The position is responsible for supporting the U.S. Audit Office in its mission to provide independent assessments of the Bank’s Information Technology control environment, including Information Security and other areas as assigned, in accordance with the Bank’s risk appetite and regulatory expectations.
Responsibilities
- Perform IT audits in accordance with established standards as outlined in the current Internal Audit Policies and Procedures by supporting the audit results and audit report inclusive of management action plans. In this capacity, the AVP of IT Audit is expected to assess the state of governance, risk management and internal control (GRC) processes to identify internal control gaps or weaknesses related to key IT risks.
- Directly perform all phases of the internal audit process, including control test work and documentation, or (where assigned to be the AIC) direct other USAO team members to perform audit work as well as reviewing/providing feedback to them on their work to ensure the collective IT audit work meets the expectations of our USAO function. Specifically, the position will be assigned to assess the GRC processes of the Bank's Information Technology (including Information Security) Group, including general controls, technology infrastructure (Network, DB, Servers/OS, and Data Centers), disaster recovery, applications controls, SDLC and pre and post implementation assessments of new business initiatives where Information Technology is a key component.
- Demonstrate analytical and critical thinking skills in assessing the Bank's GRC processes, inclusive of enterprise and emerging risks, for the areas assigned to audit (or perform other assurance activities of, including issues tracking and validation, continuous monitoring, auditable entity/key project/key IT application risk assessments, etc.).
- The result of the execution of the assigned IT audit activities will require a root-cause analysis of the factors that led to the identification of internal control gaps or weaknesses. The position must help report results of audit work in an effective and timely manner, leading to appropriate remedial action and ongoing management of risk.
- Be able to draft audit findings, actively and promptly discuss them with management, and provide the final product to Auditor-in-Charge (AIC) or Senior Vice President for incorporation into final audit report, inclusive of audit issue rating(s) and related recommendations, and audit report rating(s), as relevant. When presenting internal control gaps or weaknesses identified in the course of the audit activities to Bank management, be able to advise management on the adequacy, sufficiency, effectiveness and sustainability of the corrective actions (SMARTS action plans).
- Demonstrate positive influence on management to advance the internal control environment for IT through credible challenge and the identification, reporting and tracking of high impact risk issues that align with industry best practices and regulatory requirements and expectations for the areas of expertise. Therefore, an understanding of relevant regulatory expectations is essential to execute the audit engagements. As relevant, contribute with the Third Line of Defense's assessment of management's plans to respond to regulatory issues and inquiries.
- Adhere to the Internal Audit methodology in place. Minimize Quality Assurance comments (e.g., through robust and timely documentation of workpapers prior to report issuance), and address QA findings promptly.
- Based on changes in the business work environment, job responsibilities can change, and additional functions and tasks may be added or removed accordingly. Additionally, this position will perform other duties as required, and participate in special projects as deemed necessary and appropriate by Management.
Minimum Requirement and skills
Education: Bachelor's Degree
Experience: 6-8 years of relevant internal audit experience or related IT experience.
- Experience with Control assessments and testing, Operational Risk Management, SOX or Compliance testing.
- Must be versatile, able to work effectively, independently, and as part of a team.
- Outstanding verbal and written communication skills.
- Proficient in Microsoft Excel, Microsoft Word, and other Office products (advanced).
- Ability to deliver practical solutions in a demanding high-pressure environment.
- Demonstrate analytical and critical thinking skills in assessing the Bank’s GRC processes, inclusive of enterprise and emerging risks, for the areas assigned to audit (or perform other assurance activities of, including issues tracking and validation, continuous monitoring, auditable entity/key project/key business risk assessments, etc.).
The typical base pay range for this role is between $110K-$140K depending on job-related knowledge, skills, experience and location. Additionally, our Employee Benefit Program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits, 401(k) retirement and savings plan, educational assistance and training programs, paid maternity and parental bonding leave, and paid vacation, sick leave, and holidays.
Mitsubishi UFJ Trust and Banking Corporation New York Branch ("MUTB-NY") is an Equal Employment Opportunity Employer.