Associate Information Security Auditor in New York at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Associate Information Security Auditor based in the United States.
This is an opportunity to contribute to a mission-driven cybersecurity team focused on strengthening information security, privacy, and organizational resilience.
The Associate Information Security Auditor will evaluate security controls, assess their effectiveness, and help ensure alignment with established standards and regulatory requirements.
You will work closely with cybersecurity professionals, business teams, control owners, and external auditors across a broad range of audit and compliance activities.
The role combines information security auditing, governance, risk monitoring, compliance oversight, and operational security support.
You will help maintain high-quality audit evidence, identify control gaps, and support risk-based strategies that strengthen the overall security program.
The position also provides exposure to emerging technologies, including artificial intelligence, with an emphasis on secure-by-design and privacy-by-design principles.
This fully remote role is well suited to an early-career cybersecurity professional who is analytical, detail-oriented, collaborative, and eager to grow within a high-impact environment.
- Define the controls and requirements to be reviewed in accordance with established documentation frameworks and control implementation strategies.
- Evaluate control implementation and effectiveness across information security, privacy, artificial intelligence, and related compliance areas.
- Participate in information security audit engagements and serve as a liaison between external auditors and internal teams.
- Coordinate with business units to assess alignment with control requirements and provide governance and oversight support.
- Create, maintain, organize, and provide control evidence while coordinating with designated control and evidence owners.
- Review audit frameworks, artifact requests, and quality assurance requirements to ensure submitted evidence meets applicable criteria and can be reproduced when necessary.
- Apply risk-based monitoring approaches to inform risk treatment strategies and assess the effectiveness of implemented controls.
- Support day-to-day security operations and help ensure alignment with applicable policies, standards, frameworks, laws, and regulations.
- Monitor security incidents, metrics, account reviews, and other indicators, supporting incident response when deviations from expected security baselines occur.
- Contribute security and compliance perspectives to new strategies, technologies, and organizational projects, promoting secure-by-design and privacy-by-design practices.
- Help ensure program-level compliance with applicable laws, standards, regulatory requirements, and industry guidance.
- Perform additional information security, audit, compliance, and governance responsibilities as assigned.
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology Compliance, or a related field is required; additional relevant experience or an Associate’s degree combined with relevant experience may be considered in lieu of the degree.
- At least 1 year of professional experience in IT auditing, security operations, information security, compliance, or a related field.
- Experience evaluating information security controls and compliance requirements against frameworks such as ISO 27001, ISO 27701, SOC 2, NIST Cybersecurity Framework, NIST 800-53, or NIST 800-171.
- Working knowledge of the CIS Critical Security Controls and MITRE Framework.
- Ability to analyze control evidence, identify gaps and risks, communicate findings, and support practical remediation strategies.
- Strong attention to detail and the ability to maintain accurate documentation and evidence throughout audit and compliance activities.
- Effective written and verbal communication skills, with the ability to collaborate with technical teams, business stakeholders, auditors, and leadership.
- Ability to work independently while contributing effectively within a cybersecurity and compliance team.
- U.S. citizenship is required for this position.
- Experience in a nonprofit environment is a plus.
- Experience developing or contributing to information technology policies, standards, and procedures is preferred.
- Experience conducting audits, assessments, or compliance oversight activities and communicating control expectations, findings, and cybersecurity best practices is advantageous.
- CISA certification is a plus.
- Familiarity with COBIT5, FIBF, CJIS, or other cybersecurity control frameworks is beneficial.
- Compensation: $29.28–$46.83 USD per hour, with base pay determined by factors including education, experience, and skills.
- Fully remote work environment.
- Medical insurance options, including PPO, EPO, and HSA plans, with eligibility beginning on the first day of employment.
- Dental and vision insurance.
- $500 wellness card for eligible health coverage participants.
- 401(k) retirement plan with a 4% company match, vested from the first day of employment.
- Flexible Spending Account (FSA) and Dependent Care Account (DCA).
- Life insurance coverage.
- Bonding leave and paid time off.
- Paid holidays and a paid volunteering program.
- Bonus eligibility.
- Wellness program and employee engagement activities.
- Professional development opportunities and tuition reimbursement.
- Student loan paydown program.
- Employee referral program.
- Employee Assistance Program (EAP).
- Inclusive, collaborative workplace with opportunities for continuous learning and career development.