1

Audit Manager Jobs in Guam (NOW HIRING)

Be Seen First

Vulnerability Remediation Asset Management (VRAM). * Perform System-Level Continuous Monitoring (SLCM) activities, including: * * Vulnerability scanning. * Audit log review. * Remediation tracking.

New

Be Seen First

Vulnerability Remediation Asset Management (VRAM). * Perform System-Level Continuous Monitoring (SLCM) activities, including: * * Vulnerability scanning. * Audit log review. * Remediation tracking.

New

GU

$16.75 - $21.25/hr

Conducts random chart audits to ensure accuracy of medical records. * Provides application support ... Follows up with Senior Managers to ensure the correct action is taken. * Demonstrates solid ...

GU · On-site

Develop and execute a comprehensive Vulnerability Management Strategy; perform vulnerability and ... Sustain System-Level Continuous Monitoring (SLCM): conduct routine scans, audit log analysis, drive ...

GU · On-site

Lead internal and external audit activities. * Strengthen enterprise risk management and compliance frameworks. * Ensure compliance with applicable accounting standards, tax regulations, and ...

GU · On-site

Design, manage, secure, and maintain complex industrial and building automation network ... audits, incident reports, performance analysis, configuration backup validation, RMF/STIG artifacts)

Lead internal and external audit activities. * Strengthen enterprise risk management and compliance frameworks. * Ensure compliance with applicable accounting standards, tax regulations, and ...

GU · On-site

Support Board reporting, governance activities, and executive presentations. * Assist with audit activities and ensure strong financial governance practices. Treasury & Capital Management * Monitor ...

Clinician (C&Y) (50091)

Hagatna, GU · On-site

$18 - $21/hr

Provide brief case management to coordinate referrals and connect clients with appropriate internal ... Participate in peer chart audit reviews, and quality assurance activities to ensure regulatory ...

GU · On-site

$17.50 - $22/hr

Participates in and respond to audits and inspections related to ordnance accounting, ordnance ... Provides metrics for expenditures; maintains all files concerning ordnance management IAW OPNAV and ...

... management system, applicable international and local standards and customer requirements. * In ... and audit findings are addressed with efficient service quality investigation, including: root ...

Showing results 21-39

Audit Manager information

What does an audit manager do?

An Audit Manager oversees and coordinates the auditing process within an organization or for clients. Their responsibilities include planning and executing audits, managing audit teams, assessing financial statements for accuracy and compliance, and identifying areas of risk or improvement. They also ensure that all audits are conducted in accordance with relevant laws, standards, and company policies. Audit Managers often serve as a bridge between clients or departments and their audit team, providing guidance, feedback, and recommendations based on audit findings.

What is the difference between Audit Manager vs Internal Auditor?

AspectAudit ManagerInternal Auditor
CertificationsCPA, CIA, CISACPA, CIA, CISA
Work EnvironmentPublic accounting firms, corporations, government agenciesInternal departments within organizations
ResponsibilitiesOversees audit teams, plans audits, reports to managementConducts internal audits, assesses internal controls, recommends improvements
Industry UsageWidely used in accounting, finance, and consulting firmsCommon within large organizations' internal audit departments

Audit Managers focus on leading audit teams and managing external or internal audits, often working across multiple clients or departments. Internal Auditors perform detailed internal reviews within a single organization to improve controls and compliance. Both roles require similar certifications and work environments but differ mainly in scope and focus.

What are the key skills and qualifications needed to thrive as an audit manager, and why are they important?

To thrive as an Audit Manager, you need strong analytical abilities, in-depth knowledge of accounting standards, and typically a bachelor's degree in accounting or finance, often supported by a CPA or similar certification. Familiarity with audit management software, data analytics tools, and ERP systems is essential. Leadership, attention to detail, and excellent communication skills help Audit Managers guide teams and interact effectively with clients. These skills ensure the delivery of high-quality audits, risk mitigation, and compliance with regulatory standards.

How does an audit manager typically balance client expectations with regulatory compliance requirements?

