Make an impact as an IT, Security and Internal Control Audit Analyst by identifying risks, strengthening controls, and partnering with key teams to protect the organization.
IT & Security Controls Evaluation and Assurance Activities
- Support the planning and execution of IT, information security, and technology-related audits and assurance reviews.
- Assess the design and operating effectiveness of IT general controls and security controls.
- Perform testing of controls related to areas such as access management, change management, IT operations, backup and recovery, incident management, vulnerability management, and data protection.
- Review IT processes, policies, procedures, system configurations, and supporting documentation to identify control weaknesses and potential risks.
- Document testing results, observations, and supporting evidence in accordance with established internal control methodology.
- Assist in identifying control deficiencies, root causes, risk implications, and opportunities for improvement.
- Prepare clear and concise findings and recommendations for management.
- Support the tracking and validation of remediation activities and management action plans, ensuring timely and effective closure.
Risk Assessment and Monitoring:
- Perform risk assessments for new and existing systems, applications, vendors and technology processes.
- Support the development and maintenance of the risk register, ensuring risks are well-described, assessed and updated.
- Monitor key risk indicators (KRIs) and provide insights on emerging risks or trends.
- Prepare dashboards and reports highlighting risk insights for senior management.
Governance, Policies and Compliance:
- Assist in drafting, updating and reviewing IT policies, standards and procedures to align with regulatory, industry best practices and internal group policies.
- Support compliance with applicable regulatory requirements and internal governance standards.
- Contribute to periodic governance reporting and technology risk presentations.
Continuous Improvement
- Contribute to improving IT and security control frameworks, internal control methodologies, and assurance processes.
- Identify opportunities to enhance the efficiency and effectiveness of control testing and monitoring.
- Stay informed about emerging cybersecurity threats, technology risks, regulatory developments, and industry practices relevant to IT audit and security.
Education and Experience
- Bachelor’s degree in IT, Cybersecurity, Audit, Risk Management, or related discipline.
- 2–5 years of experience in IT audit, information security, controls, or cybersecurity.
- Hands‑on experience with IT control testing, risk assessments, or security evaluations.
- Good understanding of ITGC, security principles, and key areas like access, change, and vulnerability management.
- Knowledge of frameworks such as ISO 27001, COBIT, or NIST; relevant certifications (e.g., CISA, CISSP) are a plus.
Skills and Competencies
- Strong analytical, critical‑thinking, and problem‑solving abilities, with expertise in identifying control weaknesses and assessing their impact.
- Excellent attention to detail, with a solid understanding of technology, cybersecurity risks, and audit evidence.
- Effective communication skills—both written and verbal—and the ability to challenge processes constructively.
- Strong organizational and project management capabilities, capable of handling multiple activities and deadlines independently.
- High integrity, objectivity, and a proactive mindset focused on continuous improvement and stakeholder collaboration.