Are you looking for career opportunities that provide top-notch benefits including paid vacation & sick leave outstanding health & dental insurance on-site health clinics for you & your dependents a generous retirement plan and much more Travis County Technology & Operations is looking for an Information System Auditor to join the Enterprise Risk Management Division.
This class is in the Enterprise Risk Management series of job classifications. The Information Systems Auditor position offers an exciting opportunity to join a collaborative diverse Information Assurance team and make a meaningful impact by helping protect the technology information assets and public trust that support County operations and essential community services. Under limited supervision the Information Systems Auditor performs complex information technology and cybersecurity audit work involving governance risk management regulatory compliance privacy operational technology cloud services and enterprise security controls. Responsibilities include developing risk-based audit plans evaluating compliance with federal state and industry security frameworks conducting technical and operational assessments and providing recommendations that improve the Countys cybersecurity posture resilience and overall governance. The position serves as a trusted advisor to County leadership on information technology risks emerging threats and strategic control improvements partnering with departments across the organization to enhance security compliance and operational effectiveness. This role offers the opportunity to work with a wide variety of technologies and business functions influence enterprise-wide risk management decisions and help shape the Countys cybersecurity and governance strategy in a dynamic and collaborative environment dedicated to public service.
Distinguishing Characteristics:
The Information Systems Auditor is a highly analytical and self-directed professional who combines technical expertise with sound audit judgment to independently evaluate information technology cybersecurity privacy and governance risks. The successful candidate demonstrates the ability to assess complex technical environments identify control weaknesses and provide practical risk-based recommendations that strengthen the Countys security posture while supporting operational objectives.
This position requires the ability to understand and evaluate emerging technologies evolving cybersecurity threats cloud computing environments artificial intelligence identity and access management third-party services and regulatory compliance requirements. The ideal candidate is a trusted advisor who communicates technical risks clearly to both technical and non-technical audiences builds collaborative relationships across departments while maintaining audit independence and exercises sound professional judgment when balancing risk compliance and business needs.
Distinguished from lower-level classifications by the complexity of assignments level of independence responsibility for leading enterprise-wide audit engagements and ability to provide strategic guidance to County leadership on technology governance cybersecurity and risk management.
Duties and Responsibilities
Develops and executes a risk-based annual information technology audit plan aligned with organizational priorities.
Conducts enterprise technology risk assessments to identify areas requiring audit or management attention.
Evaluates governance risk management and internal control processes using recognized frameworks.
Assesses the effectiveness of organizational cybersecurity governance and risk management practices.
Performs technical and operational audits of cybersecurity controls including identity and access management endpoint security network security vulnerability management logging and monitoring data protection and incident response.
Evaluates compliance with applicable federal state and industry requirements including but not limited to the NIST Cybersecurity Framework NIST SP 800-53 CJIS Security Policy HIPAA PCI DSS.
Evaluates risks associated with artificial intelligence automation cloud computing SaaS platforms and emerging technologies.
Reviews implementation of AI governance controls data protection model oversight and responsible AI practices where applicable.
Evaluates third-party technology providers and outsourced services to determine adequacy of security controls and contractual compliance.
Reviews independent assurance reports including SOC reports FedRAMP authorizations penetration tests and security assessments.
Presents audit findings and recommendations to executive leadership elected officials and Commissioners Court.
Tracks remediation efforts and validates implementation of corrective actions.
Provides advisory services on technology initiatives without impairing audit independence.
Collaborates within Technology and Operations and with external County departments to improve governance and control maturity.
Coordinates activities with external auditors and regulatory agencies.
Performs other job-related duties as assigned.
Minimum Requirements
Education and Experience: Bachelors degree in Computer Science Information Systems Business Administration or a directly related field AND five (5) years of relevant work experience in either IT auditing or an information technology role with significant exposure to internal controls and risk assessment practices; OR Any combination of education and experience that has been achieved and is equivalent to the stated education and experience and required knowledge skills and abilities sufficient to successfully perform the duties and responsibilities of this job.
Licenses Registrations Certifications or Special Requirements: Valid Texas Drivers License.
Preferred: Progressively responsible experience in information systems auditing cybersecurity risk management information security compliance or related information technology disciplines. Industry-recognized certification such as CompTIA Security Certified Information Systems Auditor (CISA) Certified Risk and Information Systems Control (CRISC) or Certified Governance Risk & Compliance (CGRC).
Knowledge Skills and Abilities: Knowledge of:
Risk-based auditing methodologies
Information security principles
Cybersecurity governance
Regulatory and Security Frameworks such as NIST CSF 2.0 NIST 800-53 NIST AI RMF HIPAA PCI-DSS CJIS
Texas cybersecurity statutes
Cloud security architectures
Identity and Access Management
Third-party risk management
Artificial intelligence governance
Secure software development lifecycle
Data analytics techniques
Skill in:
Risk analysis
AI risk analysis
Technical writing
Data analytics
Cloud security review
Interviewing stakeholders
Ability to coordinate and perform multiple tasks/projects simultaneously balancing priorities and deliverables.