Audit Managers often face the challenge of meeting client deadlines and expectations while ensuring all work strictly adheres to regulatory standards and professional guidelines. This involves clear communication with clients about timelines, requirements, and necessary documentation, as well as staying up-to-date with evolving audit regulations. Audit Managers also lead their teams to manage workloads effectively and conduct thorough quality reviews, ensuring that both client satisfaction and compliance are achieved. Regular training and collaboration with other departments, such as legal or risk, help maintain this balance.

What does an audit manager do?

Audit managers supervise an audit team and inspect the financial records of companies. As an audit manager, you may work as a general business auditor or specialize in a particular industry. For example, premium audit managers work exclusively in the insurance field. Regardless of industry, your job duties as an audit manager include traveling to business offices to conduct audits, auditing companies’ accounting and financial records, overseeing your audit team, and writing reports of your findings.

What are the most commonly searched types of Audit jobs in Guam? The most popular types of Audit jobs in Guam are:
What are popular job titles related to Audit Manager jobs in GU? For Audit Manager jobs in GU, the most frequently searched job titles are:
Infographic showing various Audit Manager job openings in Guam as of August 2026, with employment types broken down into 92% Full Time, and 8% Contract. Highlights an 100% In-person job distribution.

Information Systems Security Analyst

EIGENNET LLC

Santa Rita, GU • On-site

$65K - $75K/yr

Full-time

Posted 3 days ago

New

Be Seen First

After you apply to this job, you can share why you’re interested to jump to the top of the candidate list.


Job description

Job Title: Information Systems Security Engineer (ISSE) – Systems Security Analyst

Employment Type: Full-Time – Up to 40 hours per week
Employment Status: Contingent Upon Contract Award
Customer Agency: Naval Facilities Engineering Systems Command (NAVFAC) Marianas – Command Information Office (CIO3 Office)

Work Location: On-Site

Place of Performance:

  • Naval Facilities Engineering Systems Command (NAVFAC) Marianas facilities:
    • Building 205, Halsey Drive, Nimitz Hill, Piti, Guam 96915.
    • Building 3179, Sumay Drive, Naval Base Guam, Santa Rita, Guam 96915.
  • Additional Government facilities as required:
    • Marine Corps Base Camp Blaz, Guam.
    • Andersen Air Force Base, Guam.

 

Position Overview

·       The Information Systems Security Engineer (ISSE) will provide cybersecurity engineering support to the Naval Facilities Engineering Systems Command (NAVFAC) Marianas Command Information Office (CIO). The ISSE will support the protection, operation, and continuous improvement of Facility-Related Control Systems (FRCS) by ensuring the confidentiality, integrity, availability, and security of Government information systems, networks, and data.

·       The successful candidate will execute cybersecurity engineering activities supporting the Risk Management Framework (RMF), Authority to Operate (ATO) authorization processes, vulnerability management, continuous monitoring, security assessments, and cybersecurity risk management activities across NAVFAC Marianas installations.

·       This position requires demonstrated experience supporting Department of the Navy (DoN) and Department of Defense (DoD) cybersecurity environments, including RMF implementation, NIST SP 800-53 security controls, eMASS authorization package management, vulnerability assessments, Security Technical Implementation Guide (STIG) compliance, Plan of Action and Milestones (POA&M) management, and configuration management activities.

·       The ISSE will work independently with minimal Government supervision and serve as a mission-essential cybersecurity resource supporting cybersecurity operations, Configuration Control Board (CCB) activities, and Cyber Emergency Response Team (CERT) functions.

 

