Senior Staff IT Security Auditor
Western Governors UniversityAbout the role
If you’re passionate about building a better future for individuals, communities, and our country—and you’re committed to working hard to play your part in building that future—consider WGU as the next step in your career.
Driven by a mission to expand access to higher education through online, competency-based degree programs, WGU is also committed to being a great place to work for a diverse workforce of student-focused professionals. The university has pioneered a new way to learn in the 21st century, one that has received praise from academic, industry, government, and media leaders. Whatever your role, working for WGU gives you a part to play in helping students graduate, creating a better tomorrow for themselves and their families.
The salary range for this position takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs.
At WGU, it is not typical for an individual to be hired at or near the top of the range for their position, and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is:
Job Description
Job Summary
The Senior Staff IT Security Auditor (one level under Principal-level) serves as an experienced security professional and trusted advisor to internal business units and IT departments. This role requires strong internal audit expertise, excellent client relationship skills, and the ability to mentor junior team members while independently managing complex audit engagements. The position reports to the Senior Manager of Information Security and plays a key role in executing the annual audit plan.
Key Responsibilities
Audit Planning & Execution
· Audit Planning Contribution: Actively participate in annual audit planning, providing risk insights and recommendations for audit scope and priorities
· Engagement Scoping: Improve detailed audit programs and testing procedures for assigned audits, determining appropriate scope and resource needs
· Multi-Engagement Management: Simultaneously manage 2-3 audit engagements while mentoring junior staff assigned to projects
· Methodology Enhancement: Recommend improvements to audit procedures and contribute to methodology development
Internal Client Advisory
· Department-Level Advisory: Serve as a trusted security advisor to department heads, IT managers, and business unit leaders
· Risk Consultation: Help internal clients understand security risks and develop practical mitigation strategies
· Relationship Management: Build strong, collaborative relationships with audit clients to facilitate open communication and effective remediation
· Control Design Support: Advise on control design and implementation to prevent issues before they occur
Technical Assessment & Testing
· Advanced Testing: Conduct sophisticated technical assessments, including configuration reviews, penetration test validation, and control effectiveness testing
· Root Cause Analysis: Identify underlying causes of control failures and systemic issues across the organization
· Cross-Functional Reviews: Lead audits spanning multiple departments and technology platforms
· Emerging Technology: Assess security controls in cloud environments, DevOps pipelines, and modern application architectures
· Data Analytics: Use data analysis tools to identify anomalies and test large populations of transactions
Communication & Reporting
· Management Presentations: Present audit findings and recommendations to the director and VP-level management with confidence and clarity
· Risk Communication: Translate technical vulnerabilities into business risks that resonate with non-technical stakeholders
· Report Writing: Produce clear, concise audit reports that drive action and provide practical recommendations
· Issue Negotiation: Navigate disagreements on findings and ratings through collaborative discussion and evidence-based arguments
· Status Reporting: Provide regular updates to the Senior Lead Auditor on engagement progress and emerging risks
Compliance & Risk Management
· Framework Application: Apply multiple regulatory frameworks (NIST, GLBA, FERPA, ISO 27001, SOC 2) to audit engagements
· Risk Assessment: Conduct risk assessments for assigned business areas and contribute to enterprise risk discussions
· Control Mapping: Map
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s