Internal Auditor, Enterprise Controls and Technology Assurance

Paycom - ATS

Omaha (NE)

On-site

USD 75,000 - 95,000

Full time

8 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

401(k)
401(k) match
Dental insurance
Employee assistance program
Health insurance
HSA
Life insurance
Paid time off
Vision insurance

Job summary

Detego Health in Omaha seeks an independent Internal Auditor to provide objective assurance over IT general controls, cybersecurity, and data governance within a regulated healthcare environment. This technology-first role focuses on control design, operating effectiveness, and remediation validation rather than day-to-day ownership.

You will lead risk-based audits across Microsoft 365, Azure, SaaS platforms, endpoints and core infrastructure, assess data protection (PHI) and privacy controls,

Qualifications

  • 7–12+ years in internal audit, IT audit, technology risk, or cybersecurity assurance.
  • Strong knowledge of SOC 2, HIPAA safeguards, and access governance.
  • Experience auditing cloud environments (Microsoft 365, Azure) and SaaS platforms.
  • CISA preferred; CISSP/CRISC/CIA are strong additional credentials.
  • Excellent written and executive-level communication skills.

Responsibilities

  • Lead risk-based audits of IT general controls and cybersecurity controls across defined environments.
  • Assess automated and configurable controls on core business platforms (claims, finance, HR, CRM, vendor systems).
  • Evaluate data governance and privacy controls across data lifecycle, PHI safeguards, backup integrity, and disaster recovery testing.
  • Plan, execute, and report on audits with evidence validation and remediation validation.
  • Support readiness activities for SOC 2, HIPAA, URAC and other frameworks, including pre-audit testing.

Skills

IT audit
Cybersecurity
Internal controls
Executive communication

Job description

Company OverviewDetego Health's mission is to connect real-life needs with innovative product design, delivering affordable, approachable health care benefits that feel personal, while deeply understanding our members and partners to improve lives and redefine access to health care.We're looking for passionate people who want to make a difference and help us redefine access to health care for individuals and small businesses by delivering certainty, connection and significance where others won’t.Ready to build something great together? Join a team that values growth, collaboration and the unique perspective you bring.Position SummaryDetego Health is seeking an independent and analytical Internal Auditor to provide objective assurance over enterprise technology controls and, secondarily, the operational processes that support them, within a regulated healthcare environment. This is a technology-first assurance role. Its primary mandate is the design and operating effectiveness of IT general controls, cybersecurity controls, application and system controls across Microsoft 365, Azure, SaaS platforms, endpoints, Salesforce, AI, and core infrastructure. Operational process assurance is a defined secondary scope focused on control execution rather than end-to-end business operations.The Internal Auditor provides independent assurance over control design, operating effectiveness, and remediation validation while remaining separate from day-to-day control ownership and execution. The role identifies systemic control and process breakdowns and supports continuous improvement through defensible testing, findings, and remediation validation. This is not a financial audit or general accounting audit role. Candidates should bring direct experience auditing technology controls, IT general controls, cybersecurity controls, access governance, system controls, or related technology risk areas.Key ResponsibilitiesKey ResponsibilitiesTechnology, Cybersecurity & IT ControlsLead risk-based audits of IT general controls and cybersecurity controls, including identity and privileged access, change management, logging and monitoring, incident response, endpoint/cloud security, backup and recovery, and security configuration.Evaluate control design and effectiveness across Microsoft 365, Azure, SaaS platforms, endpoints, and core infrastructure, including segregation of duties and role-based access.Application, System & Data ControlsAssess automated and configurable controls across core business platforms, including claims, finance, HR, CRM, and vendor systems.Evaluate system configurations, interfaces, data validation, reporting accuracy, and controls designed to prevent errors, unauthorized access, and inconsistent outcomes.Assess data governance and privacy controls across the data lifecycle, including safeguards for PHI and other sensitive information, backup integrity, disaster recovery testing, and remediation.Risk-Based Audit & Operational AssurancePlan and execute independent, risk-based audits using walkthroughs, control testing, sampling, data analysis, and evidence validation.Evaluate operational processes to confirm controls are appropriately designed, documented, consistently executed, and supported by sufficient evidence.Identify control deficiencies, root causes, recurring failure patterns, and risk exposure; recommend corrective actions and validate remediation through follow-up testing.Provide secondary assurance over control-related operational processes such as access reviews, change control, vendor onboarding, and regulatory complaint handling.Compliance & External Audit ReadinessSupport readiness and internal assurance activities for SOC 2, HIPAA, URAC, client audits, and future frameworks such as HITRUST.Conduct pre-audit testing, maintain defensible workpapers, identify gaps before external assessments, and validate remediation.Emerging Technology & AI GovernanceAs the function matures, evaluate governance and controls related to AI, automation, and technology-enabled decision-making, including ownership, data usage, monitoring, change management, and lifecycle controls.Assess emerging technology risks using applicable frameworks, including ISO 42001 and the NIST AI Risk Management Framework.Audit Planning, Reporting & Continuous ImprovementSupport annual risk assessments and maintain a risk-based audit plan and audit universe aligned with enterprise priorities.Track audit findings, remediation activities, and follow-up testing while identifying systemic risk trends and control maturity gaps.Prepare clear audit reports outlining risk, business impact, findings, and remediation expectations, and present results to leadership and the governing body.Qualifications7 to 12 or more years of experience in internal audit, IT audit, technology risk, or cybersecurity assurance, with the majority in IT or technology audit.Strong knowledge of internal controls, risk-based auditing, and evidence-based testing practices, with demonstrated depth in IT general controls and cybersecurity control testing.Strong working knowledge of SOC 2, HIPAA Security Rule administrative and technical safeguards, and access governance.Demonstrated ability to independently execute technology audit engagements end-to-end, including reporting and remediation validation.Strong written and executive-level communication skills.PreferredHealthcare or other regulated industry experience.Experience auditing cloud environments (Microsoft 365, Azure, SaaS platforms).Familiarity with NIST, COBIT, ISO 27001, or similar frameworks.CISA strongly preferred. CISSP, CRISC, or CIA are strong additional credentials.Compensation & BenefitsCompensation: 75,000- 95,000Work Location: Omaha-based employees will work in-office or on a hybrid schedule. We are also remote-friendly for employees located outside of the Omaha area.Benefits: 401(k), 401(k) matching, Dental insurance, Employee assistance program, Health insurance, Health savings account, Life insurance, Paid time off, Vision insuranceDetego Health is an equal opportunity employer
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior IT Controls Auditor — Healthcare & Cybersecurity
Senior IT Controls Auditor — Healthcare & Cybersecurity