Essential Duties and Responsibilities

  • Execute Risk Management Framework (RMF) lifecycle activities (Steps 1–6) in accordance with applicable Department of the Navy (DoN), Department of Defense (DoD), and NAVFAC Echelon II cybersecurity guidance.
  • Review and validate:
    • System inventories.
    • Security documentation.
    • Authorization artifacts.
    • Compliance evidence.
    • RMF package information.
  • Support Authority to Operate (ATO) authorization activities for Facility-Related Control Systems (FRCS), including:
    • Maintaining and tracking authorization packages.
    • Supporting annual security reviews.
    • Preparing and maintaining Memorandums for Record (MFRs) for approved baseline changes during RMF Step 6 activities.
  • Develop, maintain, and update cybersecurity documentation, including:
    • System Security Plans (SSPs).
    • Security policies.
    • Standard Operating Procedures (SOPs).
    • Implementation plans.
    • After-action reports.
    • Cybersecurity-related technical documentation.
  • Apply NIST SP 800-53 security controls and tailor cybersecurity requirements to FRCS operational environments.
  • Develop and execute vulnerability management strategies using approved DoD and Department of the Navy cybersecurity processes.
  • Perform vulnerability and compliance assessments using approved cybersecurity tools, including:
    • ACAS/Nessus.
    • Security Content Automation Protocol (SCAP).
    • Evaluate STIG.
    • Security Center.
    • Vulnerability Remediation Asset Management (VRAM).
  • Perform manual Security Technical Implementation Guide (STIG) and Security Requirements Guide (SRG) compliance validation using:
    • .ckl files.
    • .cklb checklist formats.
  • Generate cybersecurity assessment reports and maintain vulnerability documentation, including:
    • Scan results.
    • Compliance artifacts.
    • Remediation documentation.
    • Risk acceptance documentation.
  • Upload and maintain cybersecurity artifacts within applicable systems, including:
    • Enterprise Mission Assurance Support Service (eMASS).
    • Vulnerability Remediation Asset Management (VRAM).
  • Perform System-Level Continuous Monitoring (SLCM) activities, including:
    • Vulnerability scanning.
    • Audit log review.
    • Remediation tracking.
    • Plan of Action and Milestones (POA&M) updates.
  • Support RMF Step 4 assessment activities by:
    • Coordinating technical evidence collection.
    • Performing system validation activities.
    • Supporting security assessment preparation with system owners and assessment teams.
  • Serve as a cybersecurity technical representative and/or Configuration Management (CM) Officer supporting Configuration Control Board (CCB) activities.
  • Perform:
    • Cybersecurity impact analyses.
    • Risk assessments.
    • Security reviews for proposed FRCS configuration changes.
  • Support cybersecurity incident response operations as part of the MAR Cyber Emergency Response Team (CERT).
  • Participate in designated on-call rotations and provide cybersecurity support during emergency or mission-essential conditions.
  • Coordinate cybersecurity support activities across multiple FRCS environments and installation locations.
  • Prepare and provide cybersecurity status reporting, including:
    • Bi-weekly RMF status reports.
    • Monthly status reports.
    • Contract-required documentation.
  • Maintain FRCS RMF project tracking information using applicable project management systems, including:
    • Maximo.
    • eProjects.
  • Provide on-site cybersecurity support at Naval Base Guam and other supported locations, including:
    • Marine Corps Base Camp Blaz.
    • Andersen Air Force Base.
  • Perform other cybersecurity engineering duties as assigned by the Contracting Officer’s Representative (COR).

 

Required Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Information Technology, Engineering, or a related technical discipline preferred.
  • Equivalent combinations of education, professional experience, and cybersecurity certifications may be considered.
  • Minimum five (5) years of professional experience supporting Risk Management Framework (RMF) activities.
  • Minimum one (1) year of specialized experience supporting Facility-Related Control Systems (FRCS) cybersecurity engineering and RMF implementation.
  • Demonstrated experience executing RMF lifecycle activities (Steps 1–6) within:
    • Department of Defense environments.
    • Department of the Navy environments.
  • Experience supporting Authority to Operate (ATO) processes, including:
    • Authorization package development.
    • Security reviews.
    • Security documentation maintenance.
  • Experience developing and maintaining cybersecurity documentation, including:
    • System Security Plans (SSPs).
    • Plans of Action and Milestones (POA&Ms).
    • Memorandums for Record (MFRs).
    • SOPs.
    • Security policies.
    • Implementation plans.
  • Experience implementing and assessing NIST SP 800-53 security controls.
  • Experience performing cybersecurity assessments using DoD-approved tools, including:
    • ACAS/Nessus.
    • SCAP.
    • Evaluate STIG.
    • Security Center.
    • VRAM.
  • Experience performing manual STIG/SRG compliance validation using .ckl and .cklb checklist formats.
  • Experience supporting continuous monitoring activities, including:
    • Vulnerability management.
    • Audit reviews.
    • Remediation tracking.
    • POA&M management.
  • Experience supporting Configuration Control Board (CCB) activities and cybersecurity impact assessments.
  • Experience supporting cybersecurity incident response operations, CERT activities, or equivalent cyber defense functions.
  • Strong written and verbal communication skills with the ability to communicate effectively with:
    • Government personnel.
    • System owners.
    • Information Systems Security Managers (ISSMs).
    • Cybersecurity stakeholders.
  • Ability to work independently, prioritize multiple tasks, and perform cybersecurity activities with minimal Government supervision.
  • Ability to operate within secure military installation environments while complying with DoD security requirements.
  • Ability to perform essential field activities, including:
    • Walking on uneven terrain.
    • Climbing ladders.
    • Bending, crouching, and reaching.
    • Lifting and moving IT equipment up to 25 pounds.
    • Conducting on-site cybersecurity assessments.

