Senior Legislative IT Auditor I

State of ColoradoDenver, CO
Hybrid

About The Position

The Office of the State Auditor (OSA) currently has an opening for a full-time Senior IT Auditor I position in our IT Audit Division. This position will be responsible for conducting risk-based IT performance audits to assess whether governmental IT and information security programs and systems are designed, implemented and operate effectively, in compliance with policies, procedures, laws, regulations, and/or industry leading practices. The Senior IT Auditor I position will assist and perform all aspects of assigned IT performance audits, which include planning, fieldwork, findings development, report preparation and production, Legislative Audit Committee (LAC) presentations, audit file workpaper preparation, and follow-up work related to verifying implementation status of audit recommendations for audit status reporting. The position will assist with or facilitate tasks including, but not limited to, the following, as applicable: Development of audit planning deliverables, including risk assessments, audit scopes, audit budgets and schedules; Execution of fieldwork procedures, including tests of design, implementation, and operating effectiveness of IT systems and information security related processes and controls; Development of written audit findings, recommendations, and reports drafts. The position may assist with day-to-day operations of all stages of the IT audit process for specific, assigned audit projects in consultation with the IT audit manager and/or chief IT auditor. The position must manage time effectively as well as be able to perform under heavy, diverse, and complex workloads to produce quality deliverables within established timeframes and deadlines. The position may assist with administrative tasks related to IT audit contract monitoring. The position may assist with training and coaching other IT audit staff, as it relates to audit processes, standards, and best practices, as well as operational IT or information security processes, controls, technologies, standards and practices. The positions will provide such trainings through activities such as, on-the-job training sessions and informal or formal presentations and communications. Other related IT audit functions and duties as deemed necessary.

Requirements

  • One (1) or more years’ of professional experience performing IT audits.
  • One year at the IT senior auditor level or equivalent.
  • Bachelor’s degree from an accredited university, in a field of study relevant to information technology, information security/assurance, management information systems (MIS), computer science, computer engineering.
  • Active CISA certification or attainment of CISA certification is expected within 18 months of hire date.
  • Must be a Colorado resident.

Nice To Haves

  • Professional IT auditing experience, which includes either IT general controls experience across information security, systems development, change management, or computer operations processes, or IT risk-based auditing across any number of IT and information security process areas, technologies, or services.
  • Knowledge of, or experience with, Generally Accepted Government Auditing Standards (i.e., the Yellow Book) and other internal control standards, such as Green Book or COSO.
  • Knowledge of, or experience with, relevant IT auditing standards, frameworks, and regulations, such as COBIT, IIA GTAGs, FISCAM, NIST SP 800-53, ISO/IEC 27001, HIPAA, PCI, Sarbanes-Oxley 404, etc.
  • CISM, CISSP, or other IT audit related certifications.
  • Commitment to ongoing career development, including audit project management skills.
  • Strong critical thinking and problem solving skills.
  • Demonstrated ability to work well under deadlines and heavy workloads.
  • Excellent written and verbal skills.
  • Competency with Microsoft Windows and Office applications, including Word, Excel, and PowerPoint.
  • Knowledge of, or experience with, audit management software and electronic audit workpaper packages.

Responsibilities

  • Conduct risk-based IT performance audits to assess whether governmental IT and information security programs and systems are designed, implemented and operate effectively, in compliance with policies, procedures, laws, regulations, and/or industry leading practices.
  • Assist and perform all aspects of assigned IT performance audits, including planning, fieldwork, findings development, report preparation and production, Legislative Audit Committee (LAC) presentations, audit file workpaper preparation, and follow-up work related to verifying implementation status of audit recommendations for audit status reporting.
  • Assist with or facilitate tasks including, but not limited to, development of audit planning deliverables (risk assessments, audit scopes, audit budgets and schedules), execution of fieldwork procedures (tests of design, implementation, and operating effectiveness of IT systems and information security related processes and controls), and development of written audit findings, recommendations, and reports drafts.
  • Assist with day-to-day operations of all stages of the IT audit process for specific, assigned audit projects in consultation with the IT audit manager and/or chief IT auditor.
  • Manage time effectively and perform under heavy, diverse, and complex workloads to produce quality deliverables within established timeframes and deadlines.
  • Assist with administrative tasks related to IT audit contract monitoring.
  • Assist with training and coaching other IT audit staff on audit processes, standards, and best practices, as well as operational IT or information security processes, controls, technologies, standards and practices through on-the-job training sessions and informal or formal presentations and communications.
  • Perform other related IT audit functions and duties as deemed necessary.

Benefits

  • Hybrid work location
  • Outstanding opportunities for professional development and continued skills training
  • Excellent work-life programs including flexible work schedule opportunities
  • Eco-Pass for public transportation, as well as transportation reimbursements for parking, and bicycle commuters.
  • Strong, secure, yet flexible retirement benefits including PERA Defined Benefit Plan or PERA Defined Contribution Plan, plus 401K and 457 plans
  • Medical and dental health plans
  • Flexible Spending Accounts
  • Life insurance options
  • Limited travel required
  • 11 paid holidays per year plus paid vacation and sick leave
  • Automatic short and optional long-term disability coverage
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service