Jobs · Maryland

Director, Audit Response & Compliance Operations

Maryland Department of Information Technology · Crownsville, MD · 2 days ago
HybridFull-time

Main Purpose

This position is the operational execution of Maryland DoIT’s enterprise audit response function, exercising day-to-day command authority over the State Audit Response Operating Model (SAROM). SAROM is DoIT’s foundational governance framework for audit response, defining the accountability model, intake standards, routing logic, escalation paths, and reporting cadence used to manage Office of Legislative Audits (OLA) requests, external audits, corrective actions, and policy attestations.

Reporting Structure

The position reports directly to the Senior Director of Compliance within the Department of Information Technology and operates as the senior operational lead for the SAROM function. The role works in close coordination with DoIT executive leadership, agency compliance liaisons, the Office of Legislative Audits, and external audit partners, and may provide functional directions to analysts, coordinators, or contractors supporting audit response activities.

Position Duties

  • Direct enterprise intake operations across email and ServiceNow, ensuring every audit request – internal, external, or legislative – is formally captured, classified, and accountable to a defined owner from the moment it enters the organization.
  • Establish and enforce service level expectations, escalation thresholds, and operational throughput standards to prevent response degradation, missed commitments, or reputational exposure.
  • Govern workflow and routing automation so requests are assigned to the correct owners on first touch and escalated when delays or risks emerge.
  • Serve as steward of the authoritative audit repository, standard templates, operating procedures, and record retention discipline, preserving evidentiary integrity and audit defensibility.
  • Lead cross-agency response coordination to deliver unified submissions, consistent messaging, and full enterprise visibility into open audit obligations and corrective actions.
  • Produce executive-level reporting on audit posture, throughput, aging, and risk trends to inform Senior Leadership and external stakeholders.
  • Drive continuous improvement of SAROM by analyzing performance data, capturing lessons learned from completed engagements, and evolving intake, routing, and escalation standards to keep pace with changing regulatory and operational demands.
  • Partner with DoIT leadership, agency liaisons, and external auditors to build trusted working relationships, clarify expectations, and resolve disputed or ambiguous findings before they escalate.

Minimum Qualifications

  • Education: Bachelor’s degree in Information Technology, Computer Science, Information Systems, Business Administration, Accounting/Finance, or a related field.
  • Experience: Three (3) years’ experience in creating and maintaining an audit/compliance program for an organization of over 100 or more employees in an information technology environment. This would include risk management and/or quality assurance.
  • Note: Candidates may substitute two additional years of qualifying experience for the degree requirement.

Preferred Qualifications

  • Experience creating and maintaining an audit/compliance program in a public sector information technology environment (county, state, or federal).
  • Hands-on experience working in a system of record that uses workflow configuration and reporting, such as ServiceNow to track audit/compliance information.

Similar jobs