The Senior IT Audit Analyst is primarily responsible for performing information technology (IT), information security (IS), operational assurance, and advisory engagements, including the assessment of risks and internal controls, development of engagement objectives and programs, drafting formal reports, and presenting results to the Audit Committee. This position requires effective communication both verbally and in writing to obtain and document reliable and relevant evidence for the engagements.
Duties include:
- Leading Assurance and Advisory Projects, Follow-up Audits, and Special Projects, according to the comprehensive internal audit plan, or as assigned
- Assisting with Annual Risk Assessment
- Assisting with the coordination of Quarterly Audit Committee Meetings
- Performing other duties as assigned
Qualifications:
Three years of related experience. A postsecondary degree may be used as an alternative for years of direct experience; 2 years for an associate’s degree, 4 years for a bachelor’s degree, 6 years for a master’s degree, 7 years for a professional degree, or 9 years for a doctoral degree.
Preferences:
- A bachelor's degree from an accredited college or university in finance, accounting, statistics, business, computer science, management information systems, or a related field
- Master of Business Administration or master’s degree from an accredited college or university in finance, accounting, statistics, computer science, management information systems, or a related field
- Possession of Certified Internal Auditor (CIA), Certified Investments and Derivatives Auditor (CIDA),Certified Public Accountant (CPA), Certified Information System Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP) or Certified Fraud Examiner (CFE) credential
- Experience in public accounting or auditing, and the financial services industry
Knowledge, Skills and Abilities:
- Knowledge of relevant industry standards, including the IIA Standards, the Center for Internet Security’s Critical Security Controls (CIS CSC framework), NIST security Standards, and Committee of Sponsoring Organizations (COSO) framework, IT Security and Compliance standards, and related principles
- Thorough knowledge of governance, risk and control appropriate to the organization
- Strong data analytics skills
- Proficient in preparing visual analytics, dashboard using Tableau and/or other software
- Extensive Microsoft Office skills (Excel, Word, Visio, Access and Project)
- Excellent written and verbal communication and presentation skills
- Solid organizational and leadership skills
- Ability to perform at a high level in a team environment
- Ability to work independently, exercise independent judgment, and prioritize work assignments to meet deadlines
- Ability to research and summarize key points effectively
- Advanced knowledge and experience of industry related IT infrastructure, solutions, and platforms for defending against the threat landscape, including firewalls, security incident and event monitoring, vulnerability and penetration management