- Salary
- $92k – $120k/yr
- Location
- Austin, TX, TX, US
- Workplace
- Remote
- Department
- Finance
- Education
- Bachelor
- Source
- GovernmentJobs
Description
Are you looking for career opportunities that provide top-notch benefits including paid vacation & sick leave, outstanding health & dental insurance, on-site health clinics for you & your dependents, a generous retirement plan, and much more? Travis County Technology & Operations is looking for an Information System Auditor to join the Enterprise Risk Management Division.
This class is in the Enterprise Risk Management series of job classifications. The Information Systems Auditor position offers an exciting opportunity to join a collaborative, diverse Information Assurance team and make a meaningful impact by helping protect the technology, information assets, and public trust that support County operations and essential community services. Under limited supervision, the Information Systems Auditor performs complex information technology and cybersecurity audit work involving governance, risk management, regulatory compliance, privacy, operational technology, cloud services, and enterprise security controls. Responsibilities include developing risk-based audit plans, evaluating compliance with federal, state, and industry security frameworks, conducting technical and operational assessments, and providing recommendations that improve the County's cybersecurity posture, resilience, and overall governance. The position serves as a trusted advisor to County leadership on information technology risks, emerging threats, and strategic control improvements, partnering with departments across the organization to enhance security, compliance, and operational effectiveness. This role offers the opportunity to work with a wide variety of technologies and business functions, influence enterprise-wide risk management decisions, and help shape the County's cybersecurity and governance strategy in a dynamic and collaborative environment dedicated to public service.
Distinguishing Characteristics:
The Information Systems Auditor is a highly analytical and self-directed professional who combines technical expertise with sound audit judgment to independently evaluate information technology, cybersecurity, privacy, and governance risks. The successful candidate demonstrates the ability to assess complex technical environments, identify control weaknesses, and provide practical, risk-based recommendations that strengthen the County's security posture while supporting operational objectives.
This position requires the ability to understand and evaluate emerging technologies, evolving cybersecurity threats, cloud computing environments, artificial intelligence, identity and access management, third-party services, and regulatory compliance requirements. The ideal candidate is a trusted advisor who communicates technical risks clearly to both technical and non-technical audiences, builds collaborative relationships across departments while maintaining audit independence, and exercises sound professional judgment when balancing risk, compliance, and business needs.
Distinguished from lower-level classifications by the complexity of assignments, level of independence, responsibility for leading enterprise-wide audit engagements, and ability to provide strategic guidance to County leadership on technology governance, cybersecurity, and risk management.
- Develops and executes a risk-based annual information technology audit plan aligned with organizational priorities.
- Conducts enterprise technology risk assessments to identify areas requiring audit or management attention.
- Evaluates governance, risk management, and internal control processes using recognized frameworks.
- Assesses the effectiveness of organizational cybersecurity governance and risk management practices.
- Performs technical and operational audits of cybersecurity controls including identity and access management, endpoint security, network security, vulnerability management, logging and monitoring, data protection, and incident response.
- Evaluates compliance with applicable federal, state, and industry requirements including but not limited to the NIST Cybersecurity Framework, NIST SP 800-53, CJIS Security Policy, HIPAA, PCI DSS.
- Evaluates risks associated with artificial intelligence, automation, cloud computing, SaaS platforms, and emerging technologies.
- Reviews implementation of AI governance controls, data protection, model oversight, and responsible AI practices where applicable.
- Evaluates third-party technology providers and outsourced services to determine adequacy of security controls and contractual compliance.
- Reviews independent assurance reports including SOC reports, FedRAMP authorizations, penetration tests, and security assessments.
- Presents audit findings and recommendations to executive leadership, elected officials, and Commissioners Court.
- Tracks remediation efforts and validates implementation of corrective actions.
- Provides advisory services on technology initiatives without impairing audit independence.
- Collaborates within Technology and Operations and with external County departments to improve governance and control maturity.
- Coordinates activities with external auditors and regulatory agencies.
- Performs other job-related duties as assigned.
Bachelor's degree in Computer Science, Information Systems, Business Administration or a directly related field AND five (5) years of relevant work experience in either IT auditing or an information technology role with significant exposure to internal controls and risk assessment practices;
OR,
Any combination of education and experience that has been achieved and is equivalent to the stated education and experience and required knowledge, skills, and abilities sufficient to successfully perform the duties and responsibilities of this job.
Licenses, Registrations, Certifications, or Special Requirements:
Valid Texas Driver's License.
Preferred:
•Progressively responsible experience in information systems auditing, cybersecurity, risk management, information security, compliance, or related information technology disciplines.
•Industry-recognized certification such as CompTIA Security+, Certified Information Systems Auditor (CISA), Certified Risk and Information Systems Control (CRISC), or Certified Governance Risk & Compliance (CGRC).
Knowledge, Skills, and Abilities:
Knowledge of:
- Risk-based auditing methodologies
- Information security principles
- Cybersecurity governance
- Regulatory and Security Frameworks such as NIST CSF 2.0, NIST 800-53, NIST AI RMF, HIPAA, PCI-DSS, CJIS
- Texas cybersecurity statutes
- Cloud security architectures
- Identity and Access Management
- Third-party risk management
- Artificial intelligence governance
- Secure software development lifecycle
- Data analytics techniques
- Risk analysis
- AI risk analysis
- Technical writing
- Data analytics
- Cloud security review
- Interviewing stakeholders
- Ability to coordinate and perform multiple tasks/projects simultaneously, balancing priorities and deliverables.
- Competent interpersonal skills, demonstrating the ability to lead projects and mentor others.
- Ability to evaluate business processes and IT technology, identify risks and evaluate controls.
- Both verbal and written communication.
- Perform independent risk-based IT and cybersecurity audits.
- Analyze complex technical environments.
- Interpret regulatory requirements.
- Evaluate security architectures.
- Assess effectiveness of cybersecurity controls.
- Review major technology projects for governance and control considerations.
- Develop practical, risk-based recommendations.
- Facilitate organizational compliance with federal, state, and local security regulatory requirements by studying existing and new security legislation; interpreting organizational impact, and; advising management on needed actions.
- Communicate technical concepts to non-technical audiences.
- Exercise sound professional judgment and independence.
- Maintain confidentiality of sensitive information.
- Maintain professional and technical knowledge by attending educational workshops; reviewing professional publications; establishing personal networks; participating in professional societies.
- Ability to work collaboratively in a team environment, foster positive working relationships, share knowledge, and mentor less experienced staff to promote professional growth and organizational success.
Physical requirements include extended periods of sitting, using a computer and other standard office equipment. Subject to visual acuity, speech and hearing, hand and eye coordination and manual dexterity necessary to operate a computer and office equipment. Occasional lifting or carrying of equipment or materials (typically less than 25 pounds) may be required. Must be able to remain focused and alert while working on detailed technical tasks, especially during incident response or time-sensitive audits.
Work Hours: 8 am - 5 pm, Monday-Friday.
Works some holidays, some nights, and some weekends
Location: 700 Lavaca Street Austin, Texas 78701
Department: Information Security
Criminal, Driving, Education, CJIS fingerprints, and Employment Background Checks Required.
For updates or questions on this position, contact: [email protected]
This job description is intended to be generic in nature. It is not necessarily an exhaustive list of all duties and responsibilities. The essential duties, functions and responsibilities and overtime eligibility may vary based on the specific tasks assigned to the position.