Overview
This role designs, implements, and monitors IT controls for core applications and systems. Responsibilities include analyzing IT data to assess risk and improve processes and efficiency.
Responsibilities
- Conduct risk assessments of information technology systems and internal processes.
- Assess security risks for systems, applications, and processes with emphasis on cybersecurity risks against common control frameworks and regulations, including but not limited to HIPAA, NIST, and ISO-27001; recommend mitigations.
- Use qualitative and quantitative analysis methods to assess risk and provide outputs to risk stakeholders.
- Design, monitor, and evaluate controls for effectiveness and efficiency to mitigate risks based on the organization’s defined risk appetite.
- Prepare finalized reports documenting identified risks and recommended controls to support treatment decisions.
- Prepare and document standard procedures and protocols.
- Review and prepare scheduled audit reports from both internal and external requests.
- Design application and system-level controls aligned with best auditing and security practices.
- Partner with business owners to identify key controls and coordinate measurement efforts to improve processes.
- Complete optimization reviews and prepare audit reports associated with the completion of scheduled audits.
- Assist with designing the IT environment to conform to relevant industry standards, such as ISO 27001, HIPAA, Sarbanes-Oxley, and PCI-DSS, and other related state requirements.
- Assist with evaluation of controls against security best practices.
- Serve as the primary liaison among auditing bodies, IT security management, compliance, and business stakeholders.
- Assist with implementation of department strategy related to information systems and technology architecture.
- Perform other duties as assigned.
- Comply with all policies and standards.
Requirements
- Bachelor’s degree in IT, MIS, Accounting, Finance, Business Administration, related field, or equivalent experience.
- 3+ years of combined auditing and IT controls design experience.
- Knowledge of IT systems and processes and experience evaluating internal technical control systems.
Preferred Qualifications
- CISSP, CRISC, CISA, CISM, FAIR, CPA, or CIA.
Compensation & Benefits
- Pay Range: $70,100.00 - $126,200.00 per year
- Comprehensive benefits package, which may include:
- Health insurance
- 401K and stock purchase plans
- Tuition reimbursement
- Paid time off plus holidays
- Flexible work approach (remote, hybrid, field, or office work schedules)
- Actual pay may be adjusted based on skills, experience, education, and other job-related factors permitted by law, including full-time or part-time status.
- Total compensation may also include additional forms of incentives.
- Benefits may be subject to program eligibility.
Location
Remote position within the United States.
Candidates must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. Sponsorship and future sponsorship are not available for this opportunity, including employment-based visa types H-1B, L-1, O-1, H-1B1, F-1, J-1, OPT, or CPT.