IT Auditor II

Brotherhood Mutual Insurance Company
Fort Wayne, IN, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours
Job source

Tech stack

Control Objectives for Information and Related Technology (COBIT) Cyber Security Information Systems Data Security Information Technology Audit IT Management Information Technology

Job description

Independently execute governance, risk, and compliance activities, including internal IT audits. Assist in reviewing IT policies and standards, collaborating with stakeholders to ensure effective controls and regulatory compliance., To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

  • Assist the team lead and management with risk and control consulting for IT and business departments with understanding and fulfilling their responsibilities related to IT governance, risk, and compliance.
  • Execute IT Audit Plan items assigned by the team lead and management. Prepare or review assigned reports of audit findings and opportunities for improvement and communicate these to appropriate company leadership.
  • Review and update assigned policies to ensure they comply with industry standards and corporate needs.
  • Assist with maintaining the controls framework for measuring the organization’s controls and risk, assist with the collection of metrics to be reported to Senior Management that display policy compliance, finding remediation, and security posture.
  • Follow/support the communication mechanisms to report results of audits, risk/controls consulting projects, and investigations to management and the Audit Committee.
  • Work with compliance to ensure legal and regulatory obligations for cybersecurity and privacy are being met as directed by the team lead and management.
  • Perform assigned vendor risk management activities.
  • Assist the team lead and management in maintaining a risk register for cyber risks affecting the business, providing reasonable assurance that risk management, control, and governance systems are functioning as intended.
  • Follow the company’s ERM approach to evaluating risks and ensure the organization’s risk posture is within the risk tolerance limits.
  • Assist with the coordination of external audits/reviews and gather/document assigned artifacts for external requests for attestation of security and privacy practices.
  • Complete other duties as assigned.

Requirements

  • Must possess strong written, verbal, and presentation skills.
  • Self-motivated with strong interpersonal, communication and analytical skills.
  • Strong project management capabilities.
  • Understanding of financial audit principles and the Sarbanes-Oxley Act or Model Audit Rule Act.
  • Familiarity with NAIC Insurance Data Security Model Law.
  • Familiarity with New York DFS Cyber Security Regulations (23 NYCRR 500 and related).
  • Familiarity with NIST Cyber Security Framework (NIST CSF).
  • Familiarity with Service Delivery and Controls Frameworks (COBIT, NIST, ITIL).
  • Familiarity with privacy regulations (e.g. GDPR, CCPA).
  • Effectively interface with external contacts, Brotherhood employees, managers, and department staff members., List Degree Requirement, Years’ Experience, and Certifications
  • Bachelor’s degree, preferably in IT, Business Administration, or Accounting required.
  • Must have two to three years of external and/or internal information technology, auditing or GRC experience.
  • Certified Information Systems Auditor (CISA) and/or Chartered Property and Casualty Underwriter (CPCU) designation is desired.
  • An insurance background is highly desired.

Terms and Conditions

This description is intended to describe the general content of and requirements for the performance of this position. It is not to be construed as an exhaustive statement of duties, responsibilities, or requirements.

Because the company’s niche is the church and related ministries market, and because effective service requires a thorough understanding of this market, persons in this position must be familiar with church operations and must conduct themselves in a manner that will neither alienate nor offend persons within this target niche.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah · World Congress 2025

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:17 min

Governing enterprise IT as a global automotive CIO

Katrin Lehmann Katrin Lehmann +1 · Coffee With Developers

5:00 min

Managing complex state with scope-based resource management

Bjarne Stroustrup · World Congress 2022

Videos

See all

Related articles

See all