Peraton is seeking an experienced Information System Audit Engineer to serve as the program's primary expert on financial audit readiness, information systems audit compliance, and internal controls oversight for the BASIS program.
This is a senior advisory role with a primary focus on supporting and leading DoD financial audits — including FIAR, FISCAM, ICOFR, DHA MERHCF, and OMB Circular A-123 engagements — while also developing, implementing, and maintaining the internal processes, procedures, and compliance frameworks necessary to sustain continuous audit readiness across the DEERS application portfolio.
The selected candidate will serve as the principal liaison between the program team, Government stakeholders, and external audit bodies, ensuring all financial and information systems audit activities are executed with rigor, completeness, and timeliness. This individual will own the program's Compliance Audit Support Plan, lead Corrective Action Plan (CAP) development and remediation tracking, and provide actionable advisory recommendations to senior leadership and Government customers on audit findings, business process improvements, and internal control enhancements.
The position will be responsible for the following but not limited too:
This position is remote.
Responsibilities
- Serve as the senior advisor and primary point of contact for all DoD financial audit engagements, including DHA MERHCF, DoD CIO ICOFR, FIAR (Financial Improvement and Audit Readiness), and SSAE (Statement on Standards for Attestation Engagements).
- Provide comprehensive material and personnel support during anticipated external audit examinations, producing all required digital artifacts and deliverables per established audit criteria and timelines.
- Respond comprehensively to Provided By Client (PBC) data calls issued by external auditors, including the OIG (Office of Inspector General), GAO (Government Accountability Office), OUSD(C) (Office of the Under Secretary of Defense, Comptroller), and other external audit bodies.
- Actively demonstrate system controls to auditors to support DMDC application and systems control objectives during examination engagements.
- Advise program leadership and the Government on strategies to address Notice of Findings and Recommendations (NFRs) and Notifications of Findings (NOFs); evaluate and provide recommendations for their adjudication.
Continuous Audit Readiness & Internal Controls
- Proactively maintain continuous audit readiness by performing ongoing internal control (IC) assessments, business process analysis, and risk identification across the DEERS application portfolio.
- Develop, execute, and maintain a comprehensive Compliance Audit Support Plan encompassing audit readiness methodology, policies, and procedural documentation in compliance with FISCAM and FFMIA requirements.
- Ensure the application and compliance of Financial Management (FM) overlays to NIST SP 800-53 Rev 5 security controls, including ICAM (Identity, Credential, and Access Management) onboarding requirements, as they relate to financial internal control objectives.
- Support and provide advisory expertise for OMB Circular A-123, FISCAM, and RMF audit activities, ensuring alignment between IT general controls and financial management objectives.
- Coordinate with Product Managers and technical leads to identify system areas with potential vulnerabilities or compliance violations that may create audit exposure.
Internal Process & Procedure Development
- Develop, document, and implement internal processes and procedures to ensure program-wide compliance with all audit-related deliverable requirements specified in the Performance Work Statement (PWS).
- Establish and maintain an audit readiness methodology that standardizes how the program prepares for, executes, and follows up on audit engagements.
- Develop and maintain FISCAM and FFMIA procedural documentation, ensuring alignment with current Federal standards and DoD audit requirements.
- Create and enforce internal tracking mechanisms for audit deliverable deadlines, PBC data call responses, and corrective action milestones to ensure no deliverable lapses.
- Identify and devise new or revised policies, best practices, and business process improvements that address significant impediments to auditability across the program.
Corrective Action & Remediation Management
- Develop, execute, and manage Corrective Action Plans (CAPs) in response to audit findings, encompassing the full lifecycle: identification, tracking, and verification of corrective actions taken.
- Deliver actionable recommendations to improve client internal controls, accounting procedures, and financial statements based on audit outcomes and assessments.
- Monitor and report on CAP remediation progress to program leadership and Government stakeholders; escalate at-risk items in a timely manner.
- Coordinate cross-functionally with security, development, and operations teams to implement technical and procedural corrective actions within established remediation timelines.
Advisory & Stakeholder Engagement
- Advise senior program leadership and Government customers on all aspects of information systems audit, financial audit readiness, and internal controls compliance.
- Represent the program during external audit engagements and Government reviews; serve as the authoritative voice on audit-related matters at Integrated Progress Reviews (IPRs) and Monthly Status Reviews (MSRs).
- Provide advisory guidance on the integration of audit readiness activities within the program's Agile / DevSecOps delivery model to embed compliance by design.
- Brief Government stakeholders on audit readiness posture, open findings, remediation status, and process improvement initiatives on a recurring basis.