Competent interpersonal skills demonstrating the ability to lead projects and mentor others.
Ability to evaluate business processes and IT technology identify risks and evaluate controls.
Both verbal and written communication.
Ability to:
Perform independent risk-based IT and cybersecurity audits.
Analyze complex technical environments.
Interpret regulatory requirements.
Evaluate security architectures.
Assess effectiveness of cybersecurity controls.
Review major technology projects for governance and control considerations.
Develop practical risk-based recommendations.
Facilitate organizational compliance with federal state and local security regulatory requirements by studying existing and new security legislation; interpreting organizational impact and; advising management on needed actions.
Communicate technical concepts to non-technical audiences.
Exercise sound professional judgment and independence.
Maintain confidentiality of sensitive information.
Maintain professional and technical knowledge by attending educational workshops; reviewing professional publications; establishing personal networks; participating in professional societies.
Ability to work collaboratively in a team environment foster positive working relationships share knowledge and mentor less experienced staff to promote professional growth and organizational success.
Work Environment & Other Information
Work primarily performed in office setting either on-site or in a secure hybrid/telework environment. May involve occasional visits to data centers agency offices or vendor locations for security inspections audits or meetings. Must adhere to strict security protocols and procedures including physical access controls fingerprint-based background checks and secure area clearances. May occasionally work outside normal business hours to respond to security incidents or meet project deadlines.
Physical requirements include extended periods of sitting using a computer and other standard office equipment. Subject to visual acuity speech and hearing hand and eye coordination and manual dexterity necessary to operate a computer and office equipment. Occasional lifting or carrying of equipment or materials (typically less than 25 pounds) may be required. Must be able to remain focused and alert while working on detailed technical tasks especially during incident response or time-sensitive audits.
Work Hours: 8 am - 5 pm Monday-Friday. Works some holidays some nights and some weekends
Location:700 Lavaca Street Austin Texas 78701
Department: Information Security
Criminal Driving Education CJIS fingerprints and Employment Background Checks Required.
For updates or questions on this position contact:
Job SummaryAre you looking for career opportunities that provide top-notch benefits including paid vacation & sick leave outstanding health & dental insurance on-site health clinics for you & your dependents a generous retirement plan and much more Travis County Technology & Operations is looking fo...
Job Summary
Are you looking for career opportunities that provide top-notch benefits including paid vacation & sick leave outstanding health & dental insurance on-site health clinics for you & your dependents a generous retirement plan and much more Travis County Technology & Operations is looking for an Information System Auditor to join the Enterprise Risk Management Division.
This class is in the Enterprise Risk Management series of job classifications. The Information Systems Auditor position offers an exciting opportunity to join a collaborative diverse Information Assurance team and make a meaningful impact by helping protect the technology information assets and public trust that support County operations and essential community services. Under limited supervision the Information Systems Auditor performs complex information technology and cybersecurity audit work involving governance risk management regulatory compliance privacy operational technology cloud services and enterprise security controls. Responsibilities include developing risk-based audit plans evaluating compliance with federal state and industry security frameworks conducting technical and operational assessments and providing recommendations that improve the Countys cybersecurity posture resilience and overall governance. The position serves as a trusted advisor to County leadership on information technology risks emerging threats and strategic control improvements partnering with departments across the organization to enhance security compliance and operational effectiveness. This role offers the opportunity to work with a wide variety of technologies and business functions influence enterprise-wide risk management decisions and help shape the Countys cybersecurity and governance strategy in a dynamic and collaborative environment dedicated to public service.
Distinguishing Characteristics:
The Information Systems Auditor is a highly analytical and self-directed professional who combines technical expertise with sound audit judgment to independently evaluate information technology cybersecurity privacy and governance risks. The successful candidate demonstrates the ability to assess complex technical environments identify control weaknesses and provide practical risk-based recommendations that strengthen the Countys security posture while supporting operational objectives.
This position requires the ability to understand and evaluate emerging technologies evolving cybersecurity threats cloud computing environments artificial intelligence identity and access management third-party services and regulatory compliance requirements. The ideal candidate is a trusted advisor who communicates technical risks clearly to both technical and non-technical audiences builds collaborative relationships across departments while maintaining audit independence and exercises sound professional judgment when balancing risk compliance and business needs.
Distinguished from lower-level classifications by the complexity of assignments level of independence responsibility for leading enterprise-wide audit engagements and ability to provide strategic guidance to County leadership on technology governance cybersecurity and risk management.
Duties and Responsibilities
Develops and executes a risk-based annual information technology audit plan aligned with organizational priorities.
