Essential Duties and Responsibilities
- Execute and support the annual IT SOX compliance program, including oversight and coordination of third-party IT SOX activities.
- Perform testing and evaluation of IT General Controls (ITGCs) and application controls, including access management, change management, system operations and other key technology controls.
- Partner with business and IT control owners to identify control gaps, communicate findings and support appropriate remediation.
- Perform IT risk assessments to support the development of the annual internal audit plan.
- Plan and execute risk-based IT audits, including scoping, testing, documentation, reporting and follow-up on remediation activities.
- Evaluate technology governance and compliance with internal policies, regulatory requirements and applicable control frameworks.
- Provide audit and controls support for new system implementations, ERP upgrades and major system changes, including evaluating risks, control design, data integrity, access, change management and implementation readiness.
- Participate in pre-implementation and post-implementation reviews to identify control or risk concerns and work with project teams to address findings.
- Identify opportunities to strengthen and scale the IT control framework as the organization continues to grow.
- Clearly communicate audit findings, risks and recommendations to IT leadership, business stakeholders and senior leadership.
- Coordinate with external auditors and other assurance partners as needed.
Qualifications
- Strong knowledge of IT SOX, ITGCs, internal controls and IT risk.
- 5+ years of IT Audit, IT Risk, IT SOX or IT Compliance experience.
- Public company and/or public accounting experience preferred.
- Experience with system implementations, ERP upgrades or major technology changes from an audit or controls perspective.
- Familiarity with frameworks such as COSO, COBIT, NIST and ISO.
- Ability to independently execute audits, identify risks and communicate findings and recommendations.
- Strong communication skills with the ability to work effectively with IT, business and senior leadership.
- Proactive, solutions-oriented and comfortable working independently in a growing organization.
- Bachelor’s degree in Accounting, Information Systems, Computer Science or related field.
- CISA, CIA or CPA preferred.
PI286975067