Paycom - ATS • Omaha (NE)

Hybrid
USD 75,000 - 95,000
401(k)
401(k) match
Dental insurance
+6
Identity, Access, and IT Operations Specialist
Identity, Access, and IT Operations Specialist

Paycom - ATS • Omaha (NE)

Hybrid
USD 95,000 - 125,000
401(k)
Health insurance
Paid time off
+1
Enterprise Incident and Resilience Manager
Enterprise Incident and Resilience Manager

Paycom - ATS • Omaha (NE)

Hybrid
USD 65,000 - 80,000
401(k) matching
Dental insurance
Employee assistance program
+5
Paralegal I
Paralegal I

Paycom - ATS • Omaha (NE)

Hybrid
USD 65,000 - 80,000
401(k) matching
Dental insurance
Employee assistance program
+5
IT Internal Auditor - Remote
IT Internal Auditor - Remote

Crane Co. • Stamford (CT), Northern (KY)

Hybrid
USD 85,000 - 120,000
IT Internal Audit Manager
IT Internal Audit Manager

Align Technology, Inc. • Tempe (AZ)

On-site
USD 120,000 - 180,000
Senior Regulatory Filings & Licensing Specialist
Senior Regulatory Filings & Licensing Specialist

Paycom - ATS • Omaha (NE)

Hybrid
USD 90,000 - 130,000
401(k)
401(k) matching
Dental insurance
+6
Senior Auditor - IT
Senior Auditor - IT

Integra-Lifesciences • Princeton (NJ)

Hybrid
USD 120,000 - 170,000
Senior IT Auditor
Senior IT Auditor

Regional Management Corp • Greer (SC), Northern (KY)

Hybrid
USD 97,000 - 120,000
IT Audit Director
IT Audit Director

Thomas Brooke International • Cleveland (OH)

On-site
USD 100,000 - 130,000
Competitive compensation package
25% bonus target
Monthly car allowance
+2