Information Technology Auditor II

Southwest Gas
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Intermediate
Compensation
$ 109K

Job location

Tech stack

Microsoft Windows
Microsoft Active Directory
Artificial Intelligence
Amazon Web Services (AWS)
Data analysis
Azure
Unix
Software as a Service
Cloud Computing
Control Objectives for Information and Related Technology (COBIT)
Computer Security
Information Systems
Databases
Computer Engineering
Linux
Identity and Access Management
Information Technology Operations
Information Systems Security Architecture Professional
Microsoft Office
Microsoft Software
Microsoft SQL Server
Oracle Applications
SharePoint
Security Information and Event Management
Software Engineering
Software Vulnerability Management
IT General Controls (ITGC)
Mitre Att&ck
Information Technology
Process Control Systems
Data Analytics
CIS Benchmarks
Network Server

Job description

The Information Technology Auditor II is responsible for helping the Internal Audit department maintain an independent, objective assurance and consulting function designed to add value and improve the Company's operations. This position works independently with appropriate oversight, identifying and assessing risks, developing risk-based audit programs, and planning and executing audit and consulting engagements primarily related to information technology, cybersecurity, and technology-enabled business processes. The position evaluates governance, risk management, and control processes, provides recommendations to improve the effectiveness and efficiency of Company operations, and continues developing technical expertise, professional judgment, and audit leadership skills through increasingly complex assignments., + Cloud infrastructure technologies (Microsoft Azure, Amazon Web Services (AWS), and cloud-based/SaaS platforms), application development and support, and emerging technologies

  • Industrial control systems
  • Database technologies (Oracle, SQL Server, etc.)
  • Networking (various hardware/software and relevant practices)
  • System security (identity and access management, SIEM/SOC/SOAR, endpoint security, vulnerability management, and security operations)
  • Frameworks or industry best practices (e.g., COSO, COBIT, NIST, DHS, CISA, SANS, ISO 27001, MITRE ATT&CK, CIS Controls, Global Internal Audit Standards, and ISACA guidance)
  • Knowledge of domestic and global data privacy regulations and requirements (e.g., CCPA, CPRA, GDPR, etc.)
  • Cybersecurity
  • Artificial intelligence, generative AI governance, automation, or other emerging technologies
  • Sarbanes-Oxley design and operating assessments (system-generated reports, IT general controls, and automated controls)
  • Audit software (audit management, analytics, and governance, risk, and compliance (GRC) platforms)
  • Large-scale IT system implementations, transformations, migrations, or upgrades

Requirements

This position requires at least two years of relevant experience in internal audit, external audit, information technology, cybersecurity, risk management, or related fields and a bachelor's degree in computer science, computer engineering, information systems, information technology, cybersecurity, data analytics, or a related field from an accredited university, or equivalent combination of education and experience sufficient to successfully perform the essential job responsibilities. The individual should also demonstrate the following qualifications:

Strong analytical and problem-solving skills Excellent soft skills including, but not limited to, communication (both verbal and written), teamwork, building interpersonal relationships, organizational savvy, introspection, and diplomacy Ability to adapt to change and balance multiple assignments Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), or other relevant certification preferred Demonstrated foundational knowledge, practical experience, or exposure in one or more of the following technology, cybersecurity, risk management, or control areas is preferred:

  • Familiarity with regulatory, legal, and compliance requirements related to the natural gas industry or other highly regulated industries
  • Data analytics
  • General IT operations
  • Ability to read or write computer code (any language)
  • Microsoft technologies (Desktop, Servers, Active Directory, SharePoint, Office)
  • Operating systems (Windows, UNIX, Linux)

Benefits & conditions

At Southwest Gas, attracting the best talent is key to our strategy and success as a company. We use flexibility to develop competitive compensation offers to ensure we are able to hire the best candidates. The quoted salary range represents the minimum and maximum of the pay range for the position. It is provided as a good faith estimate as to what our ideal candidates are likely to expect, as we tailor our offers within the range based on the selected candidate's experience, industry knowledge, location, technical and communication skills and other factors that may prove relevant during the interview and selection process.

About the company

Our History Southwest Gas Corporation was founded in 1931 and is a subsidiary of Southwest Gas Holdings Inc. We provide natural gas service to Arizona, Nevada, and portions of California. Our communities, and the more than 2 million customers we serve, are the reasons why we've been heating things up for decades. So, whether you're enjoying a backyard barbeque with friends, getting cozy indoors during the winter, or preparing an epicurean delight in your new restaurant, Southwest Gas is here to support your comfort and your lifestyle. Southwest Gas is an equal opportunity employer, disability/veteran, and an at-will employer.

Apply for this position