Assurance Experienced Associate, Third Party Attestation

BDO USA, LLP

Torch of Friendship (FL)

On-site

USD 70,000 - 90,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

BDO USA, LLP is seeking an Assurance Experienced Associate, Third Party Attestation to prepare SOC 1/2/3 reports, SOC for Cybersecurity and other attestation services. The role involves documenting, validating, testing, and assessing client internal controls across various industries, with emphasis on IT controls and governance.

The position requires understanding of professional standards (SOC, ISO, HITRUST, SOX) and the ability to communicate findings, develop relationships with clients, and

Qualifications

  • Bachelor's degree in Accounting or related field is required.
  • 1+ years of IT/IT audit experience required.
  • Experience with SOC, WebTrust, HITRUST, SOX, ISO 27001 and security/privacy engagements preferred.
  • Professional certifications (CPA, CISA, CISSP, CIA, CISM, CRISC, CGEIT) preferred.

Responsibilities

  • Prepare third-party attestation reports (SOC 1, SOC 2, SOC 3).
  • Document, validate, test and assess client control systems.
  • Identify and communicate control improvements to clients.
  • Support IT risk assessments and ensure tech integration in examinations.

Skills

Verbal and written communication
Analytical and diagnostic skills
Project management
Multi-tasking
Travel willingness
Data analytics awareness

Education

Bachelor's degree in Accounting/IT/MIS/Business/Finance/Economics
Master's degree in Accounting (preferred)

Tools

Microsoft Office (Word, Excel, PowerPoint)
ERP systems
Databases (Oracle, SQL)
UNIX/Windows operating systems

Job description

Job Summary:

The Assurance Experienced Associate, Third Party Attestation will be responsible for the preparation of third-party attestation reports, including System and Organization Controls (SOC) 1, SOC 2, SOC 3, SOC for Cybersecurity and WebTrust for CAs, as well as HITRUST, SSPA, ISO, MRC and CSA STAR applying most areas of the governing standard as necessary and documenting, validating, testing, and assessing various control systems, including internal controls. Our TPA individuals specialize in thesespecific areas to understand the entire technology risk umbrella rather thanmaintaining overall knowledge in Information TechnologyGeneralControl (ITGC)audit or IT audit.

Job Duties:
Control Environment:
  • Applies knowledge and understanding of the collective effect of various factors on establishing or enhancing effectiveness, or mitigating the risks, of specific policies and procedures by:
    • Identifying and considering all applicable policies, laws, rules, and regulations of the firm, regulators, or other authoritative bodies as part of engagement team
    • Making constructive suggestions to improve client internal control procedures
    • Documenting and validating the operating effectiveness of the clients' internal control system
    • Documenting business and IT processes and controls and tests key controls for service organizations in a variety of industries
    • Identifying and prioritizing key risks, and assesses their impact and likeliness of occurrence;
    • Communicating to the client areas to improve processes, strengthen controls, mitigate risks, and/or increase efficiency
    • Developing and maintaining relationships with client personnel and management
    • Ensuring technology is appropriately integrated into the examination process
GAAS:
  • Applies knowledge and understanding of professional standards; application of the principles contained in professional standards; and the ability to document and communicate an understanding and application of professional standards on an engagement by:
    • Developing and applying an intermediate knowledge of auditing theory, a sense of audit skepticism, and the use of BDO audit manuals
    • Applying auditing theory to various client situations
    • Documenting working papers and attestation reports in line with BDO policy, identifying deviations and notifying more senior team members in order to obtain appropriate approvals
    • Applying knowledge to identify instances where testing may be reduced or expanded and notifying more senior team members of the occurrence
    • Contributing ideas and opinions to the engagement team
Methodology:
  • Applies knowledge and application of BDO standards to guide effective and efficient delivery of quality services and products by:
    • Completing all appropriate documentation of BDO work papers
    • Ensuring assigned work is performed in accordance with BDO methodology and requirements
Research:
  • Applies methodology used to seek or maintain information from authoritative sources and to draw conclusions regarding a target issue based on the information by:
    • Researching basic and intermediate topics and forming an initial opinion on the treatment independently
Training:
  • Attend professional development and training sessions on a regular basis
  • Complete required CPE hours to maintain applicable certifications
  • Other duties as required
Qualifications, Knowledge, Skills and Abilities:
Education:
  • Bachelor's degree in Accounting, Computer Science, Management Information Systems, Business Administration, Managerial Marketing and Entrepreneurship, Finance or Economics, required
  • Master's degree in Accounting and minor or dual major in Information Systems or other advanced degree, preferred
Experience:
  • One (1) or more years of prior experience in IT, internal or external audit or relevant industry experience, required
  • Experience performing internal control reviews, preferred
  • Experience performing SOC, WebTrust, HITRUST, SOX, ISO 27001 and security/privacy advisory engagements, preferred
  • Relevant experience-based internship, preferred
License/Certifications:
  • One or more of the following certifications are preferred:
  • Certified Public Accountant (CPA)
  • Certified Information Systems Auditor (CISA)
  • Certified Information Systems Security Professional (CISSP)
  • ISO 27001 Lead Auditor certification
  • HITRUST Certified Common Security Framework Professional (CCSFP)
  • Certified Internal Auditor (CIA)
  • Certified Information Security Manager (CISM)
  • Certified Ethical Hacker (C | EH)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified in the Governance of Enterprise IT (CGEIT)
Software:
  • Proficiency in Microsoft Office Suite, specifically Word, Excel and PowerPoint, required
  • Prior experience with various applications (e.g., ERP systems), operating systems (e.g., UNIX, Windows); and databases (e.g., Oracle, SQL), preferred
  • Exposure to cloud platforms, SaaS applications, security and engineering tools, and other industry software, preferred
Other Knowledge, Skills & Abilities:
  • Basic understanding and experience planning and coordinating the stages to perform technology-focused audits and assessments
  • Knowledge of internal controls and professional standards and regulations (SOC, ISO, WebTrust, HITRUST, Sarbanes-Oxley, etc.)
  • Knowledge of data analytics and emerging technologies beneficial
  • Strong verbal and written communication skills with the ability to adapt style and messaging to effectively communicate and interact with professionals at all levels both within the client organization and the firm
  • Ability to successfully multi-task while working independently and within a group environment
  • Solid analytical and diagnostic skills and ability to break down complex issues and implementing appropriate resolutions
  • Able to work in a demanding, deadline driven environment with a focus on details and accuracy
  • Solid project management skills
  • Ability to travel as necessary

