificial intelligence, identity and access management, third-party services, and regulatory compliance requirements. The ideal candidate is a trusted advisor who communicates technical risks clearly to both technical and non-technical audiences, builds collaborative relationships across departments while maintaining audit independence, and exercises sound professional judgment when balancing risk, compliance, and business needs. Distinguished from lower-level classifications by the complexity of assignments, level of independence, responsibility for leading enterprise-wide audit engagements, and ability to provide strategic guidance to County leadership on technology governance, cybersecurity, and risk management.

Requirements

  • Bachelor's degree in Computer Science, Information Systems, Business Administration or a directly related field AND five (5) years of relevant work experience in either IT auditing or an information technology role with significant exposure to internal controls and risk assessment practices; OR, Any combination of education and experience that has been achieved and is equivalent to the stated education and experience and required knowledge, skills, and abilities sufficient to successfully perform the duties and responsibilities of this job.
  • Valid Texas Driver's License.
  • Knowledge of risk-based auditing methodologies
  • Knowledge of information security principles
  • Knowledge of cybersecurity governance
  • Knowledge of regulatory and security frameworks such as NIST CSF 2.0, NIST 800-53, NIST AI RMF, HIPAA, PCI-DSS, CJIS
  • Knowledge of Texas cybersecurity statutes
  • Knowledge of cloud security architectures
  • Knowledge of identity and access management
  • Knowledge of third-party risk management
  • Knowledge of artificial intelligence governance
  • Knowledge of secure software development lifecycle
  • Knowledge of data analytics techniques
  • Skill in risk analysis
  • Skill in AI risk analysis
  • Skill in technical writing
  • Skill in data analytics
  • Skill in cloud security review
  • Skill in interviewing stakeholders
  • Ability to coordinate and perform multiple tasks/projects simultaneously, balancing priorities and deliverables.
  • Competent interpersonal skills, demonstrating the ability to lead projects and mentor others.
  • Ability to evaluate business processes and IT technology, identify risks and evaluate controls.
  • Ability to perform independent risk-based IT and cybersecurity audits.
  • Ability to analyze complex technical environments.
  • Ability to interpret regulatory requirements.
  • Ability to evaluate security architectures.
  • Ability to assess effectiveness of cybersecurity controls.
  • Ability to review major technology projects for governance and control considerations.
  • Ability to develop practical, risk-based recommendations.
  • Ability to facilitate organizational compliance with federal, state, and local security regulatory requirements by studying existing and new security legislation; interpreting organizational impact, and; advising management on needed actions.
  • Ability to communicate technical concepts to non-technical audiences.
  • Ability to exercise sound professional judgment and independence.
  • Ability to maintain confidentiality of sensitive information.
  • Ability to maintain professional and technical knowledge by attending educational workshops; reviewing professional publications; establishing personal networks; participating in professional societies.
  • Ability to work collaboratively in a team environment, foster positive working relationships, share knowledge, and mentor less experienced staff to promote professional growth and organizational success.

Nice To Haves

  • Progressively responsible experience in information systems auditing, cybersecurity, risk management, information security, compliance, or related information technology disciplines.
  • Industry-recognized certification such as CompTIA Security+, Certified Information Systems Auditor (CISA), Certified Risk and Information Systems Control (CRISC), or Certified Governance Risk & Compliance (CGRC).

Responsibilities

  • Develops and executes a risk-based annual information technology audit plan aligned with organizational priorities.
  • Conducts enterprise technology risk assessments to identify areas requiring audit or management attention.
  • Evaluates governance, risk management, and internal control processes using recognized frameworks.
  • Assesses the effectiveness of organizational cybersecurity governance and risk management practices.
  • Performs technical and operational audits of cybersecurity controls including identity and access management, endpoint security, network security, vulnerability management, logging and monitoring, data protection, and incident response.
  • Evaluates compliance with applicable federal, state, and industry requirements including but not limited to the NIST Cybersecurity Framework, NIST SP 800-53, CJIS Security Policy, HIPAA, PCI DSS.
  • Evaluates risks associated with artificial intelligence, automation, cloud computing, SaaS platforms, and emerging technologies.
  • Reviews implementation of AI governance controls, data protection, model oversight, and responsible AI practices where applicable.
  • Evaluates third-party technology providers and outsourced services to determine adequacy of security controls and contractual compliance.
  • Reviews independent assurance reports including SOC reports, FedRAMP authorizations, penetration tests, and security assessments.
  • Presents audit findings and recommendations to executive leadership, elected officials, and Commissioners Court.
  • Tracks remediation efforts and validates implementation of corrective actions.
  • Provides advisory services on technology initiatives without impairing audit independence.
  • Collaborates within Technology and Operations and with external County departments to improve governance and control maturity.
  • Coordinates activities with external auditors and regulatory agencies.
  • Performs other job-related duties as assigned.

Benefits

  • Paid vacation & sick leave
  • Outstanding health & dental insurance
  • On-site health clinics for you & your dependents
  • Generous retirement plan
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service