Certified Public Accountant
Posted 10 days ago
megaplanitScottsdale (AZ)
Accountants and AuditorsOther Scientific and Technical Consulting Services
SENIORITY
Senior
About the role
The Audit Manager provides security assessments and consulting services to a wide range of clients against industry standards such as SSAE‑18 SOC1 &2, PCIDSS, ISO, HIPAA, and NIST. The role is remote with minimal travel requirements. The Audit Manager prepares executive‑level and technical reports detailing assessment findings, security gaps, and solutions to improve the client’s security posture. The position involves executing management testing, providing direct technical expertise and training, and managing a high volume of work within established policies and procedures.
Responsibilities
Provide practical recommendations for information security and governance around a diverse range of technologies and compliance drivers which include ISO, PCI, and HIPAA
Perform comprehensive technical audits such as SSAE‑18 SOC1 &2, PCIDSS, ISO27001/27002, NIST800‑53/171/CSF, and HIPAA Security for MegaplanIT Holdings, LLC clients
Provide Trusted Advisory Services as well as Policy and Procedure Development during audit engagements
Develop reports that detail compliance gaps for all assessments, including risk severity level, systems impacted, business risk summary, and recommendations for remediation
Create roadmaps to achieve full compliance before a formal audit via gap assessment techniques with prioritized remediation steps, estimated work efforts, and associated timelines
Manage and drive evidence gathering for all standards' requirements and advise clients on how to achieve compliance
Review deliverables with clients, guide remediation activities and provide advisory services that could be of benefit concerning industry trends around achieving and maintaining compliance (i.e., technical solutions)
Serve as a Subject Matter Expert, providing knowledge and assistance in a broad range of security, risk, and compliance fields
Assist the Business Development/Sales team by answering operational and technical questions related to but not limited to SSAE‑18 SOC1 &2, PCIDSS, PCISLC, PCISSF, ISO27001/27002, Policy and Procedure, Penetration Testing, and HIPAA compliance
Support security practice offerings in pre‑sales and post‑sales roles
Assist with developing and managing internal and external delivery processes, procedures, and methodologies
Develop and maintain positive relationships with client personnel
Maintain high morale by contributing to an effective, positive work environment
Guide oneself through a professional development process, including timely completion of reviews and goal setting for additional training and certification
Deliver work that meets or exceeds expectations based on a strong understanding of the client's business and needs
Maintain effective communication between other consultants, management, and client stakeholders
Participate in industry conferences and professional organizations
Provide additional value for clients by offering constructive insights and consultative advice based on personal experience with the client, their industry, established standards, and leading practices
Demonstrate a high level of commitment to client success as shown by responding promptly to changes in client expectations both professionally and effectively
Requirements
Knowledge of SSAE‑18 SOC1 &2 regulations with an emphasis on testing requirements, auditing in administrative services, and basic accounting principles
Professional certifications (e.g., CPA, CIA) and/or an MBA along with demonstrated technical abilities in select areas (regulatory compliance, security, privacy, cyber security, etc.) are preferred
Abilities in select areas (e.g., accounting, regulatory compliance, etc.) are preferred
Able to multi‑task and work independently with minimum supervision to meet client deadlines
Must be flexible, proactive, quick to learn, and possess a can‑do attitude
Excellent written and oral communication skills with the ability to express thoughts clearly, listen effectively, and contribute to a team environment
Proven experience conducting enterprise risk and security assessments
Ability to conduct IT audits about policies, process and procedure design, and information security aspects of privacy and regulatory compliance standards
Be able to communicate compliance, information security, and technology issues clearly to business and technical clientele
Pass criminal background check
Possess sufficient information security knowledge and experience to conduct technically complex security assessments
Possess a minimum of one year of experience in each of the following information security disciplines: Application security, Information systems security, Network security
Possess a minimum of one year of experience in each of the following audit/assessment disciplines: IT security auditing, Information security risk assessment or risk management
Nice to Have
Minimum of 5 years of previous experience conducting assessments
Experience in SSAE‑18 SOC1 &2 work is preferred
Candidates should have previous management experience
#J-18808-Ljbffr
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
