Job Title: Sr. Analyst - Internal Controls (IT)
Job ID: 89940
Location: Calgary, Alberta
What you will be doing:
- Provide guidance on the design and implementation of ITGCs, ITACs, and SoD controls during system implementations, upgrades, and transformation initiatives.
- Collaborate with project teams to identify key risks and recommend appropriate control activities to mitigate those risks.
- Support the integration of controls into business processes, workflows, and system configurations.
- Review proposed system designs and configurations to identify potential control gaps and compliance risks.
Controls Assessment and Validation
- Assess the design effectiveness of ITGCs, ITACs, automated controls, and SoD controls.
- Support control walkthroughs and documentation reviews to confirm controls are adequately designed and aligned to risks.
- Assist in validating control implementation prior to system go-live.
- Facilitate remediation efforts for identified control deficiencies and track progress through to resolution.
Segregation of Duties (SoD)
- Assist in the development and execution of SoD risk assessments.
- Support the review of role design, user access models, and security configurations for SoD compliance.
- Identify potential conflicting access and coordinate with stakeholders to evaluate mitigating controls.
- Support the implementation and monitoring of SoD governance processes.
Testing and Compliance Support
- Participate in ITGC, ITAC, and SoD testing activities to evaluate control operating effectiveness.
- Assist with the development of test procedures and the collection of supporting evidence.
- Support management's compliance activities related to CSOX and other regulatory requirements.
- Maintain appropriate control documentation, risk assessments, and compliance records.
- Contribute to the ongoing evolution of the organization's IT controls framework and methodology.
What you must have:
- Bachelor's degree in Information Systems, Computer Science, Accounting, Finance, Business, or a related discipline.
Relevant professional certifications are considered an asset, including:
- CISA (Certified Information Systems Auditor)
- CIA (Certified Internal Auditor)
- CPA (Chartered Professional Accountant)
- CISSP (Certified Information Systems Security Professional)
- CRISC (Certified in Risk and Information Systems Control)
- CISM (Certified Information Security Manager)
Experience
- 3 to 7 years of experience in IT controls, IT audit, SOX/CSOX compliance, risk management, cybersecurity governance, or a related field.
- Experience supporting ERP implementations or large-scale system transformation projects.
- Experience evaluating and testing ITGCs, ITACs, automated controls, and SoD controls.
- Familiarity with ERP environments such as Oracle, SAP, Workday, or other enterprise applications is preferred.