IT Audit & Controls Analyst
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
IT Audit & Controls Analyst (ITGC/SOX): Executing IT General Controls testing and supporting technology risk, cybersecurity maturity, and SOX assessments with an accent on control evidence, operating effectiveness, and audit-ready documentation. Focus on identifying control deficiencies, validating remediation, and analyzing security risks across applications, systems, and technology processes.
Location: Fully remote within the United States
Company
is a technology and professional services firm specializing in innovative technologies and nationwide technology management services.
What you will do
- Execute IT General Controls testing across applications, systems, and technology processes.
- Evaluate control design and operating effectiveness, including evidence collection and validation.
- Prepare audit-ready workpapers documenting procedures, evidence, results, and conclusions.
- Identify control gaps and deficiencies, escalate issues, and perform remediation validation testing.
- Support technology risk assessments, cybersecurity maturity assessments, and IT SOX testing.
- Maintain testing trackers and report control effectiveness, exceptions, and remediation progress.
Requirements
- At least one year of professional experience in ITGC, IT audit, technology risk, cybersecurity risk, or IT SOX.
- Hands-on experience testing technology controls and evaluating control design and operating effectiveness.
- Ability to collect, evaluate, and validate control evidence and prepare defensible workpapers.
- Knowledge of logical access, user provisioning, privileged access, change management, computer operations, and security controls.
- Strong analytical, risk-assessment, communication, documentation, and time-management skills.
- Ability to work independently and manage deliverables in a fully remote environment.
Nice to have
- IT SOX testing experience and exposure to cybersecurity maturity assessments.
- Familiarity with cybersecurity and IT control frameworks and GRC tools.
- Experience working with Internal Audit, external auditors, Information Security, or Technology Risk teams.
- CISA, Security+, CRISC, or progress toward a relevant certification.
Culture & Benefits
- Fully remote work within the United States.
- Competitive salary.
- Independent work with ownership of deliverables and minimal supervision.
- Collaboration with control owners, audit teams, Information Security, and program leadership.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →