IT Auditor 3+ - Cybersecurity Audit (Internal Only)

State of WashingtonThurston County – Olympia, WA
Hybrid

About The Position

This listing is for current employees of the Office of the Washington State Auditor. The State Auditor’s Office is working together to make a real difference in how government operates, always looking for new ideas to ensure their work provides value to the clients they serve. They take pride in the services performed for the governments and people of Washington. They are committed to building and maintaining a collaborative workplace environment that supports all employees. This includes ensuring inclusion and equity throughout the agency, while embracing individual differences. With 15 offices statewide, 400 positions, and important work to do, they welcome talented people to join their team. The Washington State Auditor’s Office (SAO) prides itself in offering flexible schedules and a hybrid work environment that helps staff balance work and life. They also offer a comprehensive package of health and wellness benefits to employees. The Team Cybersecurity Audit completes cybersecurity performance audits with State and Local governments to improve IT security. Their cybersecurity audits examine IT systems, looking for weaknesses that attackers could exploit and proposing solutions to help strengthen those systems. The mission is to collaborate with governments to provide actionable recommendations to improve the security posture of IT systems supporting essential government operations and services. This will be accomplished by building trust and relationships, sharing knowledge about cybersecurity leading practices and resources, scoping audits flexibly, completing quality and timely audits with prioritized recommendations, and refining methods and approaches to stay relevant and meet emerging needs.

Requirements

  • Bachelor's degree and at least two years in IT audit.
  • Obtained either a relevant professional certification including but not limited to: Certified Information System Auditor (CISA), General Security Essentials Certification (GSEC), Certified Information System Security Processional (CISSP), or a Master's degree in data analytics, cybersecurity or closely related field.
  • Demonstrate an understanding of IT security requirements and best practices.
  • Produce qualitative analyses of superior quality.
  • Excel at documenting their work; writing results; and presenting their work to audiences ranging from team members to legislative members and staff.
  • Demonstrate skill with project management, management control systems, research design, data collection, data analysis, and report writing.
  • Develop recommendations that improve IT security and increase accountability.
  • Have a functional understanding of public administration and government.
  • Effectively communicate verbally and in writing with a variety of audiences, including colleagues, audited agencies, and the public.

Nice To Haves

  • Degree in a field applicable to IT security and/or analyzing government programs is strongly preferred.
  • Experience with governments, performance auditing and/or accountability auditing and technical knowledge and associated with cybersecurity is preferred.
  • Relevant volunteer and/or work experience may substitute for education on a year-for-year basis.
  • Needs some assistance with more complex technical tests such as vulnerability scans.
  • Occasionally, still needs some assistance drawing accurate conclusions.
  • Occasionally, still needs some Security Specialist assistance for new, complex controls.

Responsibilities

  • Assist with each part of a cybersecurity audit engagement, from audit planning through final audit presentation.
  • Work on other IT audit projects.
  • Evaluate a variety of government agencies and local governments.
  • Serve on a team and may also manage contractors for portions of their assigned work.
  • Assist, develop, lead, and conduct independent cybersecurity performance audits.
  • Manage time and projects effectively due to the demanding, time-bound, and important nature of the work.
  • Be responsible for overall audit planning through final audit presentation of any size or level of complexity cybersecurity audits.
  • Independently lead audits that cover increasingly complex cybersecurity environments, which may involve multiple state agencies, local governments or levels of government.
  • Provide expert level technical services in security for cybersecurity audits.
  • May lead larger, more complex audits and coordinate the efforts of other auditors to accomplish the overall audit objectives under the direction of an assistant audit manager or audit manager.
  • Identify, develop and refine leading practice criteria used by auditors to test state and local government alignment with leading practices.
  • Compare and contrast different leading practices and standards, summarize differences and articulate the impact and applicability to the audits of using different standards.
  • Understand data with IT security special handling requirements and how the data impact to the audit, and how those special handling requirements overlap with different leading practices.
  • Independently coordinate and scope technical testing performed by SAO consultants or SAO IT security specialists in most IT security environments but may need Security Specialist assistance in a more complex and mature IT security environment.
  • Conduct and take the lead accurately analyzing most technical testing in moderate to complex environments.
  • Independently assess the results of work performed to develop meaningful IT security recommendations.
  • Draw accurate conclusions using the information gathered through interviews, observation, security testing and document reviews to determine control alignment and gaps, make recommendations based on audit results for controls in most IT security environments.
  • Identify the most significant weaknesses and strengths within the scope of IT security program reviewed.
  • Collaborate with team members to ensure optimal IT security recommendations.

Benefits

  • Flexible schedules
  • Hybrid work environment
  • Comprehensive package of health and wellness benefits
  • Full benefits package
  • Paid vacation, sick leave and holidays
  • Growth and development opportunities, including 80+ hours of training each biennium
  • Educational and professional certification reimbursements
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service