Seeking CISA-Certified Consultant for NIST Framework Internal Audit

Job ID: 39767998

Budget: $1,500 – $3,000 USD

I’m preparing nuXight (www.nuXight.com) for launch to the higher-education market and need a seasoned, CISA-certified professional to run our first full NIST internal audit. We are already in compliance with the NIST framework so we are not looking for a builder but an auditor. The review must also map every relevant control to HECVAT, FERPA, and GDPR so we can present a clean bill of health to university risk officers.

Scope
Our own gap-analysis work is complete; what I need now is an independent, formally documented internal audit that puts fresh eyes on the controls and ties them back to the requirements above. The emphasis is equally on NIST, HECVAT, FERPA, and GDPR, with the ultimate goal of demonstrating airtight compliance when external assessors step in.

Key focus areas (all must be covered):
• Risk assessment
• Control implementation
• Compliance verification

What you’ll deliver
1. An audit plan outlining methods, sampling, and interview schedule
2. Fieldwork and evidence collection, on-site or remote as needed
3. A final report that includes:
• Executive summary for non-technical stakeholders
• Detailed findings mapped to NIST, HECVAT, FERPA, GDPR controls
• Gap analysis with severity ratings
• Practical remediation recommendations and roadmap
4. A signed attestation letter suitable for our university clients

Acceptance criteria
• Report clearly cross-references each finding to the specific control set(s) affected.
• All raw evidence is made available for spot checks.
• Recommendations are prioritized by risk and effort.
• Delivery meets the agreed timeline.

Requirements to be considered
• Current CISA certification (please attach proof).
• A redacted sample of a past NIST internal audit that also touched HECVAT, FERPA, or GDPR.
• Brief outline of your methodology and estimated schedule.

If this aligns with your expertise, I look forward to reviewing your proposal.