RESPECs Data & Technology Solutions (DTS) team is seeking an experienced IT Auditor II to support the Office of Court Administration in evaluating vendor cybersecurity controls ensuring compliance with contractual and regulatory standards and mitigating third-party risk.
This role is ideal for professionals passionate about information security vendor governance and public-sector IT compliance bringing both technical and analytical acumen to one of the most critical state-level initiatives in Texas.
Responsibilities:
- Review vendor contracts SLAs and cybersecurity clauses for compliance and alignment with Texas state standards.
- Audit vendor environments and assess cybersecurity controls against NIST ISO 27001 PCI-DSS and SOC 2 frameworks.
- Collect and analyze technical evidencesuch as configurations access logs and security policiesto validate control effectiveness.
- Conduct interviews with vendor personnel to evaluate governance and operational practices.
- Identify control gaps assess risk exposure and recommend corrective actions.
- Prepare concise professional audit reports and risk summaries for executive stakeholders.
- Track and validate remediation activities and closure of audit findings.
- Collaborate with internal OCA staff and RESPEC project leadership to ensure vendor risks are communicated and addressed.
Qualifications :
Qualifications:
- 5 years auditing cybersecurity frameworks (NIST ISO 27001 PCI-DSS SOC 2).
- 5 years technical IT auditing across network IAM endpoint and incident response systems.
- 5 years drafting audit reports and presenting findings to executive legal or compliance audiences.
- 5 years analytical and investigative experience identifying and remediating IT control gaps.
- 4 years vendor or third-party risk auditing experience.
- 3 years reviewing policy and documentation accuracy and completeness.
Nice to Have:
- Cloud cybersecurity auditing (AWS Azure Google Cloud).
- Experience in incident response or breach assessment.
- Ability to interpret technical and legal contract language (SLAs security clauses).
- Background in government or regulated industries.
- Strong communication skills for executive-level presentations.
- Certifications: CISA CISSP CRISC or ISO 27001 Lead Auditor.
Additional Information :
All your information will be kept confidential according to EEO guidelines.
All your information will be kept confidential according to EEO guidelines.
Remote Work :
No
Employment Type :
Contract