IT Auditor Jobs in USA with Visa Sponsorship
IT Auditors evaluating controls, systems, and compliance frameworks are regularly sponsored for H-1B visas by banks, consulting firms, and healthcare organizations. The role qualifies as a specialty occupation, and employer demand consistently outpaces available talent. For detailed occupation requirements, see the O*NET profile.
See All IT Auditor JobsOverview
Showing 5 of 63+ IT Auditor jobs


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?
See all 63+ IT Auditor jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new IT Auditor roles.
Get Access To All Jobs
INTRODUCTION
Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.
ROLE AND RESPONSIBILITIES
The Info Security Risk Auditor is responsible for supporting and enforcing information security policies, standards, and procedures to safeguard proprietary, personal, and privileged electronic data. This role works closely with user departments and cross-functional teams to implement robust security controls, drive compliance, and foster a culture of security awareness.
Primary Responsibilities:
- Risk & Governance
- Align security policies and standards with IT infrastructure frameworks (ISO 27001, NIST, ITIL)
- Lead policy exception and risk management, including logging, assessment, and mitigation
- Conduct vendor tier assessments, clarify tiering logic, and ensure correct application of security reviews
- Oversee remediation of critical/high vulnerabilities, verify aging data, and confirm with SLOs on unresolved exploits
-
Support overall application security governance
-
Compliance & Certification
- Ensure compliance with regulatory requirements (ISO 27001, NYDFS, NIST)
- Lead and support ISO 27001/ISMS program implementation and audits for assigned geographies/scope
- Maintain and update compliance trackers, dashboards, and reporting frameworks
- Perform audits to identify control gaps and implement corrective action plans
- Monitor compliance with corrective actions and address non-compliance issues
-
Review and attest security attributes for applications, including MFA, orientation, data type, and access provisioning
-
Incident Management & Investigation
- Facilitate and lead security incident investigations, including physical security, fire safety, access control, and environmental controls
- Ensure proper logging and escalation of incidents
-
Coordinate with other teams for incident related activities
-
Security Awareness & Training
- Drive security awareness campaigns, training, and infographics for employees and contractors
- Track and report on training completion rates, phishing metrics, and awareness initiatives
-
Develop and communicate security content, including videos and best practices
-
Stakeholder Engagement & Communication
- Communicate professionally with stakeholders and end users through multiple channels
- Collaborate with business, and other concerned teams for regulatory reporting and audit support
-
Provide consulting and support for customer audits, contract reviews, and acquired entity compliance
-
Physical Security & Site Compliance
- Conduct physical compliance walks, assess fire safety, access control, secure printing, and data privacy at sites
ENGLISH PROFICIENCY ASSESSMENT WILL BE REQUIRED AFTER APPLICATION
You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in.
REQUIRED QUALIFICATIONS:
- 8+ years of information security experience
- Experience with ISO27001 (ISMS), HITRUST CSF, NIST Cybersecurity Framework, SOC Type1/2
- Professional proficiency both with English and Spanish
- Proven auditing skills and ability to manage risk assessments/projects independently
- Proven excellent verbal and written communication skills
- Proven solid presentation skills, especially the ability to explain technology to non-technical personnel
- Demonstrated ability to work independently, meet deadlines, and maintain stakeholder confidence
PREFERRED QUALIFICATIONS:
- Certifications: CISSP, CISA, ISO27001 Lead Implementer or Lead Auditor
- Experience in physical security, compliance walks, and site-level assessments
At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone - of every race, gender, sexuality, age, location and income - deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.
UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations.
UnitedHealth Group is a drug-free workplace. Candidates are required to pass a drug test before beginning employment.

INTRODUCTION
Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.
ROLE AND RESPONSIBILITIES
The Info Security Risk Auditor is responsible for supporting and enforcing information security policies, standards, and procedures to safeguard proprietary, personal, and privileged electronic data. This role works closely with user departments and cross-functional teams to implement robust security controls, drive compliance, and foster a culture of security awareness.
Primary Responsibilities:
- Risk & Governance
- Align security policies and standards with IT infrastructure frameworks (ISO 27001, NIST, ITIL)
- Lead policy exception and risk management, including logging, assessment, and mitigation
- Conduct vendor tier assessments, clarify tiering logic, and ensure correct application of security reviews
- Oversee remediation of critical/high vulnerabilities, verify aging data, and confirm with SLOs on unresolved exploits
-
Support overall application security governance
-
Compliance & Certification
- Ensure compliance with regulatory requirements (ISO 27001, NYDFS, NIST)
- Lead and support ISO 27001/ISMS program implementation and audits for assigned geographies/scope
- Maintain and update compliance trackers, dashboards, and reporting frameworks
- Perform audits to identify control gaps and implement corrective action plans
- Monitor compliance with corrective actions and address non-compliance issues
-
Review and attest security attributes for applications, including MFA, orientation, data type, and access provisioning
-
Incident Management & Investigation
- Facilitate and lead security incident investigations, including physical security, fire safety, access control, and environmental controls
- Ensure proper logging and escalation of incidents
-
Coordinate with other teams for incident related activities
-
Security Awareness & Training
- Drive security awareness campaigns, training, and infographics for employees and contractors
- Track and report on training completion rates, phishing metrics, and awareness initiatives
-
Develop and communicate security content, including videos and best practices
-
Stakeholder Engagement & Communication
- Communicate professionally with stakeholders and end users through multiple channels
- Collaborate with business, and other concerned teams for regulatory reporting and audit support
-
Provide consulting and support for customer audits, contract reviews, and acquired entity compliance
-
Physical Security & Site Compliance
- Conduct physical compliance walks, assess fire safety, access control, secure printing, and data privacy at sites
ENGLISH PROFICIENCY ASSESSMENT WILL BE REQUIRED AFTER APPLICATION
You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in.
