
IT Audit & Risk Assessor
On-site
Full Time
#Technology
#Legal Tech
#Cloud
#IT Audit
#Risk Assessment
#SOC 2
#HIPAA
#FedRAMP
#GDPR
#OWASP Top 10
#Agile
#Waterfall
Filevine is revolutionizing the legal industry by providing intuitive, cloud-based workflow tools that help professionals manage their organizations more effectively. Recognized by Deloitte and Inc. as one of the fastest-growing and most innovative technology companies in the country, we are dedicated to building a seamless intersection between legal and business operations. We are currently looking for a Senior IT Audit & Risk Assessor to join our Information Security team on-site in the United States to ensure our infrastructure and applications meet the highest security standards.
Responsibilities
- Manage CJIS obligations, including clearances and regular audits.
- Support federal and international security audits, such as FedRAMP, StateRAMP, and Canadian compliance requirements.
- Develop and execute the strategy for our GRC programs.
- Collaborate with Legal, HR, Compliance, and Development teams to implement secure IT best practices.
- Train staff on secure coding techniques to reduce the need for emergency patching.
- Oversee the resolution of audit, compliance, and risk assessment findings.
- Maintain comprehensive policy and procedure libraries.
- Complete security questionnaires and manage third-party vendor risks.
- Lead annual penetration testing and internal risk assessment initiatives.
Must-haves
- Bachelor’s degree in Computer Science, Information Technology, or a related field.
- At least 4 years of professional experience in IT audit and risk assessment.
- Strong knowledge of compliance frameworks including SOC 2, HIPAA, FedRAMP, GDPR, and CCPA/CPRA.
- Familiarity with the OWASP Top 10 and web-related technologies.
- Experience assessing technical security controls across Agile and Waterfall development environments.
- Excellent communication skills with the ability to explain complex security concepts to both technical teams and senior management.
- Proven ability to influence stakeholders and build strong professional relationships.
Nice-to-haves
- Extensive experience with formal audits and automated compliance tools.
- Professional certifications such as CISSP, CISA, CISM, CRISC, or CIPP/US.
- Specific experience with GRC tool implementation.
Benefits
- Comprehensive medical, dental, and vision insurance.
- Disability insurance coverage.
- Paid time off.
- Supportive work environment with ergonomic, height-adjustable workstations.
- Opportunities for professional growth within a dedicated leadership team.










