*This position requires an Active Public Trust clearance or higher to be considered.*
ProSync Technology Group, LLC (ProSync) is an award-winning, SDVOSB Defense Contracting company with a strong military heritage and a record of excellence in supporting the Department of Defense and the Intelligence Community. If you have prior military service or government contracting experience, are proud to serve and support our nation, and want to help support ProSync's mission to "Define and Redefine the State of Possible,” please apply today!
ProSync Technology Group, LLC. is looking for a meticulous and experienced Auditor to join our team. This role involves performing comprehensive audits to ensure compliance with federal regulations and internal policies.
Responsibilities:
- Enhancing and executing mandated internal and external Cybersecurity audits, using the appropriate audit taxonomy, to evaluate CDC IT and cybersecurity programs, on-premise, cloud, and vendor-hosted systems, applications, networks, and infrastructures to assess and identify gaps and weaknesses requiring mitigation to ensure confidentiality, availability, and integrity of CDC assets and data.
- Collecting, analyzing, and submitting FISMA metrics on a quarterly and annual basis which includes working with and educating CDC SMEs to ensure data collected is accurate and free from errors.
- Working with HHS on FISMA metrics submissions and addressing follow-up questions regarding the data submitted on a quarterly and annual basis.
- Conducting program and project management activities necessary to address audit findings and align the cybersecurity program with the OMB, HHS, and CDC strategic plans.
- Performing Information Technology audits, cybersecurity assessments, and establishing governance to evaluate and improve high-risk program areas on an annual basis (e.g., High Value Assets).
- Performing customer outreach for upcoming audits and during existing audits.
- Developing audit materials for non-IT audiences, as well as analysis documentation for presentation to governance bodies and agency leadership.
- Performing technical writing to document outcomes of audits and security assessments, developing audit action plans to address high-risk program objectives to include configuration management, patch management, risk management, incident response, security authorization, and other program controls identified during annual IT audits.
- Conducting meetings with CDC leadership to develop prioritized lists of program objectives, performing analysis of identified objectives, defining the specific goals needed to meet each objective, defining, and prioritizing specific requirements for each objective, and defining timelines and milestones for each objective.
- Defining and documenting the necessary design and development actions required to meet specific requirements as