***Note: This position is open to applicants based in the Philippines only.
(Internal Position Title: Senior Technology Risk Compliance (ITGC) (IT Audit & Compliance))
JOB SCOPE
Provide services to AGO’s clients, whether assurance or advisory in nature, designed to strengthen internal controls and help improve IT and business performance. Client engagements may include IT SOX, IT Internal Audits, Service Organization Controls (SOC) related engagements.
Internally, will assist in IT strategic internal initiatives that may cover IT operations, security, and compliance. It may include executing IT security and operational assessment using industry standards and frameworks, and data security and privacy regulations.
ESSENTIAL JOB FUNCTIONS
To perform this job successfully, an individual must be able to perform each essential function satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- Performs advanced bookkeeping and accounting tasks
- Performs clerical accounting procedures requiring familiarity with, and experience in, accounting office practices as well as knowledge of a variety of accounting classifications
- Perform account reconciliations
- Prepare journal entries
- Review and prepare client’s vendor invoices for payment
- Prepare monthly billings for clients
- Investigate general ledger balance discrepancies
- Assist or run and package monthly, quarterly and annual financial reports for client
- As requested by client, perform other tasked as outlined in the "agreed upon procedures" engagement or other special projects as needed that falls within the scope of capabilities.
- Maintain confidentiality of all materials related to performing all job task
- Provide high quality client service, working directly with onshore and/or client teams to understand and evaluate client’s IT environment and controls.
- Perform efficient execution of controls testing related to Information Technology General Controls (ITGC), Application Controls, and IT security controls.
- Assist in maintaining risk, threat and controls inventory as aligned with globally accepted standards or frameworks.
- Execute IT infrastructure configuration reviews based on best practices and accepted benchmarks.
- Oversee the validation of risk assessments, process and technology control designs, control gap identification, test scripts and evidence and identification of compensating controls.
- Manage IT remediation process including tracking and resolutions of findings from internal and/or external audit findings, risk assessments, self-reported items, and other control assessments.
- Ensure that appropriate remediation plans are developed to appropriately mitigate vulnerabilities and defects in a timely manner to reduce risk to systems and information. Where potential system weaknesses are identified, partner with other team members within Information Security, IT and business units to implement compensating controls.
- Other duties as assigned
QUALIFICATIONS
Skills and Working Experience
- At least 3 years of experience related to audits/reviews of IT General Controls across different platforms (Application, Operating System, Database) related to the following:
- User Access Management
- Backup and Recovery Management
- Batch Job Management
- System development/acquisition, migration, and implementation.
- IT Applications/Automated Controls related to business processes such Procure to Pay, Order to Cash, Inventory, Payroll, Treasury, Record to Report, etc.
- With exposure with any of engagements related to IT SOX, IT Interna l Audit, Service Organization Controls (SOX), Information Security Review, and/or Cloud Security review/testing.
- Certifications related to CISA, CISM, CRISC, and CIA is an advantage
- Ability to effectively work and collaborate on a work from home environment.
- Ability to understand and interpret IT industry frameworks and regulations such as ITIL, NIST 800-53, ISO 27002, CIS, OWASP, COBIT, HIPAA, Data Privacy Act 2012.
- With a qualitative trait of being accountable, proactive problem solving, and proven ability to adapt and learn in an innovative environment.
- Excellent project management, teamwork, and client service skills.
- Excellent presentation, written and oral communication skills.
TECHNICAL AND OTHER SKILLS:
- Intermediate knowledge of Microsoft Office - Required
- Ability to read and follow instructions and directions from supervisors or clients. Ability to read and follow workflow or process manuals.
- Strong time management and organizational skills – Required
- Attention to detail and accuracy – Required