01Responsibilities
Independently execute detailed testing procedures over access management, change management, IT operations, and system interfaces in accordance with firm methodologies and regulatory standards (e.g., SOX, SOC, NIST, ISO 27001).
Able to identify and document key IT risks, control gaps, and improvement opportunities across enterprise systems, cloud environments, and digital platforms.
Proactively analyze and clearly articulate the design and effectiveness of automated controls, system configurations, and data flows that support financial, operational, and compliance objectives.
Prepare clear, well-supported documentation and workpapers in accordance with firm and regulatory standards.
Work closely with business, risk, and technology stakeholders, including management, IT leadership, and occasionally regulators, to communicate findings and recommendations clearly and professionally.
Contribute to the development of reports and client deliverables that summarize observations, root causes, and practical recommendations for risk mitigation and process improvement.
Build foundational skills in areas such as cybersecurity, cloud computing, identity and access management, data analytics, automation tools, and industry-specific regulations (e.g., HIPAA, SEC, FFIEC).
Approach new challenges with curiosity and a critical-thinking mindset, learning from diverse projects and client environments.
Participate in team collaboration, coaching, and knowledge-sharing to foster a supportive and high-performance culture.
Support coaching and review of Staff work, providing feedback and knowledge sharing.
Basic Qualifications:
Chartered Accountant, MBA, CMA, bachelors degree in information systems, Computer Science, Information Technology, or related fields.
2-4 years of experience in IT internal audit, risk management, or consulting.
Basic understanding of IT controls, IT SOX, system development lifecycle (SDLC), and IT governance frameworks.
Familiarity with tools such as Microsoft Excel, Microsoft Word, Microsoft PowerPoint, Workiva, Audit Board, Archer, Teammate, ServiceNow, or other internal audit management software.
Preferred Qualifications:
Strong attention to detail and documentation accuracy.
Foundational understanding of risk