Point your AI agent at freehire and let it find you a job.

Get the CLI →

Brandt Information Services. LLC

NewBe an early applicant

IT Auditor

Posted Updated
Discussion

Summary

The IT Auditor owns Brandt's information security compliance program across PCI DSS, SOC 2 Type 2, and GovRAMP: running internal audits, control assessments, evidence collection, and remediation tracking, administering the GRC tool, managing external assessors, and training stakeholders company-wide. Requires IT audit/GRC experience with NIST 800-53 and related frameworks.

IT Auditor

Must be US Citizen or Green Card holder

Full Time Salaried Position

Remote Work Within the Continental United States

Reports to: Chief Information Officer (CIO) / Chief Information Security Officer (CISO), Security Team

Team: Security (alongside Security Engineers)

About Brandt

Brandt is the get-outdoors company. State and local agencies steward the parks, lakes, and wildlife people come for; our platforms make getting there easy, from reserving a campsite to renewing a permit, and help agencies manage those resources sustainably. A family with a trip planned doesn't get a second try at opening day, and neither do we. We're modernizing our platform, building new products, and assembling high-performing teams that have AI embedded in every workflow.

Learn more about Brandt at .

About the Role

The IT Auditor is responsible for maintaining and advancing Brandt's information security compliance posture across PCI DSS, SOC 2 Type 2, and GovRAMP, ensuring the company's internal controls, policies, and procedures satisfy regulatory and contractual requirements. This role reviews and assesses the adequacy of Brandt's IT controls, produces findings and remediation recommendations, and provides guidance for client contract governance related to security and compliance obligations. The Auditor works across every department to educate stakeholders, answer compliance questions, deliver training, and hold departments accountable to their compliance standards, while managing external relationships with assessors, pen testers, auditors, and compliance vendors. Success in this role requires being a stickler for standards without becoming a blocker: someone comfortable saying no, but who collaborates with stakeholders to find workable paths to compliance.

Expectations

  • Own day-to-day compliance execution for PCI DSS, SOC 2 Type 2, and GovRAMP, including audit prep, evidence collection, and remediation tracking
  • Conduct internal audits and control assessments; produce formal reports with findings and prioritized recommendations for improvement
  • Conduct periodic gap analyses and readiness assessments ahead of formal audits or certification milestones
  • Assess and maintain controls against the NIST 800-53 control framework as it applies to GovRAMP/FedRAMP authorization
  • Maintain and administer Brandt's GRC tool as the system of record for controls, policies, and evidence
  • Provide guidance on client contract governance, ensuring security/compliance terms are understood and achievable before commitments are made
  • Partner with all departments (not limited to IT and Security) to educate staff on compliance requirements, answer questions, and deliver training
  • Hold department heads accountable to their compliance obligations; escalate persistent gaps to the CIO
  • Draft, maintain, and enforce company security policies, ensuring adherence within Security, IT, and beyond
  • Manage relationships with external compliance organizations, third-party assessors, penetration testers, and compliance-related vendors
  • Monitor changes in regulatory and framework requirements (PCI, SOC 2, GovRAMP/FedRAMP, NIST 800-53) and update Brandt's compliance program accordingly
  • Collaborate with Security Engineers and IT/Hosting teams to translate audit findings into practical, implementable controls
  • Balance rigor with pragmatism: apply consistent standards while working with stakeholders to find compliant solutions rather than simply issuing denials

Qualifications

  • 4–6 years of experience in IT audit, information security compliance, or GRC, ideally spanning multiple frameworks (PCI DSS, SOC 2, GovRAMP/FedRAMP, or similar)
  • GovRAMP or FedRAMP experience strongly preferred
  • Familiarity with NIST 800-53 controls and their application to GovRAMP/FedRAMP authorization
  • Security certification such as CISA, CISSP, or CISM (CISA preferred)
  • Hands-on experience with a GRC platform (e.g., Vanta, Drata, Secureframe, OneTrust, or equivalent)
  • Working knowledge of IT general controls (ITGCs), risk assessment methodology, and control testing
  • Demonstrated experience working collaboratively and cross-functionally, with a positive, solutions-oriented attitude
  • Excellent written and verbal communication skills; able to translate technical findings for non-technical audiences
  • Bachelor’s degree in Information Systems, Computer Science, Business, or related field, or equivalent experience

Compensation & benefits

Compensation is set within Brandt's job architecture for the Senior band with a salary range of $107,000.00-$120,000.00. Level and salary are determined by your experience, the scope of the team you'll lead, and internal equity. We back the role with benefits built for people staying for the long haul:

  • Health insurance, with several plans fully covered for you and discounted coverage for family members.
  • Vision insurance fully covered for you, with discounted coverage available for family members; dental insurance available for purchase.
  • A flexible, open PTO policy available after 30 days of continuous service, plus nine paid holidays.
  • A 401(k) plan with company matching contributions, plus eligibility for an annual year-end performance bonus targeted at 7% of base salary.
  • Up to eight weeks of paid parental leave.
  • Life insurance and long-term disability insurance, both fully covered by the company.
  • A free Udemy account for ongoing professional development.

Brandt Information Services, LLC is an Equal Employment Opportunity (EEO) employer and welcomes all qualified applicants. Applicants receive fair and impartial consideration without regard to race, sex, color, religion, national origin, age, disability, veteran status, genetic data, or other legally protected status.

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available