Mid-Level Audit/COOP Business Analyst
Chenega Services & Federal Solutions Washington, District of Columbia, United States · $140K–$150K/yr
Defense & Space · 1,001-5,000 employees
About the role
The analyst supports FISMA and OIG audits by evaluating information security controls, documenting audit procedures, and tracking remediation efforts. Additionally, they are responsible for developing disaster recovery tests, managing backup strategies, and overseeing system restoration processes.
What they look for
Requirements
Candidates must hold a bachelor's degree in a relevant field and possess three to five years of experience in federal IT audits or cybersecurity compliance. The role requires strong analytical and communication skills, along with the ability to obtain and maintain a Public Trust clearance.
Benefits
Full description
Overview
Come join a company that strives for Extraordinary People and Exceptional Performance!
Chenega Services & Federal Solutions, LLC, a Chenega Professional Services’ company, is looking for a Mid-Level Audit/COOP Business Analyst to support the Federal Housing Finance Agency (FHFA) audit, assessment and continuity of operations (COOP) activities by evaluating information technology systems, cybersecurity controls, and business processes. This position supports Federal Information Security Modernization Act (FISMA) audits, Office of Inspector General (OIG) audits, information technology control assessments, implementation of COOP and remediation tracking activities. The analyst is responsible for documenting audit procedures, analyzing technical and operational evidence, identifying control weaknesses, and communicating findings and recommendations to stakeholders.
Our company offers employees the opportunity to join a team where there is a robust employee benefits program, management engagement, quality leadership, an atmosphere of teamwork, recognition for performance, and promotion opportunities. We actively strive to channel our highly engaged employee’s knowledge, critical thinking, and innovative solutions for our clients.
Responsibilities
- Support the planning, execution, and reporting of FISMA audits, OIG audits, information technology audits, and cybersecurity assessments.
- Evaluate information security controls and assess compliance with FISMA, NIST guidance, FHFA policies, and federal cybersecurity requirements.
- Collect, review, and maintain audit evidence, supporting documentation, and workpapers in accordance with federal audit standards.
- Coordinate with system owners, cybersecurity personnel, business stakeholders, and audit teams to obtain required documentation and evidence.
- Assist in developing audit programs, test procedures, risk assessments, and evaluation methodologies.
- Track audit findings, recommendations, corrective actions, and Plans of Action and Milestones (POA&Ms) through remediation and closure.
- Prepare status reports, briefing materials, dashboards, and executive-level summaries of audit activities and remediation efforts.
- Participate in interviews, walkthroughs, control testing, and validation activities.
- Communicate audit results and recommendations clearly to technical and non-technical audiences.
- Maintain awareness of emerging cybersecurity threats, federal audit standards, and industry best practices.
- Assist senior auditors and project leadership in the execution of contract deliverables and customer support activities.
- Develop and Execute Disaster Recovery Tests and Simulations: Develop and execute disaster recovery tests and simulations to validate the effectiveness of DR plans and procedures.
- Implement and Manage Backup Strategies: Implement and manage backup strategies to ensure that data is regularly backed up and can be restored effectively.
- Oversee Data and System Restoration: Oversee the restoration of data and systems from backups in the event of a disaster or data loss incident.
- Maintain Detailed Documentation: Create and maintain detailed documentation of disaster recovery plans, processes, and procedures.
- Continuously Review and Improve DR Strategies: Continuously review and improve DR strategies and procedures to ensure they remain effective and up-to-date.
Qualifications
- Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Information Technology, Accounting, Business Administration, or a related field.
- Three (3) to five (5) years of experience supporting federal IT audits, cybersecurity assessments, FISMA evaluations, OIG audits, COOP implementations or related compliance activities.
- Experience maintaining audit documentation, workpapers, and supporting evidence.
- Experience with disaster recovery planning, risk assessments, and business impact analyses, including the development and execution of disaster recovery tests and simulations.
- Strong written and verbal communication skills.
- Ability to obtain and maintain a Public Trust clearance.
Preferred Qualifications:
- Certified Information Systems Auditor (CISA).
- Certified Information Systems Security Professional (CISSP).
- Certified Information Security Manager (CISM).
- Experience reviewing Service Organization Control (SOC) reports.
- Experience using Governance, Risk, and Compliance (GRC) platforms or audit management tools.
- Experience developing executive-level dashboards and reporting metrics.
- Familiarity with cybersecurity continuous monitoring programs.
Knowledge, Skills and Abilities:
- Ability to analyze large datasets and identify risks, trends, and control weaknesses.
- Strong analytical, organizational, and problem-solving skills.
- Ability to prepare professional reports, presentations, audit documentation, and briefing materials.
- Ability to communicate technical concepts effectively to both technical and non-technical audiences.
- Ability to manage multiple assignments and meet established deadlines.
- Proficiency with Microsoft Office Suite, including Excel, Word, PowerPoint, Outlook, and Teams.
- Ability to work independently and collaboratively in a hybrid work environment.
- Ability to maintain professionalism and confidentiality while handling sensitive information.
Final salary determination based on skill-set, qualifications, and approved funding.
Many of our jobs come with great benefits – Some offerings are dependent upon the role, work schedule, or location, and may include the following:
Paid Time Off
PTO / Vacation – 5.67 hours accrued per pay period / 136 hours accrued annually
Paid Holidays - 11
California residents receive an additional 24 hours of sick leave a year
Health & Wellness
Medical
Dental
Vision
Prescription
Employee Assistance Program
Short- & Long-Term Disability
Life and AD&D Insurance
Spending Account
Flexible Spending Account
Health Savings Account
Health Reimbursement Account
Dependent Care Spending Account
Commuter Benefits
Retirement
401k / 401a
Voluntary Benefits
Hospital Indemnity
Critical Illness
Accident Insurance
Pet Insurance
Legal Insurance
ID Theft Protection
Estimated Salary/Wage
USD $140,000.00/Yr. Up to USD $150,000.00/Yr.
Similar roles
-
Business Analyst II
Axon Scottsdale, Arizona, United States · $91K–$152K/yr
-
CRM Business Analyst
Sequoia Connect Ciudad de México, Mexico
-
Operations Business Analyst
Total Loan Services LLC Dayton, Ohio, United States
-
Sr. Portfolio Business Analyst
PlayStation Global San Diego, California, United States · $135K–$202K/yr
-
GCP Business Analyst
VIATEQ Corporation Washington, District of Columbia, United States · $80K–$130K/yr
-
Azure Business Analyst
VIATEQ Corporation Washington, District of Columbia, United States · $80K–$130K/yr