What are the responsibilities and job description for the Information Security (IT) Auditor position at Platinum Technology LLC?
Company Description Platinum Technology LLC provides professional IT support services to businesses in Northern Colorado, delivering enterprise-level solutions at prices that work for small organizations. The company focuses on proactive, reliable technology management so clients can concentrate on running their businesses instead of troubleshooting IT issues. Leveraging experience, time-tested best practices, and automation tools, Platinum Technology optimizes workflows and system performance. Team members work closely with clients to maintain secure, efficient, and resilient IT environments that support long-term business growth.
Role Description The IT Security Auditor’s role is crucial for our continued compliance and operational excellence. You will conduct comprehensive audits across our IT infrastructure, identifying risks and ensuring the effectiveness of our controls. A key part of your role will involve collaborating closely with multiple product owners to perform periodic reviews and regularly update IT system workflows and compliance protocols. Your ability to manage time effectively and multitask will be essential in adapting to evolving regulations and business needs, ensuring our IT operations support our growth.
Essential Functions:
- Evaluate the Information Security Program, including recommending updates to existing policies and procedures to help ensure they are in accordance with established industry practice and compliant with federal and state regulations.
- Coordinate internal/external IT audits and assessments. Organize, track, and ensure the remediation of IT audit or assessment findings and recommendations.
- Utilize the prevailing cybersecurity examination tool and perform ongoing assessments to ensure that information is adequately safeguarded. Validate that the Information Security Program is constantly maturing.
- Review vendor IT documentation and audits to validate that all vendors comply with internal information security policies and applicable regulations. Provide related summaries to the CEO. Ensure the Risk Management Committee is involved in approving any significant documentation exceptions to the Vendor Management Program.
- Audit IT solutions, systems and configurations, user access controls, and settings periodically to ensure compliance with established policy and guidelines. Report anomalies to senior management and applicable Committees.
- Recommend content for the cyber security training program. Review analytics, responses, and results for training administered to evaluate the effectiveness of the program. Ensure that the assignment and tracking of training recommended is coordinated through Human Resources personnel. Prepare periodic reporting to the Risk Management Committee of the findings and communicate the effectiveness of the program.
- Develop and maintain the Business Continuity and Incident Response plans. Coordinate the implementation of these plans with the organization and business lines, respectively.
- Coordinate the testing of the Business Continuity and Incident Response plans. Organize, track, and ensure compliance with established policy, procedures, and guidelines.
- Report any information security incident to the CEO immediately. Assist with coordination and
- documentation of the response to an information security incident according to established policies and procedures, as requested.
- Prepare appropriate documentation (e.g., narratives, flowchart, control matrices, segregation of duties analyses, audit reports, etc.) in support of all assurance and consulting work performed.
- Assist in the follow-up on internal audit recommendations to ensure implementation.
- Comply with auditing standards, follow good business practices, and efficiently utilize audit resources.
- Perform other related duties as requested by supervisor.
Qualifications & Requirements:
- Local Candidates Preferred;
- Bachelor's Degree or 2 years related work experience;
- The position requires technical knowledge and experience in network architecture, design, configuration, and implementation;
- Candidate should have in-depth knowledge of network routing, firewalls, intrusion detection systems, internet filtering, anti-virus technology, application security, secure email gateways, and PCI and GLBA compliant environments;
- Candidate who maintains the Certified Information Systems Auditor (CISA) designation or working towards a Certified Information Systems Security Professional (CISSP) designation is preferred;
- Strong organization, time management, and communication skills are required. Must be comfortable writing technical documentation;
- Motivated/Self Starter;
- Technical Capacity;
- Communication Proficiency;
- Stress Management/Composure;
- Thoroughness; and
- Customer/Client Focused
Responsibility and Decision-Making Authority
- Involve other team members to establish best practices/decisions;
- Act independently when required; and
- Maintain Platinum Technology corporate values and policy
Supervisory Responsibility
This position has no supervisory responsibilities.
SUPERVISION RECEIVED: Supervision is provided by the CEO/Senior Network Engineer and includes assignment of duties, inspection of work, training, coaching, and performance evaluations.
EDUCATION/ EXPERIENCE:
- Bachelor's Degree;
- 2 years of IT audit experience in a public accounting firm preferred;
- Working towards or holds a CISA Certification;
- Additional certifications (CPA/CISSP/CIA/CFE);
- Experience in presenting technology recommendations from a business perspective; and
- Continued Coursework in Information Security
Hours of Work
- Normal hours of work will be Monday-Friday between 6:00 AM and 6:00 PM based on a Flex Schedule;
- Hours may vary and will require evening and weekend work as directed by the company's needs; and
- Team member may be periodically deployed in the field for direct customer resolution
Work Environment
This position operates in a professional office environment.
Travel
Travel is expected for this position.
Physical Demands
The physical demands described here are representative of those that must be met by an employee to
successfully perform the essential functions of this job.
The employee is occasionally required to:
- Sit, climb, or balance and stoop, kneel, crouch or crawl;
- The employee must frequently lift and/or move objects up to 10 pounds; and
- Occasionally lift and/or move objects up to 40 pounds
Work Authorization/Security Clearance (if applicable)
Must provide proper documentation to prove eligibility to work in the United States. Must pass pre-employment credit check and Colorado Bureau of Investigation background check.
EEO Statement
Platinum Technology is an Equal Opportunity Employer that does not discriminate based on actual or perceived race, creed, color, religion, alienage or national origin, ancestry, citizenship status, age, disability or handicap, sex, marital status, veteran status, sexual orientation, genetic information, or any other characteristic protected by applicable federal, state or local laws.
Other Duties
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this position. Other duties, responsibilities and activities may be requested/required by the CEO, at any time, with or without notice.