IT Auditor
Summary
The IT Auditor owns Brandt's information security compliance program across PCI DSS, SOC 2 Type 2, and GovRAMP: running internal audits, control assessments, evidence collection, and remediation tracking, administering the GRC tool, managing external assessors, and training stakeholders company-wide. Requires IT audit/GRC experience with NIST 800-53 and related frameworks.
IT Auditor
Must be US Citizen or Green Card holder
Full Time Salaried Position
Remote Work Within the Continental United States
Reports to: Chief Information Officer (CIO) / Chief Information Security Officer (CISO), Security Team
Team: Security (alongside Security Engineers)
About Brandt
Brandt is the get-outdoors company. State and local agencies steward the parks, lakes, and wildlife people come for; our platforms make getting there easy, from reserving a campsite to renewing a permit, and help agencies manage those resources sustainably. A family with a trip planned doesn't get a second try at opening day, and neither do we. We're modernizing our platform, building new products, and assembling high-performing teams that have AI embedded in every workflow.
Learn more about Brandt at .
About the Role
The IT Auditor is responsible for maintaining and advancing Brandt's information security compliance posture across PCI DSS, SOC 2 Type 2, and GovRAMP, ensuring the company's internal controls, policies, and procedures satisfy regulatory and contractual requirements. This role reviews and assesses the adequacy of Brandt's IT controls, produces findings and remediation recommendations, and provides guidance for client contract governance related to security and compliance obligations. The Auditor works across every department to educate stakeholders, answer compliance questions, deliver training, and hold departments accountable to their compliance standards, while managing external relationships with assessors, pen testers, auditors, and compliance vendors. Success in this role requires being a stickler for standards without becoming a blocker: someone comfortable saying no, but who collaborates with stakeholders to find workable paths to compliance.
Expectations
- Own day-to-day compliance execution for PCI DSS, SOC 2 Type 2, and GovRAMP, including audit prep, evidence collection, and remediation tracking
- Conduct internal audits and control assessments; produce formal reports with findings and prioritized recommendations for improvement
- Conduct periodic gap analyses and readiness assessments ahead of formal audits or certification milestones
- Assess and maintain controls against the NIST 800-53 control framework as it applies to GovRAMP/FedRAMP authorization
- Maintain and administer Brandt's GRC tool as the system of record for controls, policies, and evidence
- Provide guidance on client contract governance, ensuring security/compliance terms are understood and achievable before commitments are made
- Partner with all departments (not limited to IT and Security) to educate staff on compliance requirements, answer questions, and deliver training
- Hold department heads accountable to their compliance obligations; escalate persistent gaps to the CIO
- Draft, maintain, and enforce company security policies, ensuring adherence within Security, IT, and beyond
- Manage relationships with external compliance organizations, third-party assessors, penetration testers, and compliance-related vendors
- Monitor changes in regulatory and framework requirements (PCI, SOC 2, GovRAMP/FedRAMP, NIST 800-53) and update Brandt's compliance program accordingly
- Collaborate with Security Engineers and IT/Hosting teams to translate audit findings into practical, implementable controls
- Balance rigor with pragmatism: apply consistent standards while working with stakeholders to find compliant solutions rather than simply issuing denials
Qualifications
- 4–6 years of experience in IT audit, information security compliance, or GRC, ideally spanning multiple frameworks (PCI DSS, SOC 2, GovRAMP/FedRAMP, or similar)
- GovRAMP or FedRAMP experience strongly preferred
- Familiarity with NIST 800-53 controls and their application to GovRAMP/FedRAMP authorization
- Security certification such as CISA, CISSP, or CISM (CISA preferred)
- Hands-on experience with a GRC platform (e.g., Vanta, Drata, Secureframe, OneTrust, or equivalent)
- Working knowledge of IT general controls (ITGCs), risk assessment methodology, and control testing
- Demonstrated experience working collaboratively and cross-functionally, with a positive, solutions-oriented attitude
- Excellent written and verbal communication skills; able to translate technical findings for non-technical audiences
- Bachelor’s degree in Information Systems, Computer Science, Business, or related field, or equivalent experience
Compensation & benefits
Compensation is set within Brandt's job architecture for the Senior band with a salary range of $107,000.00-$120,000.00. Level and salary are determined by your experience, the scope of the team you'll lead, and internal equity. We back the role with benefits built for people staying for the long haul:
- Health insurance, with several plans fully covered for you and discounted coverage for family members.
- Vision insurance fully covered for you, with discounted coverage available for family members; dental insurance available for purchase.
- A flexible, open PTO policy available after 30 days of continuous service, plus nine paid holidays.
- A 401(k) plan with company matching contributions, plus eligibility for an annual year-end performance bonus targeted at 7% of base salary.
- Up to eight weeks of paid parental leave.
- Life insurance and long-term disability insurance, both fully covered by the company.
- A free Udemy account for ongoing professional development.
Brandt Information Services, LLC is an Equal Employment Opportunity (EEO) employer and welcomes all qualified applicants. Applicants receive fair and impartial consideration without regard to race, sex, color, religion, national origin, age, disability, veteran status, genetic data, or other legally protected status.
Skills
As published by greenhouse · 25 questions · 1 written answer
Basics
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter
Short answers (10)
- Preferred First Name optional
- LinkedIn Profile optional
- Website optional
- LinkedIn Profile optional
- If referred by an employee, please give employee name.
- What is your desired compensation?
- Available start date?
- If Yes, provide detailed information including what you were charged with, state where you were charged, the date of conviction and the penalty imposed.
- If Yes, what where the charges? Where? (city/state) Date of charges?
- If Yes, what where the charges? Where? (city/state) Date of charges?
Pick from a list (14)
- Are you 18 years of age or older?
- Are you legally authorized to work in the United States?
- Will you now or in the future require sponsorship for employment visa status?
- Are you related to a current employee of Brandt?
- Background Information The nature of Brandt's work involves working with governmental agencies that require a satisfactory criminal history check in accordance with applicable state law and agency security policies. As part of our contractual requirements, Brandt is required to perform due diligence on its employees regarding any previous criminal history. Depending on the role for which you are hired, this may include a Level 2 fingerprint criminal background check and subsequent approval by the law enforcement agencies for which we perform work. As part of our ongoing requirements with our state agency clients, your fingerprints will remain on file with law enforcement authorities as long as you are employed with Brandt and subject to periodic reviews. Have you ever been convicted of a felony or a first-degree misdemeanor?
- Have ever plead nolo contendere or guilty to a crime which is a felony or a first-degree misdemeanor?
- Have you have the adjudication of guilt withheld for a crime which is a felony or a first-degree misdemeanor?
- Have you ever failed a drug test?
- Do you have a CISA certification?
- Do you have GovRamp experience?
- Do you have FedRamp experience?
- Do you have PCI experience?
- I certify that my answers to all questions are true and correct without any consequential omissions of any kind whatsoever. I understand that if I am employed, any false, misleading or otherwise incorrect statements made on this application or during the pre-employment process may be grounds for my immediate termination. I further understand that if I am hired for this position, that I must submit to a criminal background check to investigate and further verify the statements contained in this application in order to proceed with employment. Acceptance:
- Check the box below if you would like to receive text messages from the company regarding your status in the hiring process. Data rates may apply. (n/a)
Written answers (1)
- Explain your auditor experience.