Logo for Brandt Information Services

IT Auditor

Role overview

Qualifications

  • 4–6 years of experience in IT audit, information security compliance, or GRC, ideally spanning multiple frameworks (PCI DSS, SOC 2, GovRAMP/FedRAMP, or similar)
  • GovRAMP or FedRAMP experience strongly preferred
  • Familiarity with NIST 800-53 controls and their application to GovRAMP/FedRAMP authorization
  • Security certification such as CISA, CISSP, or CISM (CISA preferred)

Responsibilities

  • Own day-to-day compliance execution for PCI DSS, SOC 2 Type 2, and GovRAMP, including audit prep, evidence collection, and remediation tracking
  • Conduct internal audits and control assessments; produce formal reports with findings and prioritized recommendations for improvement
  • Conduct periodic gap analyses and readiness assessments ahead of formal audits or certification milestones
  • Assess and maintain controls against the NIST 800-53 control framework as it applies to GovRAMP/FedRAMP authorization

Key facts

  • Remote from: United States
  • Full time
  • Senior (5-10 years)
  • IT Auditor
  • English

Hard skills

Other skills

  • Collaboration
  • Communication
  • Problem Solving

About the company

Brandt Information Services logo

Brandt Information Services

GovTech & Civic Tech

Since 1985, Brandt Information Services has been working closely with government agencies and private businesses — implementing innovative strategies in Wildlife Licensing & Registrations, Technology Projects & Staffing — to streamline business processes, implement industry leading solutions, and help create outdoor opportunities across the country. Brandt Information Services goes the extra mile to provide clients with the tools needed to be productive and competitive. For more information on Brandt Information Services, visit http://www.brandtinfo.com.

Company details

Company typeSME
IndustryGovTech & Civic Tech
Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

IT Auditor

Must be US Citizen or Green Card holder

Full Time Salaried Position

Remote Work Within the Continental United States

Reports to: Chief Information Officer (CIO) / Chief Information Security Officer (CISO), Security Team

Team: Security (alongside Security Engineers)

About Brandt

Brandt is the get-outdoors company. State and local agencies steward the parks, lakes, and wildlife people come for; our platforms make getting there easy, from reserving a campsite to renewing a permit, and help agencies manage those resources sustainably. A family with a trip planned doesn't get a second try at opening day, and neither do we. We're modernizing our platform, building new products, and assembling high-performing teams that have AI embedded in every workflow.

Learn more about Brandt at brandtinfo.com.

About the Role

The IT Auditor is responsible for maintaining and advancing Brandt's information security compliance posture across PCI DSS, SOC 2 Type 2, and GovRAMP, ensuring the company's internal controls, policies, and procedures satisfy regulatory and contractual requirements. This role reviews and assesses the adequacy of Brandt's IT controls, produces findings and remediation recommendations, and provides guidance for client contract governance related to security and compliance obligations. The Auditor works across every department to educate stakeholders, answer compliance questions, deliver training, and hold departments accountable to their compliance standards, while managing external relationships with assessors, pen testers, auditors, and compliance vendors. Success in this role requires being a stickler for standards without becoming a blocker: someone comfortable saying no, but who collaborates with stakeholders to find workable paths to compliance.

Expectations

  • Own day-to-day compliance execution for PCI DSS, SOC 2 Type 2, and GovRAMP, including audit prep, evidence collection, and remediation tracking
  • Conduct internal audits and control assessments; produce formal reports with findings and prioritized recommendations for improvement
  • Conduct periodic gap analyses and readiness assessments ahead of formal audits or certification milestones
  • Assess and maintain controls against the NIST 800-53 control framework as it applies to GovRAMP/FedRAMP authorization
  • Maintain and administer Brandt's GRC tool as the system of record for controls, policies, and evidence
  • Provide guidance on client contract governance, ensuring security/compliance terms are understood and achievable before commitments are made
  • Partner with all departments (not limited to IT and Security) to educate staff on compliance requirements, answer questions, and deliver training
  • Hold department heads accountable to their compliance obligations; escalate persistent gaps to the CIO
  • Draft, maintain, and enforce company security policies, ensuring adherence within Security, IT, and beyond
  • Manage relationships with external compliance organizations, third-party assessors, penetration testers, and compliance-related vendors
  • Monitor changes in regulatory and framework requirements (PCI, SOC 2, GovRAMP/FedRAMP, NIST 800-53) and update Brandt's compliance program accordingly
  • Collaborate with Security Engineers and IT/Hosting teams to translate audit findings into practical, implementable controls
  • Balance rigor with pragmatism: apply consistent standards while working with stakeholders to find compliant solutions rather than simply issuing denials

Qualifications

  • 4–6 years of experience in IT audit, information security compliance, or GRC, ideally spanning multiple frameworks (PCI DSS, SOC 2, GovRAMP/FedRAMP, or similar)
  • GovRAMP or FedRAMP experience strongly preferred
  • Familiarity with NIST 800-53 controls and their application to GovRAMP/FedRAMP authorization
  • Security certification such as CISA, CISSP, or CISM (CISA preferred)
  • Hands-on experience with a GRC platform (e.g., Vanta, Drata, Secureframe, OneTrust, or equivalent)
  • Working knowledge of IT general controls (ITGCs), risk assessment methodology, and control testing
  • Demonstrated experience working collaboratively and cross-functionally, with a positive, solutions-oriented attitude
  • Excellent written and verbal communication skills; able to translate technical findings for non-technical audiences
  • Bachelor’s degree in Information Systems, Computer Science, Business, or related field, or equivalent experience

Compensation & benefits

Compensation is set within Brandt's job architecture for the Senior band with a salary range of $107,000.00-$120,000.00. Level and salary are determined by your experience, the scope of the team you'll lead, and internal equity. We back the role with benefits built for people staying for the long haul:

  • Health insurance, with several plans fully covered for you and discounted coverage for family members.
  • Vision insurance fully covered for you, with discounted coverage available for family members; dental insurance available for purchase.
  • A flexible, open PTO policy available after 30 days of continuous service, plus nine paid holidays.
  • A 401(k) plan with company matching contributions, plus eligibility for an annual year-end performance bonus targeted at 7% of base salary.
  • Up to eight weeks of paid parental leave.
  • Life insurance and long-term disability insurance, both fully covered by the company.
  • A free Udemy account for ongoing professional development.

Brandt Information Services, LLC is an Equal Employment Opportunity (EEO) employer and welcomes all qualified applicants. Applicants receive fair and impartial consideration without regard to race, sex, color, religion, national origin, age, disability, veteran status, genetic data, or other legally protected status.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

IT Auditor Related jobs

Other jobs at Brandt Information Services

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.