REQUIRED QUALIFICATIONS:
- 8+ years of information security experience
- Experience with ISO27001 (ISMS), HITRUST CSF, NIST Cybersecurity Framework, SOC Type1/2
- Professional proficiency both with English and Spanish
- Proven auditing skills and ability to manage risk assessments/projects independently
- Proven excellent verbal and written communication skills
- Proven solid presentation skills, especially the ability to explain technology to non-technical personnel
- Demonstrated ability to work independently, meet deadlines, and maintain stakeholder confidence
PREFERRED QUALIFICATIONS:
- Certifications: CISSP, CISA, ISO27001 Lead Implementer or Lead Auditor
- Experience in physical security, compliance walks, and site-level assessments
At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone - of every race, gender, sexuality, age, location and income - deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.
UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations.
UnitedHealth Group is a drug-free workplace. Candidates are required to pass a drug test before beginning employment.
How to Get Visa Sponsorship as an IT Auditor
Lead with your technical certifications
CISA, CISSP, and CISM credentials signal to sponsoring employers that you meet specialty occupation standards. Listing them prominently on your resume strengthens both your application and the employer's H-1B petition.
Target regulated industries first
Banks, healthcare systems, and federal contractors face mandatory audit requirements and hire IT Auditors year-round. These employers have established immigration programs and are far more likely to sponsor than startups or small firms.
Frame your degree field precisely
USCIS expects a direct connection between your degree and the role. Information Systems, Computer Science, Accounting Information Systems, and Cybersecurity degrees map most cleanly to IT Auditor specialty occupation petitions.
Understand the LCA before you negotiate
Your employer files a Labor Condition Application certifying your wage meets prevailing levels for IT Auditors in your work location. Knowing this protects you from underpay and helps you evaluate offers accurately.
Ask about cap-exempt employers
Nonprofits, universities, and government-affiliated research organizations are exempt from the H-1B lottery. IT Auditors at these institutions can receive approval year-round without competing in the annual cap selection.
Address the specialty occupation question directly
Some USCIS officers scrutinize IT Auditor petitions. Having your employer document that the role requires a specific bachelor's degree, not just any degree, significantly reduces the risk of a Request for Evidence.
IT Auditor jobs are hiring across the US. Find yours.
Find IT Auditor JobsSee all 63+ IT Auditor jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new IT Auditor roles.
Get Access To All JobsFrequently Asked Questions
Does IT Auditor qualify as a specialty occupation for H-1B purposes?
Yes, but the petition needs to be drafted carefully. USCIS requires the employer to demonstrate that the role normally requires a bachelor's degree in a specific field, such as Information Systems, Accounting Information Systems, or Computer Science. Generic job descriptions referencing any business degree can trigger a Request for Evidence. Employers with detailed, technical job postings have significantly stronger approval records for this role.
What degree do I need to get sponsored as an IT Auditor?
A bachelor's degree in Information Systems, Computer Science, Cybersecurity, or Accounting Information Systems is the strongest foundation for a sponsored IT Auditor role. Degrees in general Business or Finance can work if paired with certifications like CISA or relevant coursework, but they introduce more risk in the USCIS adjudication. A three-year Australian bachelor's degree is generally accepted as equivalent to a U.S. four-year degree for H-1B and E-3 petitions.
Which employers sponsor IT Auditors most frequently?
Large financial institutions, Big Four accounting firms, healthcare networks, and federal government contractors are the most consistent sponsors for IT Auditor roles. These organizations operate under strict regulatory audit requirements, creating sustained demand regardless of hiring cycles. You can browse IT Auditor roles with confirmed sponsorship directly on Migrate Mate, which filters specifically for employers willing to support visa applications.
Can I transfer my H-1B to a new employer if I'm already an IT Auditor in the U.S.?
Yes. H-1B portability allows you to transfer to a new sponsoring employer once your initial petition has been approved and you have maintained valid status. Your new employer files a transfer petition, and you can typically begin work as soon as it is received by USCIS. There is no need to restart the lottery. The new role must still qualify as a specialty occupation under the same standards as your original petition.
Are IT Auditor H-1B petitions at higher risk of denial than other tech roles?
They face more scrutiny than core software engineering roles because USCIS sometimes questions whether audit positions require a degree in a specific field versus a general business background. Approval rates improve significantly when the job description ties responsibilities directly to technical systems, controls frameworks, or cybersecurity, and when the employer documents the degree requirement clearly. Firms with experienced immigration counsel and established sponsorship histories tend to have stronger outcomes.
What is the prevailing wage requirement for sponsored IT Auditor jobs?
U.S. employers sponsoring a visa must pay at least the prevailing wage, which is what workers in the same role, area, and experience level typically earn. The Department of Labor sets this rate to make sure companies aren't hiring foreign workers simply because they'd accept lower pay than a U.S. worker. It varies by job title, location, and experience. You can look up current prevailing wage rates for any occupation and location using the OFLC Wage Search page.
See which IT Auditor employers are hiring and sponsoring visas right now.
Search IT Auditor Jobs