Job Summary
The Assurance Experienced Manager, Third Party Attestation is responsible for leading a team of audit professionals in the planning, fieldwork, and wrap‑up phases of third‑party attestation reports. This role focuses on various types of reports including System and Organization Controls (SOC) 1, SOC 2, SOC 3, SOC for Cybersecurity, WebTrust for CAs, HITRUST, SSPA, ISO, MRC, and CSA STAR. The manager ensures compliance with relevant governing standards and regulations while documenting, validating, testing, and assessing control systems, including internal controls. The team specializes in these specific areas of third‑party attestation reports to understand the entire technology risk umbrella rather than maintaining overall knowledge in Information Technology General Control (ITGC) audit or IT audit.
Responsibilities
- Control Environment
- Apply knowledge and understanding of governing principles and document how they are applied in engagements.
- Identify and consider all applicable policies, laws, rules, and regulations of the firm, regulators, or other authoritative bodies as part of the engagement team.
- Apply a broad understanding of objectives and components of the overall control environment, organization and supervisory controls.
- Oversee planning and execution of attestation examinations, including obtaining an understanding of the control environment, designing test plans, evaluating deficiencies, and assessing the overall control environment.
- Identify and prioritize key risks and assess their impact and likelihood of occurrence.
- Oversee documenting and validating the operating effectiveness of the client’s internal control system.
- Oversee documenting business and IT processes and controls and test key controls for service organizations in a variety of industries.
- Review client attestation reports, ensuring accuracy, completeness, and that all supporting information is documented in the work papers through appropriate testing.
- Identify, analyze and discuss alternative principles with engagement leadership and the client, as needed.
- Engagement Management
- Serve as primary client contact for all questions and issues.
- Develop and maintain relationships with client personnel and management.
- Supervise the work of the engagement team and review workpapers and conclusions, preferably onsite, during fieldwork.
- Identify and delegate functions of the engagement to the auditor in charge, as deemed appropriate.
- Provide on‑the‑job training to less experienced team members.
- Identify complex issues and bring them to a resolution with client and leadership.
- Communicate suggestions to improve client internal controls and procedures to management and/or audit committee.
- Draft attestation reports and effectively communicate contents to client.
- Recognize and apply new pronouncements to client situations.
- Ensure technology is appropriately integrated into the examination process.
- Methodology
- Apply BDO standards to guide effective and efficient delivery of quality services.
- Ensure completion of all appropriate documentation in BDO workpapers.
- Conduct a detailed review to assure the audit is completed in accordance with assurance manual standards.
- Prepare and/or review required communications to management and audit committees, ensuring timeliness and completeness.
- Recommend appropriate outcomes to critical issues.
- Initiate and prepare client acceptance/retention procedures, where appropriate.
- Plan the audit process and oversee execution of procedures with quality, efficiency, and completeness despite deadlines.
- Execute proper BDO methodology, including proper archiving procedures.
- Ensure all work is performed in accordance with BDO methodology and requirements.
- Research
- Use methodology to seek or maintain information from authoritative sources and draw conclusions regarding target issues.
- Research complex topics and form an opinion on the treatment independently.
- Apply comprehensive knowledge of all appropriate research tools and draw conclusions based on appropriate research.
- Prepare memos supporting research and conclusions, and consult with others, if appropriate.
- Present issues to technical reviewers effectively and accurately.
- Supervisory Responsibilities
- Oversee supervision of Associates and Senior Associates on all projects.
- Schedule and manage the workload of Associates and Senior Associates.
- Review work prepared by Associates and Senior Associates and provide review comments.
- Provide verbal and written performance feedback to Associates and Senior Associates.
- Provide on‑the‑job learning to Associates and Senior Associates.
- Act as a career advisor to Associates and Senior Associates.
Qualifications
- Bachelor’s degree in Accounting, Computer Science, Management Information Systems, Business Administration, Managerial Marketing and Entrepreneurship, Finance, or Economics (required).
- Master’s degree in Accounting and a minor or dual major in Information Systems or another relevant advanced degree (preferred).
Experience
- Six (6) or more years of prior experience in internal or external audit (required).
- Supervisory experience (required).
- Experience performing SOC, SOX, or ISO 27001 engagements (preferred).
License/Certifications
- Certified Public Accountant (CPA)
- Certified Information Systems Auditor (CISA)
- Certified Information Systems Security Professional (CISSP)
- ISO 27001 Lead Auditor certification
- HITRUST Certified Common Security Framework Professional (CCSFP)
- Certified Internal Auditor (CIA)
- Certified Information Security Manager (CISM)
- Certified Ethical Hacker (CEH)
- Certified in Risk and Information Systems Control (CRISC)
- Certified in the Governance of Enterprise IT (CGEIT)
Software
- Proficient in Microsoft Office Suite – Word, Excel, and PowerPoint (preferred).
- Prior experience with various assurance applications (e.g., UNIX, OS400, LINUX) and databases (e.g., Oracle, SQL) and assurance research tools (preferred).
Other Knowledge, Skills & Abilities
- Excellent understanding and experience planning and coordinating the stages to perform an audit of a public and/or private company.
- Strong knowledge of internal accounting controls and professional standards and regulations (e.g., GAAP, GAAS, Sarbanes‑Oxley).
- Strong analytical and diagnostic skills with the ability to break down complex issues and implement appropriate resolutions.
- Ability to successfully multi‑task while working independently and within a group environment.
- Ability to work in a demanding, deadline‑driven environment with a focus on details and accuracy.
- Strong project management skills with the ability to manage multiple projects simultaneously.
- Able to effectively manage a team and delegate work assignments.
- Ability to encourage a team environment on engagements and contribute to the professional development of assigned personnel.
- Build and maintain strong relationships with client personnel.
- Executive presence and ability to act as primary contact on assigned engagements.
- Strong verbal and written communication skills with the ability to adapt style and messaging to effectively communicate with professionals at all levels both inside the client organization and the firm.
- Ability to travel as necessary.
Compensation
California: $130,000 - $170,000
Colorado: $115,000 - $150,000
Massachusetts: $110,000 - $140,000
NYC/Long Island/Westchester: $125,000 - $155,000
Washington: $130,000 - $150,000
Equal Employment Opportunity
Equal Opportunity Employer, including disability/vets.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability or protected veteran status. BDO USA, P.A. is an EO employer M/F/Veteran/Disability.