The Senior IT Auditor is responsible for leading and coordinating the Business Process Solutions (BPS) Division’s SOC 2 Type II readiness initiative. The position shall work closely with CSU, Operations, Technology, Human Resources, Learning & Development, Quality, Compliance, Information Security, and other process owners across the division to assess existing controls, identify compliance gaps, facilitate remediation activities, and establish an audit-ready environment.
Under the direction of the Assistant Director – CSU, the Senior IT Auditor shall serve as the subject matter expert for SOC 2 readiness activities and ensure that controls related to Security, Availability, Confidentiality, Processing Integrity, and Privacy are appropriately designed, documented, implemented, and operating effectively throughout the audit observation period.
PRIMARY DUTIES & RESPONSIBILITIES
A. SOC 2 Readiness and Compliance
- Lead the SOC 2 Type II readiness assessment for the BPS Division.
- Conduct comprehensive gap assessments against the AICPA Trust Services Criteria (TSC).
- Review existing policies, procedures, processes, controls, and system configurations to determine compliance with SOC 2 requirements.
- Evaluate control design adequacy and operating effectiveness.
- Develop, maintain, and update the SOC 2 control inventory, control matrix, and compliance framework.
- Map existing business and IT controls to applicable Trust Services Criteria.
- Assess readiness of governance, risk management, privacy, security, and compliance processes.
- Recommend improvements to strengthen control maturity and audit preparedness.
B. Audit Program Execution
- Develop detailed audit work programs, testing methodologies, and readiness procedures.
- Conduct process walkthroughs and control testing activities across BPS functions.
- Validate implementation and operation of key controls across business and support units.
- Review and assessment of IT General Controls (ITGCs), including: a. Logical access management, b. Change management, c. Incident management, d. Backup and recovery, e. Vendor management, f. Monitoring and logging controls
- Assess compliance with internal policies and established control frameworks.
- Identify control deficiencies, risks, and areas requiring remediation.
- Prepare documentation supporting audit observations, conclusions, and recommendations.
C. Documentation and Evidence Management
- Establish evidence collection requirements and audit support protocols.
- Create, organize, and maintain audit-ready documentation repositories.
- Review policies, standard operating procedures, process manuals, forms, approvals, logs, reports, and system-generated evidence.
- Ensure documentation satisfies SOC 2 Type II operating effectiveness requirements.
- Monitor completeness, accuracy, and quality of evidence during the observation period.
- Maintain a Prepared-by-Client (PBC) tracker and supporting documentation inventory.
D. Remediation Management
- Maintain a centralized remediation tracker and compliance gap log.
- Work closely with control owners and process owners to develop remediation plans and corrective actions.
- Monitor remediation activities and validate closure of identified deficiencies.
- Escalate critical issues and implementation delays to CSU leadership when necessary.
- Provide practical recommendations to strengthen governance, risk management, security, and compliance processes.
E. Stakeholder Coordination
- Partner with CSU and BPS leadership in driving audit readiness activities across the division.
- Facilitate workshops, interviews, risk assessments, and process walkthroughs.
- Coordinate with Technology, Information Security, Human Resources, Learning & Development, Operations, Compliance, and Quality teams.
- Communicate audit requirements, timelines, status updates, and expectations to stakeholders.
- Prepare executive-level reports, dashboards, and readiness presentations.
- Promote awareness of SOC 2 requirements and control ownership responsibilities.
- Serve as the primary point of contact for readiness consultants and external auditors.
- Coordinate requests for information, evidence of submission, and audit inquiries.
- Assist management in audit planning, scoping, fieldwork coordination, and issue resolution.
- Facilitate meetings between auditors and process owners.
- Support management responses to audit observations and findings.
- Assist in the preparation of final audit support packages and documentation.
G. Project Management
- Develop and maintain SOC 2 readiness project plans, milestones, and timelines.
- Monitor project progress and provide regular status updates to CSU and BPS leadership.
- Track dependencies, risks, issues, and resource requirements are associated with readiness activities.
- Ensure deliverables are completed within agreed timelines and quality standards.
- Coordinate activities across multiple stakeholders to support successful audit execution.
H. Professional Development
- Keep current developments relating to SOC 2, cybersecurity, governance, risk management, and compliance frameworks.
- Participate in relevant professional development activities and training programs.
- Share leading practices and industry insights that may strengthen the division’s audit readiness and compliance posture.
I. Relationship Management
- Foster strong working relationships with stakeholders across the BPS Division and Firm support groups.
- Maintain professionalism, objectivity, confidentiality, and independence in all audit-related activities.
- Promote collaboration and a positive working environment throughout the readiness engagement.
- Ensure that all information obtained during the engagement is handled confidentially and used only for legitimate business purposes.
J. Ad-Hoc Responsibilities
- Perform other duties and responsibilities related to the SOC 2 readiness initiative as may be assigned by the Assistant Director – CSU.
- Support additional compliance, audit readiness, governance, and risk management projects during the engagement period as required.
KEY DELIVERABLES
By the completion of the engagement, the Senior IT Auditor is expected to deliver:
- Control Inventory and Control Matrix
- Trust Services Criteria Mapping
- Evidence and Prepared-by-Client (PBC) Tracker
- External Audit Support Package
QUALIFICATIONS
Required Qualifications
- Bachelor's degree in Accountancy, Information Systems, Computer Science, Information Security, Internal Audit, or related field.
- Minimum of five (5) years of relevant experience in SOC 2 audits, internal audit, IT audit, security compliance consulting, or information security assurance engagements.
- Proven experience leading SOC 2 Type II readiness assessments and/or SOC 2 audits.
- Experience performing control testing and evaluating audit evidence.
- Strong project management and stakeholder management skills.
- Strong analytical, organizational, and problem-solving capabilities.
Preferred Certifications
One or more of the following certifications is highly preferred:
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified in Risk and Information Systems Control (CRISC)
Strong knowledge of:
- SOC 2 Trust Services Criteria (TSC)
- Risk Assessment and Control Frameworks
- NIST Cybersecurity Framework
- Information Security Governance
- Data Privacy and Protection Requirements
Experience with:
- Ticketing and Workflow Management Systems
- Audit, Governance, Risk, and Compliance (GRC) Tools
PREFERRED QUALIFICATIONS
- Strong leadership, communication, and facilitation skills.
- Excellent stakeholder management and influencing abilities.
- Strong written and verbal communication skills.
- Ability to work independently and manage multiple priorities within a fixed project timeline.
- Demonstrated professionalism, integrity, and attention to detail.
- Ability to effectively collaborate with cross-functional teams and senior leadership.
By applying, you consent to P&A Grant Thornton processing your personal data for recruitment purposes in accordance with the Data Privacy Act of 2012. Your data will be kept confidential. For any data privacy concerns or requests, you may email privacy@ph.gt.com.