We are seeking an experienced Senior IT Auditor to join our Internal Audit team and help strengthen our technology, cybersecurity, risk management, and internal control environment.
The Senior IT Auditor will plan and execute technology-focused audits, assess IT risks and controls, identify opportunities for improvement, and communicate actionable recommendations to management and senior leadership. This role will work closely with IT, Information Security, Compliance, Finance, and business stakeholders to evaluate the effectiveness of technology controls and support the organization's overall risk management objectives.
The ideal candidate is a strong communicator and critical thinker who can independently manage audit engagements while building trusted relationships across the organization.
Key Responsibilities
- Plan, lead, and execute IT audit engagements based on organizational risk assessments and the annual audit plan.
- Evaluate the design and operating effectiveness of IT general controls (ITGCs), including access management, change management, IT operations, backup/recovery, and system development controls.
- Assess cybersecurity, cloud, infrastructure, application, data, and technology-related risks and controls.
- Perform audits and risk assessments aligned with applicable frameworks, standards, and regulatory requirements.
- Review and evaluate controls related to identity and access management, privileged access, segregation of duties, vulnerability management, incident response, and data protection.
- Develop audit programs, perform testing, document workpapers, and maintain clear and well-supported audit evidence.
- Identify control gaps, assess the potential impact of findings, and develop practical, risk-based recommendations.
- Prepare audit reports and communicate findings, conclusions, and recommendations to management and senior stakeholders.
- Partner with control owners to develop remediation plans and monitor the timely resolution of audit findings.
- Support SOX, compliance, regulatory, and third-party risk initiatives as applicable.
- Leverage data analytics and technology-enabled audit techniques to improve audit efficiency and identify emerging risks.
- Stay current on evolving technology, cybersecurity threats, regulations, and industry best practices.
- Assist with special projects, investigations, risk assessments, and other advisory activities as needed.
Qualifications
- Bachelor's degree in Information Systems, Computer Science, Accounting, Finance, Cybersecurity, or a related field.
- 3+ years of experience in IT audit, technology risk, information security, internal audit, or a related field.
- Strong understanding of IT general controls and technology risk management.
- Experience auditing areas such as access management, change management, IT operations, cybersecurity, cloud environments, and application controls.
- Familiarity with frameworks and standards such as COSO, COBIT, NIST, ISO 27001, SOX, or similar.
- Strong analytical, problem-solving, documentation, and project management skills.
- Excellent written and verbal communication skills, with the ability to communicate technical issues to both technical and non-technical audiences.
- Ability to manage multiple priorities and work independently in a fast-paced environment.
- Strong attention to detail and professional judgment.