Base Career helps you apply smarter for this job.
Key skills for this role
The IT Auditor is responsible for maintaining and advancing Brandt's information security compliance posture across PCI DSS, SOC 2 Type 2, and GovRAMP, ensuring the company's internal controls, policies, and procedures satisfy regulatory and contractual requirements. This role reviews and assesses the adequacy of Brandt's IT controls, produces findings and remediation recommendations, and provides guidance for client contract governance related to security and compliance obligations. The Auditor works across every department to educate stakeholders, answer compliance questions, deliver training, and hold departments accountable to their compliance standards, while managing external relationships with assessors, pen testers, auditors, and compliance vendors. Success in this role requires being a stickler for standards without becoming a blocker: someone comfortable saying no, but who collaborates with stakeholders to find workable paths to compliance.
Must be US Citizen or Green Card holder
Full Time Salaried Position
Remote Work Within the Continental United States
Repo rts to: Chief Information Officer (CIO) / Chief Information Security Officer (CISO), Security Team
Team: Security (alongside Security Engineers)
Brandt is the get-outdoors company. State and local agencies steward the parks, lakes, and wildlife people come for; our platforms make getting there easy, from reserving a campsite to renewing a permit, and help agencies manage those resources sustainably. A family with a trip planned doesn't get a second try at opening day, and neither do we. We're modernizing our platform, building new products, and assembling high-performing teams that have AI embedded in every workflow.
Learn more about Brandt at brandtinfo.com .
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
, USA
, USA
, USA
, USA
, USA
The IT Auditor is responsible for maintaining and advancing Brandt's information security compliance posture across PCI DSS, SOC 2 Type 2, and GovRAMP, ensuring the company's internal controls, policies, and procedures satisfy regulatory and contractual requirements. This role reviews and assesses the adequacy of Brandt's IT controls, produces findings and remediation recommendations, and provides guidance for client contract governance related to security and compliance obligations. The Auditor works across every department to educate stakeholders, answer compliance questions, deliver training, and hold departments accountable to their compliance standards, while managing external relationships with assessors, pen testers, auditors, and compliance vendors. Success in this role requires being a stickler for standards without becoming a blocker: someone comfortable saying no, but who collaborates with stakeholders to find workable paths to compliance.
Own day-to-day compliance execution for PCI DSS, SOC 2 Type 2, and GovRAMP, including audit prep, evidence collection, and remediation tracking
Conduct internal audits and control assessments; produce formal reports with findings and prioritized recommendations for improvement
Conduct periodic gap analyses and readiness assessments ahead of formal audits or certification milestones
Assess and maintain controls against the NIST 800-53 control framework as it applies to GovRAMP/FedRAMP authorization
Maintain and administer Brandt's GRC tool as the system of record for controls, policies, and evidence
Provide guidance on client contract governance, ensuring security/compliance terms are understood and achievable before commitments are made
Partner with all departments (not limited to IT and Security) to educate staff on compliance requirements, answer questions, and deliver training
Hold department heads accountable to their compliance obligations; escalate persistent gaps to the CIO
Draft, maintain, and enforce company security policies, ensuring adherence within Security, IT, and beyond
Manage relationships with external compliance organizations, third-party assessors, penetration testers, and compliance-related vendors
Monitor changes in regulatory and framework requirements (PCI, SOC 2, GovRAMP/FedRAMP, NIST 800-53) and update Brandt's compliance program accordingly
Collaborate with Security Engineers and IT/Hosting teams to translate audit findings into practical, implementable controls
Balance rigor with pragmatism: apply consistent standards while working with stakeholders to find compliant solutions rather than simply issuing denials
Outdoor recreation technology company providing licensing, registrations, reservations, and e-commerce solutions to conservation agencies and their users.
Visit company websiteJobs and hiring trendsUSD 107000-120000 yearly / year
Full-time
Mid · 4+ years experience
Remote
Apply faster on company sites with our extension.