Conducts enterprise technology risk assessments to identify areas requiring audit or management attention.
Evaluates governance risk management and internal control processes using recognized frameworks.
Assesses the effectiveness of organizational cybersecurity governance and risk management practices.
Performs technical and operational audits of cybersecurity controls including identity and access management endpoint security network security vulnerability management logging and monitoring data protection and incident response.
Evaluates compliance with applicable federal state and industry requirements including but not limited to the NIST Cybersecurity Framework NIST SP 800-53 CJIS Security Policy HIPAA PCI DSS.
Evaluates risks associated with artificial intelligence automation cloud computing SaaS platforms and emerging technologies.
Reviews implementation of AI governance controls data protection model oversight and responsible AI practices where applicable.
Evaluates third-party technology providers and outsourced services to determine adequacy of security controls and contractual compliance.
Reviews independent assurance reports including SOC reports FedRAMP authorizations penetration tests and security assessments.
Presents audit findings and recommendations to executive leadership elected officials and Commissioners Court.
Tracks remediation efforts and validates implementation of corrective actions.
Provides advisory services on technology initiatives without impairing audit independence.
Collaborates within Technology and Operations and with external County departments to improve governance and control maturity.
Coordinates activities with external auditors and regulatory agencies.
Performs other job-related duties as assigned.
Minimum Requirements
Education and Experience: Bachelors degree in Computer Science Information Systems Business Administration or a directly related field AND five (5) years of relevant work experience in either IT auditing or an information technology role with significant exposure to internal controls and risk assessment practices; OR Any combination of education and experience that has been achieved and is equivalent to the stated education and experience and required knowledge skills and abilities sufficient to successfully perform the duties and responsibilities of this job.
Licenses Registrations Certifications or Special Requirements: Valid Texas Drivers License.
Preferred: Progressively responsible experience in information systems auditing cybersecurity risk management information security compliance or related information technology disciplines. Industry-recognized certification such as CompTIA Security Certified Information Systems Auditor (CISA) Certified Risk and Information Systems Control (CRISC) or Certified Governance Risk & Compliance (CGRC).
Knowledge Skills and Abilities: Knowledge of:
Risk-based auditing methodologies
Information security principles
Cybersecurity governance
Regulatory and Security Frameworks such as NIST CSF 2.0 NIST 800-53 NIST AI RMF HIPAA PCI-DSS CJIS
Texas cybersecurity statutes
Cloud security architectures
Identity and Access Management
Third-party risk management
Artificial intelligence governance
Secure software development lifecycle
Data analytics techniques
Skill in:
Risk analysis
AI risk analysis
Technical writing
Data analytics
Cloud security review
Interviewing stakeholders
Ability to coordinate and perform multiple tasks/projects simultaneously balancing priorities and deliverables.
Competent interpersonal skills demonstrating the ability to lead projects and mentor others.
Ability to evaluate business processes and IT technology identify risks and evaluate controls.
Both verbal and written communication.
Ability to:
Perform independent risk-based IT and cybersecurity audits.
Analyze complex technical environments.
Interpret regulatory requirements.
Evaluate security architectures.
Assess effectiveness of cybersecurity controls.
Review major technology projects for governance and control considerations.
Develop practical risk-based recommendations.
Facilitate organizational compliance with federal state and local security regulatory requirements by studying existing and new security legislation; interpreting organizational impact and; advising management on needed actions.
Communicate technical concepts to non-technical audiences.
Exercise sound professional judgment and independence.
Maintain confidentiality of sensitive information.
Maintain professional and technical knowledge by attending educational workshops; reviewing professional publications; establishing personal networks; participating in professional societies.
Ability to work collaboratively in a team environment foster positive working relationships share knowledge and mentor less experienced staff to promote professional growth and organizational success.
Work Environment & Other Information
Work primarily performed in office setting either on-site or in a secure hybrid/telework environment. May involve occasional visits to data centers agency offices or vendor locations for security inspections audits or meetings. Must adhere to strict security protocols and procedures including physical access controls fingerprint-based background checks and secure area clearances. May occasionally work outside normal business hours to respond to security incidents or meet project deadlines.
Physical requirements include extended periods of sitting using a computer and other standard office equipment. Subject to visual acuity speech and hearing hand and eye coordination and manual dexterity necessary to operate a computer and office equipment. Occasional lifting or carrying of equipment or materials (typically less than 25 pounds) may be required. Must be able to remain focused and alert while working on detailed technical tasks especially during incident response or time-sensitive audits.
Work Hours: 8 am - 5 pm Monday-Friday. Works some holidays some nights and some weekends
Location:700 Lavaca Street Austin Texas 78701
Department: Information Security
Criminal Driving Education CJIS fingerprints and Employment Background Checks Required.
For updates or questions on this position contact: