What are the responsibilities and job description for the IT Audit Remediation Analyst position at Assurit?
Menu
Site by Cara Cairns Design, Inc.
Capability PDF
Contact
Contact
(703) 225-3305 M - F, 8am - 6pm
Message
Same or Next Business Day Response
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Δ
- Who We Are
- Our Company Our mission is simple, our vision is clear, and our values are strong.
- Our Team Our people are our greatest asset — they will be one of yours as well.
- Our Joint Venture AdvanceX combines Noblis ESI R&D with Assurit cybersecurity expertise.
- Our Clients We are a nationwide trusted partner to the public and private sectors.
- Awards & Accomplishments Follow our journey as we work for the advancement of cybersecurity.
- Press Contract awards, strategic partnerships, and mission-driven milestones.
- What We Do
- Implementation & Advisory Develop and implement sustainable security strategies
- Risk Management Solutions
- Governance & Cyber Program Development
- Third-Party Security
- Privacy & Data Protection
- Assessment & Compliance Anticipate and alleviate risks that can threaten your business
- Audit Readiness
- Penetration Testing
- Vulnerability Scanning & Assessments
- Security Assessment & Authorization (SA&A)
- Incident & Threat Management Prevent, manage and recover from security incidents
- Data Breach Readiness
- Tabletop & Simulated Exercises
- Incident Response
- Threat Hunting
- Security Architecture & Engineering Build, deploy and monitor effective cyber safeguards
- Cloud Security
- Continuous Monitoring
- Business Continuity & Disaster Recovery
- Enterprise Mobility
- Capabilities
- Our Capabilities Discover Assurit’s ability to deliver tailored and effective solutions to your most complex cybersecurity challenges.
- Small Business Certifications
- Quality Initiatives
- NAICS / Product & Service Codes
- Certifications & Contract Vehicles
- Core Capabilities & Staff Qualifications
- Our Capabilities Our proven methodologies will tackle your most complex challenges.
- Case Studies Our extensive experience demonstrates our ability to drive measurable impact.
- Capability Statement (PDF) Download our PDF Capability Statement
- Contract Vehicles
- SBA 8(a) Certified SBA 8(a) Sole-Source and Competitive
- GSA Schedule GSA Multiple Award Schedule (MAS)
- GSA 8(a) STARS III GSA 8(a) STARS III
- NASPO ValuePoint NASPO ValuePoint
- MDA SHIELD IDIQ MDA SHIELD
- SeaPort NxG Navy SeaPort Next Generation (NxG)
- eFAST FAA eFAST
- Maryland CATS Maryland CATS
- Careers
- Contact
- CMMC L2
- SBA 8(a)
- ISO 9001
- ISO 27001
- ISO 20000-1
- CMMI-SVC ML3 v2.0
- CAGE 6VE87
- UEI DL3JL6J1XG98
- Remote
- Posted on July 21, 2026
- Support the development of practical remediation plans
- Work with control owners and stakeholders to track actions to completion
- Validate that newly implemented controls are designed appropriately and operating effectively
- Prepare clear status updates for leadership and reporting purposes
- Highlight risks or delays
- Support issue prioritization and escalation
- Help maintain overall governance and documentation throughout the remediation lifecycle
- Tracking and supporting remediation of planned DAF IT Notices of Findings and Recommendations (NFR) closures for the current Fiscal Year (FY)
- Providing audit coaching to system teams to support the development of Corrective Action Plans (CAPs) and perform validation activities to support NFR closure and strengthen long-term control sustainment
- Planning and supporting off-site NFR system deep-dive workshops
- Documenting and managing memorandums of understanding (MOU) between the client and peer organizations roles and responsibilities across various audit support functions
- Developing and maintaining SOPs for Audit Liaison activities, A-123 support, NFR remediation, CAP tracking, and third-party service provider oversight
- Supporting metrics reporting and oversight for Air Force Audit Agency controls testing progress
- Managing FIAR system scoping forms and ICOFR system lists
- Assisting with data quality and interface control testing and validation
- Documenting and executing annual FISCAM, FFMIA, and CUEC assessments
- Tracking client self-identified deficiencies
- Documenting and validating compensating controls
- Supporting the development of the IT control rationalization playbook
- Supporting implementation playbooks for standardizing controls supported by enterprise capabilities
- Facilitating Financial Management (FM) overlay implementation guidance aligned to the DAF’s Risk Management Framework (RMF)
- Active Secret clearance
- 5 years of experience
- CISA, cyber security (e.g., IAT II or CISSP), or similar IT professional certification required
- 4 year degree in information systems management, computer science, or other relevant field, or 4 years relevant experience
- Demonstrated experience leading remediation efforts for audit findings, control deficiencies, or compliance gaps
- Working knowledge of FISCAM, NIST, and FFMIA requirements and their application to IT general controls and financial system environments
- Experience developing detailed remediation plans, including root cause analysis, corrective actions, owners, and target completion dates
- Ability to assess and validate the design and operating effectiveness of newly implemented or enhanced controls
- Experience coordinating with cross-functional stakeholders, including IT, security, finance, and external audit
- Strong understanding of IT control domains such as access management, change management, configuration management, segregation of duties, interface controls, and system operations
- Experience preparing status updates, dashboards, and reporting materials for leadership, auditors, and governance forums
- Ability to identify remediation risks, dependencies, and delays, and escalate issues appropriately
- Experience supporting external audits and coordinating with auditors
- Knowledge of control testing methodologies, evidence requirements, and auditor expectations
- Strong verbal and written communication skills, including the ability to translate technical issues into business and compliance impacts
- DAF or other DOW Agency Audit / Audit Remediation Support
- Experience working with and/or auditing technologies such as SailPoint, CyberArk, AWS, Azure, Splunk
- Familiarity with the DAF or DOW business process architecture (e.g., Business Enterprise Architecture (BEA) Framework)
- Active or Interim Secret Clearance Required
- IT Audit Remediation Analyst
- IT PMO Analyst / Strategic Communications and Reporting
- QA Tester – SailPoint IdentityIQ / IAM Automation
- Mid-Level SailPoint IdentityIQ Developer (ICAM)
- Senior SailPoint IdentityIQ Developer (ICAM)
- Senior Network Defense Analyst
- Cyber Tools Senior Test & Evaluation Engineer
- Sr. Systems Engineer / Integrator
- Cyber Capabilities Technical Program Manager
IT Audit Remediation Analyst
Assurit is currently seeking an experienced IT Audit Remediation Analyst to support one of our clients.
About The Role
We are seeking an IT Audit / Business Transformation professional as part of the IT Audit Remediation staff responsible for coordinating and driving the execution of remediation activities to address audit findings and control gaps across technology processes and systems. The ideal candidate can independently drive assigned workstreams, manage competing priorities, and proactively manage upward by surfacing risks, recommendations, and decision points to leadership. This individual should be comfortable coordinating across control owners, auditors, and system teams, while requiring limited day-to-day oversight.
This Role Will
Responsibilities
Working at Assurit
Assurit is an award winning, certified small business headquartered in Fairfax, VA. We offer a highly competitive compensation and benefits package inclusive of medical and dental coverage, as well as paid time off.
Founded in 2013, Assurit has become a trusted provider of cybersecurity expertise to customers across federal, state and local governments, as well as the commercial sector. We are an employee-centric organization that focuses on the growth and development of our greatest asset – our people. We believe that if our Team is trained and educated, we will always be able to deliver our promise of customer success. If you enjoy work environments focused on continuous learning and growth, Assurit will be a great fit for you.
Whether you saw a specific job opening of ours or are simply interested in learning more about building your career at Assurit, feel free submit your resume. Based on your request, the appropriate individual within our organization will get back to you within 2 business days.
Assurit is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
To apply for this job email your resume to denise.pho@assurit.com
Spread the Word
open positions
Speak to a member of our leadership team today.
Let’s Connect
Assurit
11325 Random Hills Road
Suite 360
Fairfax, VA 22030
(703) 225-3305
(703) 226-6201 (fax)
info@assurit.com
SBA 8(a), ISO 9001:2015, ISO/IEC 27001:2022, ISO/IEC 20000-1:2018, CMMI-SVC ML3 v2.0, CMMC L2, NAICS & PSC CODES
- Implementation & Advisory
- Risk Management Solutions
- Governance & Cyber Program Development
- Third-Party Security
- Privacy & Data Protection
- Assessment & Compliance
- Audit Readiness
- Penetration Testing
- Vulnerability Scanning & Assessments
- Security Assessment & Authorization (SA&A)
- Incident & Threat Management
- Data Breach Readiness
- Tabletop & Simulated Exercises
- Incident Response
- Threat Hunting
- Security Architecture & Engineering
- Cloud Security
- Continuous Monitoring
- Business Continuity & Disaster Recovery
- Enterprise Mobility
- Assurit Awarded NASA SEWP VI Contract in Categories B and C By Denise L. Pho
- Assurit's 8(a) STARS III Contract Extended Through 2029 By Denise L. Pho
- Assurit Achieves CMMC Level 2 Certification Following Independent C3PAO Assessment By Denise L. Pho
- Capability Statement (PDF)
- Blog
- Career Opportunities
- Sitemap
Site by Cara Cairns Design, Inc.
Capability PDF
Contact
Contact
(703) 225-3305 M - F, 8am - 6pm
Message
Same or Next Business Day Response
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Δ