Pay Range: $65–$71/hr
Duration: 18-month contract (may be extended)
Schedule: Monday–Friday, 8:00 AM–5:00 PM
Summary: Our client, a major utility company, is seeking an IT Analyst V to support both IT SOX Compliance and NERC SIP Compliance activities, with an emphasis on assessing control design, operating effectiveness, risk management, and process improvement. This person will partner closely with an equivalent compliance resource from the organization's Managed Service Provider to help manage the compliance program end-to-end. The environment is primarily SAP-based, including Segregation of Duties (SoD) controls. The ideal candidate blends technical IT knowledge with internal controls/audit expertise, operates independently, and is comfortable navigating ambiguity.
Job Responsibilities: In this role, you will manage and support internal controls and compliance activities across IT SOX and NERC SIP programs. Key responsibilities include:
- Assessing control design, operating effectiveness, and risk across IT SOX and NERC SIP compliance areas
- Partnering with the client's Managed Service Provider compliance counterpart to jointly manage the compliance program end-to-end
- Supporting SAP-based control environments, including Segregation of Duties (SoD) reviews
- Serving as lead / assessor for assigned control portfolios, including deficiency review and remediation planning
- Managing risk, audit and control matrices (RACMs) and control narratives
- Conducting stakeholder interviews, requirements gathering, and current-state/future-state process mapping
- Taking a systems-thinking, end-to-end view of processes to identify gaps and improvement opportunities
- Challenging existing processes and controls where appropriate, with a bias toward simplification and improved control efficiency
Essential Job Duties and Job Functions:
- Develop, plan, and evaluate internal audit and compliance programs to ensure adherence to organizational and regulatory standards (IT SOX, NERC SIP)
- Advise and collaborate with business, IT, MSP compliance counterparts, and leadership
- Audit information systems applications and SAP-based controls to confirm appropriate design and effectiveness
- Prepare reports, status updates, and recommendations for management and executive stakeholders
- Interface with internal and external auditors to expedite audit work
- Advise on information systems, internal controls, and security procedures, including IAM/ITGC-aligned access controls
Knowledge and Skills:
- Strong understanding of both IT environments/technologies and internal control frameworks/audit principles
- Strong written and verbal communication skills
- Ability to work independently, navigate ambiguity, and drive outcomes with a resourceful, go-getter mindset
- Systems-thinking approach with the ability to understand end-to-end processes
- Curiosity and willingness to challenge existing processes and controls when appropriate
- Background in GRC or IAM is welcomed, provided the candidate has a strong internal controls mindset (IAM controls are viewed as closely aligned with ITGCs)
- SDLC control experience is beneficial but not required
Preferred Background:
- Prior experience as an IT Auditor, Senior Auditor, IT Controls Analyst, SOX Analyst, or IT Controls/Compliance Professional
- A blend of technology and controls experience is highly desirable
- CIA and/or CISA certification preferred, but not mandatory if strong controls/audit/SOX experience is demonstrated
- Open to candidates from any industry; utility experience is beneficial but not required
Education and Experience:
Bachelor's degree preferred in business, accounting, finance, information systems, technology, engineering, or a related field; equivalent experience may be considered. 7+ years of experience.