What You'll Do:
Define the required controls to be reviewed per the documentation framework and control implementation strategy
Review and assess control implementation and effectiveness in accordance with the organization’s information security program, including privacy and artificial intelligence
Actively participate in the information security audit engagements by serving as a liaison between external audit entities and internal teams
Coordinate with CIS business units to evaluate and promote alignment with control requirements, acting as a governance and oversight function
Produce, maintain, and provide control evidence remains with the designated control and evidence owners
Demonstrate understanding of the audit frameworks, audit artifact requests, and quality assurance process to ensure that the artifacts provided meet the applicable criteria, including the ability to recreate the artifacts
Implement risk-based monitoring to define risk treatment strategies and align to implemented control effectiveness when performing the reviews of the artifacts
Assist with day-to-day operational security to ensure functional alignment with applicable policies, standards, frameworks, laws, and regulations
Monitor security incidents, metrics, account review, and perform incident response as necessary when deviations from expected baselines occur
Provide input into new strategies, technologies, and projects within the organization to assure ‘secure by design’, ‘privacy by design’, and adherence to current control requirements
Ensure program level compliance with applicable laws, standards, and guidance
Other tasks and responsibilities as assigned
What You'll Need:
Bachelor’s degree in Computer Science, Cybersecurity, IT Compliance, or related field*
1+ years’ experience in IT auditing, security operations, or related position
Experience with the CIS control and compliance evaluation requirements, examples would include (ISO27001, ISO27701, SOC 2, NIST Cybersecurity Framework (CSF), NIST 800-53, NIST 800-171, etc.)
Knowledge and application of the CIS Critical Security Controls and MITRE Framework
This position requires the individual to be a citizen of the United States of America
It's a Plus if You Have:
Non-Profit experience
Contributed to or developed information technology policies, standards, and procedures
Experience performing audit, assessment, or compliance oversight activities and communicating control expectations, findings, and cybersecurity best practices to end users, system administrators, peers, and executive leadership
CISA certification
COBIT5, FIBF, CJIS or other related frameworks for implementing cybersecurity controls
*Additional years of relevant experience or a combination of an Associate’s degree or equivalent and relevant experience may be substituted for the Bachelor’s degree.
At CIS, we are committed to providing an inclusive environment in which the diverse backgrounds, experiences, and views of our employees, members, and customers are valued and respected. It is through this commitment that we are able to work together towards our common mission: to make the connected world a safer place.
Compensation Range:
USD$29.28 - $46.83Skills Required
- Bachelor's degree in Computer Science, Cybersecurity, IT Compliance, or a related field; an equivalent associate degree and relevant experience may be substituted.
- At least 1 year of experience in IT auditing, security operations, or a related position.
- Experience with CIS controls and compliance evaluation requirements, including frameworks such as ISO 27001, ISO 27701, SOC 2, NIST CSF, NIST 800-53, or NIST 800-171.
- Knowledge and application of the CIS Critical Security Controls and MITRE Framework.
- Must be a citizen of the United States of America.
- Non-profit experience.
- Experience developing or contributing to information technology policies, standards, and procedures.
- Experience performing audit, assessment, or compliance oversight activities and communicating control expectations, findings, and cybersecurity best practices.
- CISA certification.
- Experience with COBIT5, FIBF, CJIS, or related cybersecurity control frameworks.
What We Do
The Center for Internet Security, Inc. (CIS®) makes the connected world a safer place for people, businesses, and governments through our core competencies of collaboration and innovation. We are a community-driven nonprofit, responsible for the CIS Controls® and CIS Benchmarks™, globally recognized best practices for securing IT systems and data. We lead a global community of IT professionals to continuously evolve these standards and provide products and services to proactively safeguard against emerging threats. Our CIS Hardened Images® provide secure, on-demand, scalable computing environments in the cloud. CIS is home to the Multi-State Information Sharing and Analysis Center® (MS-ISAC®), the trusted resource for cyber threat prevention, protection, response, and recovery for U.S. State, Local, Tribal, and Territorial government entities, and the Elections Infrastructure Information Sharing and Analysis Center® (EI-ISAC®), which supports the rapidly changing cybersecurity needs of U.S. elections offices.