Individual salaries that are offered to a candidate are determined after consideration of numerous factors including but not limited to the candidate's qualifications, experience, skills, and geography.

California Range: $79,000 - $90,000
Colorado Range: $74,000 - $80,000
Illinois Range: $75,000 - $80,000
Massachusetts Range: $75,000 - $80,000
Minnesota Range: $70,000 - $80,000
NYC/Long Island/Westchester Range: $75,000 - $80,000

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Assurance Senior, Third Party Attestation
Assurance Senior, Third Party Attestation

BDO USA, LLP • San Francisco (CA)

On-site
USD 85,000 - 125,000
Assurance Experienced Senior, Third Party Attestation
Assurance Experienced Senior, Third Party Attestation

BDO USA, LLP • Chicago (IL)

On-site
USD 80,000 - 109,000
Assurance Experienced Senior
Assurance Experienced Senior

BDO USA, Llp • Troy (MI), Northern (KY)

Hybrid
USD 85,000 - 130,000
Assurance Associate, Third Party Attestation - Summer 2027 (Dallas)
Assurance Associate, Third Party Attestation - Summer 2027 (Dallas)

BDO USA, LLP • Dallas (TX)

On-site
USD 85,000 - 110,000
Assurance Associate, Third Party Attestation - Summer 2027 (Minneapolis)
Assurance Associate, Third Party Attestation - Summer 2027 (Minneapolis)

BDO USA, LLP • Minneapolis (MN)

On-site
USD 70,000 - 74,000
Assurance Associate Third Party Attestation Summer 2027 Minneapolis
Assurance Associate Third Party Attestation Summer 2027 Minneapolis

BDO USA, PC • Minneapolis (MN)

On-site
USD 70,000 - 74,000
Assurance Experienced Manager, Third Party Attestation
Assurance Experienced Manager, Third Party Attestation

BDO USA • Boston (MA)

On-site
USD 110,000 - 140,000
Assurance Associate, Third Party Attestation - Summer 2027 (Minneapolis)
Assurance Associate, Third Party Attestation - Summer 2027 (Minneapolis)

BDO USA • Minneapolis (MN)

On-site
USD 70,000 - 74,000
ESOP ownership
Total Rewards benefits
Assurance Associate, Third Party Attestation – Summer 2027 (Dallas)
Assurance Associate, Third Party Attestation – Summer 2027 (Dallas)

BDO USA • Dallas (TX)

On-site
USD 80,000 - 90,000
ESOP
Total Rewards benefits
Assurance Experienced Senior
Assurance Experienced Senior

BDO USA • Grand Rapids (MI)

On-site
USD 100,000 - 140,000
ESOP