
Senior IT Auditor – ITGC, Cybersecurity
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Brazil.
• Formulate IT audit strategies, schedules, and plans
• Organize working papers for Test of Design (TOD) and Test of Operating Effectiveness (TOE) assessments of IT and Operational Technology (OT) controls
• Create test plans for TOD and TOE, including verification criteria
• Develop Risk and Control Matrices (RCMs), audit programs, and control-specific request lists
• Conduct interviews, kick-off meetings, wrap-up meetings, and closing discussions with business and technology teams
• Perform TOD/TOE testing while interpreting regulations and frameworks
• Identify root causes of findings and issues discovered during testing
• Organize and summarize audit points and recommendations
• Formulate action plans for identified findings and issues
• Generate testing results reports and comprehensive executive IT audit reports
• Evaluate IT General Controls (ITGC) and cybersecurity measures, including access controls, change management, operations/infrastructure, incidents, vulnerabilities, hardening, network protection, encryption, malware, logging, and data loss prevention
• Present results and executive recommendations to stakeholders at various organizational levels
• A Bachelor’s degree is required in Information Systems, Computer Science, Computer Engineering, Information Security, Information Technology, IT Auditing, or a related discipline
• At least 3 years of experience in IT auditing
• Proven experience in conducting ITGC audits
• Proven experience in conducting cybersecurity audits
• Experience in developing working papers, Risk and Control Matrices (RCMs), and audit programs
• Experience in conducting interviews and workshops with business and technology teams
• Familiarity with TOD and TOE testing
• Experience in preparing executive audit reports
• Experience in highly regulated and technologically complex environments
• Knowledge of the NIST Cybersecurity Framework (CSF), COBIT 2019, ITIL 4, ISO/IEC 27001, ISO/IEC 27002, the 5W2H methodology, IT risk management, and risk-based auditing
• Experience with Big Four firms, SOX audits, industrial and automation environments (OT/ICS), Operational Technology (OT), IoT, AI, Data & Analytics, cyber assessments, security maturity assessments, and corporate internal audits is an advantage
• Option for remote work
• Opportunities for professional development in IT auditing, ITGC, cybersecurity, IT governance, and risk management
GEICO
State of Vermont
Welo Global
Get handpicked remote jobs straight to your inbox weekly.