 

Preferred Qualifications

  • Experience supporting:
    • NAVFAC cybersecurity operations.
    • Department of the Navy cybersecurity programs.
    • DoD cybersecurity environments.
  • Experience supporting:
    • Facility-Related Control Systems (FRCS).
    • Operational Technology (OT).
    • Industrial Control Systems (ICS).
    • Building automation and security systems.
  • Hands-on experience managing RMF authorization packages within eMASS.
  • Experience using eMASS for:
    • Authorization package management.
    • Artifact uploads.
    • Package maintenance.
  • Knowledge of:
    • DoN cybersecurity directives.
    • NAVFAC Echelon II RMF Business Rules.
    • DoD cybersecurity policies.
  • Experience tracking cybersecurity project activities using:
    • Maximo.
    • eProjects.
  • Experience supporting military installation cybersecurity operations and mission-essential environments.
  • Experience performing:
    • Security assessments.
    • Technical reviews.
    • Vulnerability remediation.
    • Cybersecurity risk management.
  • Strong technical writing skills with experience preparing:
    • Cybersecurity policies.
    • Procedures.
    • Implementation plans.
    • Incident response documentation.
  • Ability to manage multiple cybersecurity projects and FRCS environments simultaneously.

 

Required Certifications

Candidates must possess and maintain at least one approved commercial cybersecurity certification aligned with DoDM 8140.03 Work Role Code 461 (Systems Security Analyst), Intermediate Proficiency Level prior to onboarding.

Intermediate-Level Certifications

  • Certified Cloud Security Professional (CCSP).
  • CompTIA Cloud+.
  • Global Industrial Cyber Security Professional (GICSP).
  • GIAC Information Security Fundamentals (GISF).
  • GIAC Security Essentials Certification (GSEC).
  • CompTIA Security+.

Advanced-Level Certifications (Also Acceptable)

  • Registered Cybersecurity Career Professional (RCCE) Level 1.
  • Certified Information Systems Security Officer (CISSO).
  • CISSP Information Systems Security Engineering Professional (CISSP-ISSEP).
  • CompTIA Cybersecurity Analyst (CySA+).
  • FITSP-Operations (FITSP-O).
  • GIAC Cloud Security Automation (GCLD).
  • GIAC Certified Security Architect (GCSA).
  • GIAC Systems and Network Auditor (GSNA).

 

Certification Maintenance Requirements

  • Certifications must remain active and in good standing throughout contract performance.
  • Personnel must complete:
    • Minimum twenty (20) hours of Continuous Professional Development (CPD) annually; or
    • The minimum CPD requirement established by the certification provider, whichever is greater.

 

Operational Requirements

  • Position requires full-time on-site performance at Naval Base Guam.
  • Work schedule:
    • Up to forty (40) hours per week.
    • Monday through Friday.
    • During normal business hours.
    • Excluding Federal holidays.
  • Remote telework is not authorized except for emergency or situational circumstances approved by the COR.
  • Personnel are considered Emergency Essential and/or Mission Essential and may be required to support expanded mission conditions.
  • Participation in MAR Cyber Emergency Response Team (CERT) activities and on-call rotations may be required.
  • Local travel may be required between:
    • Naval Base Guam.
    • Marine Corps Base Camp Blaz.
    • Andersen Air Force Base.
  • Contractor personnel must provide their own transportation for local travel unless otherwise authorized.
  • Overtime is not authorized under this contract.