IT Audit Compliance Analysts

State of MarylandAnne Arundel, MD
Onsite

About The Position

The Audit Finance and Compliance Unit (AFCU) assists agencies with OLA Audit Resolution, follow-up & monitoring of corrective actions, and provides ad hoc audit and consultative support to State agencies. AFCU meets and collaborates regularly with agency staff to discuss corrective actions; to understand programs, processes and procedures; and to ensure corrective actions remain in focus. AFCU also serves as DBM’s Internal Audit Compliance function. The IT Audit Compliance Analyst assists agencies with monitoring multiple agency corrective actions to IT audit findings. This role will oversee a full spectrum of corrective action plans across agencies related to information technology audit findings. Coordinates with Department of Information Technology personnel on audit resolutions for statewide, common or repeat IT audit findings. The ideal candidate must possess responsible professional experience in information technology and audit management and be skillful at decision-making, best practices in governance and management practices, and relationship building. This is a Special Appointment position and serves at the pleasure of the Appointing Authority.

Requirements

  • Bachelor’s degree in Accounting, Information Systems, Accounting Information Systems, or related field from an accredited college or university.
  • A minimum of seven (5) years of professional auditing experience that includes exposure to information systems audits, network security or general IT controls.
  • Ability to manage multiple information technology audits simultaneously.

Nice To Haves

  • Experience conducting Service Organization Control (SOC) audits or reviewing SOC reports.
  • Active designation as a Certified Internal Auditor (CIA), Certified Fraud Examiner (CFE), Certified Information System Security Professional (CISSP), Certified in Risk and Information System Control (CRISC), Certified Information System Auditor (CISA)
  • Extensive experience managing internal audit programs and systems and developing and implementing audit plans.
  • Experience identifying and proactively evaluating the design and operation of programs and core management functions, and policies; and providing recommendations for improving the effectiveness and efficiency of existing programs, systems, operations and procedures.
  • Experience writing reports and preparing materials for presentations; expressing facts, conclusions, and recommendations clearly and concisely, both orally and in writing.
  • Three years of experience auditing government or legislative systems, policies, and programs (federal, state or local).

Responsibilities

  • Reviews Office of Legislative Audit reports, discussion notes, and audit work papers for agencies/programs with repeat or significant IT findings.
  • Review agency plans to resolve IT audit findings and assesses the adequacy of agency plans to satisfactorily resolve findings.
  • Lead agency status meetings to discuss the adequacy of agency corrective actions.
  • Assists and advises agencies on the adequacy of their plans to resolve findings.
  • Identifies where planned corrective actions appear inadequate and where areas of disagreement exist.
  • Highlights for the IT Audit Compliance Manager, those agencies where planned corrective actions appear inadequate and where areas of disagreement exist (e.g., agency vs. Legislative Audits).
  • May also hold interviews or discussions with legislative auditors and agency personnel regarding IT findings and agency action plans.
  • Monitors overall implementation of agency corrective and ongoing actions to resolve IT audit findings, through status reports from agency to DBM.
  • Reports to the IT Audit Compliance Manager and agency management, on the adequacy of agency actions.
  • Assist agencies with vendor risk management tasks including reviews of appropriate controls and audit requirements in vendor contracts and reviews of independent security assessments or Service Organization Control (SOC) reports of various third-party service providers that perform work for the State
  • May assist with providing training or working on special audits or reviews.

Benefits

  • STATE OF MARYLAND BENEFITS
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service