Our client, a privately owned FANG, provides innovative financial services and guidance to corporations, institutions and affluent families and individuals globally. With 130 years of financial experience and nearly 20,000 partners, they serve the world’s most sophisticated clients using leading technology and exceptional service.
- 2018 top employer for Diversity
- Average employee tenure is around 20 years (people love working here and don't leave)!
- Emphasis on a work / life balance
- Even though our client was heavily impacted by COVID 19, they did not layoff a single employee!
- Employees were given a small lump sum payout to help with COVID 19 struggles
- Juneteenth is a recognized company Holiday
The Senior IT Auditor I- Cyber is responsible for conducting and documenting audits throughout the Corporation. This role leads audit project teams, which includes providing oversight to the audit team and communicating results of the engagement to management. The Senior IT Auditor I provides technical expertise and training to auditors within the engagement audit team and works closely with Audit Managers to confirm the scope of the audit and to devise an appropriate testing approach to be performed during the engagement.
Leadership and Management
• Establishes and develop strong working relationships and open communication with key stakeholders
• Provides training, coaching, and auditing expertise to the audit team
• Accountable for own assignments and holding others accountable for theirs including proactively managing expectations
• Identify risk and controls within processes, and provide risk assessment
• Lead internal audit projects related to IT general controls, information security/cyber, pre/post system implementation, IT governance, and operational areas; drive consistency of methodology
• Assists with the development of the audit budget and/or timeframe for how the audit will be completed based on the objective and risk of the areas covered within the engagement
• Finalizes planning documents and conducts first level review of planning documents as required
• Coordinates with other audit teams (business unit, regional, and specialist) to ensure evaluations of related areas occur timely and cover key areas within the audit
• Demonstrates professional skepticism and comfort with questioning how certain processes are being performed in order to facilitate making improvements
• Applies analytical skills to review information, perform assessments of the audit results, and evaluate the adequacy of controls
• Reviews the work papers of the audit team members ensuring that departmental standards have been met
• Communicates the audit status to business unit stakeholders and Audit Services management
• Drafts findings and recommendations for the purpose of status updates, memos, and audit reports
• Maintain technical competence by ongoing training, seeking development opportunities and applying new knowledge to daily work assignments
How this position fits in the organization:
This position is on the IT Audit team which is one domain under the Corporate Services Audit practice
What are the non-negotiable requirements on this position?
4-6 years of experience. Must have an IT Audit background--area of focus is now on cyber--things like cloud, Penetration Testing , Cyber and Privacy regulations, - Data Loss Prevention, Information Security. they can have other IT audits, but CYBER IS KEY! Must be able to own complex audits including planning, scope, oversight, reporting, etc. We DO NOT want SOX IT people.
What are the nice-to-have skills?
Big4 Audit experience is HIGHLY desired
What is exciting about this opportunity?
Works on high profile projects with the company, access to leadership, group recognizes strong performers and will promote
• Minimum of 4-5 years of IT auditing and systems experience with a focus on information security and cyber security controls (e.g., NIST Cyber Security Framework controls)
• Solid knowledge of audit procedures and technical security and control standards usually obtained through related work experience and a four year degree program is required to perform system audits
• Solid understanding of Information Technology General Controls (ITGC) and non-ITGCs (e.g., Configuration Management, Vendor Management)
• Solid understanding of Information Technology Service Management (ITSM) controls (e.g., Incident Management, Problem Management)
• Skills as needed to perform testing of design and operational effectiveness of application controls (e.g., Interface Controls)
• Knowledge of the operations, functions, and objectives of interfacing areas is required to properly audit operations, services, systems, workflow, and operational impact on other areas
• Operates independently; has in-depth knowledge of business unit/function
• Knowledge of systems software applications and databases common to the mainframe and distributed environments, such as UNIX, iSeries, and Windows is a plus
• Understanding of networks, routers, and firewalls is also a plus
• Certified Information System Audit (CISA) certification is preferred. Additional certifications such as Certified Information Systems Security Professional (CISSP), or other related certifications is a plus
• Strong people management and leadership skills
• Self-starter with an ability to self-motivate
• Strong leadership and organizational skills are required
• Excellent verbal and written communication skills
• Highly numerate with strong organizational and problem solving skills with attention to detail
• Ability to proactively assess issues, identify solutions and problem solve
• Ability to react and respond on a timely basis
• Ability to adapt and react positively in a changing and dynamic work environment
• Ability to work under pressure and to deliver to tight deadlines
• Ability to develop relationships with diverse groups and various levels of technology and non-technology personnel
• Flexibility, multi-tasking, creative thinking, good business judgment skills are required to meet strict deadlines and manage other projects
• Proficiency in Data Analytics a plus
• Proficiency in Word and Excel a plus
• Must be a team player and able to work under pressure during peak periods