Internal IT Auditor

Blue Cross and Blue Shield Association
United States
8 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Artificial Intelligence Automation of Tests Configuration Management Cyber Security Information Systems Continuous Delivery Continuous Integration Data Governance Information Leak Prevention Digital Assets Information Technology Audit Internet Security
+12 more
Information Systems Security Architecture Professional Open Source Technology Systems Development Life Cycle Software Engineering Data Processing Software Security Generative AI AI Platforms Information Technology Free and Open-Source Software Machine Learning Operations Devsecops

Job description

The Senior Internal IT Auditor leads and executes audit engagements, serving as a subject matter resource and ensuring high-quality audit delivery across technology and cybersecurity domains., * Be responsible for performing and leading transactional quality review audits with limited or no supervision

  • Have expert knowledge of transactional quality assurance audit principles and methodology; considered a subject matter expert in multiple functional areas
  • Support risk assessments and development of audit plans for data and AI governance areas
  • Review controls over AI-enabled business processes, including data sourcing, model outputs, decisioning logic, and human oversight mechanisms
  • Leads corrective/ preventive action planning related to transactional audits
  • Assess design and operating effectiveness of controls related to intellectual property (IP) protection, including source code repositories, model artifacts, proprietary algorithms, and data assets
  • Perform audits of DevSecOps pipelines, including CI/CD tooling, automated testing, code promotion, and segregation of duties across development environments
  • Evaluate risks related to use of open-source software, third-party libraries, and external AI services, including licensing compliance, security vulnerabilities, and data leakage
  • Analyze risks associated with data used in software and AI development, including data governance, quality, lineage, privacy, and regulatory compliance (e.g., HIPAA data considerations)
  • Assess AI governance frameworks, including intake, approval, ethical review, monitoring, incident management, and model retirement processes
  • Research issues and shares the findings of that work with varying groups effectively (executives, managers, line staff, etc.)
  • Develop and maintains productive client and staff relationships through individual contacts and group meetings
  • Be proficient in either operational, financial or IT auditing, but not yet an expert. Work still needs oversight to be released and reviewed by Management
  • Work to achieve operational targets with direct impact on BSC departmental results
  • Be responsible for entire projects or processes within BSC annual audit program
  • Communicate with parties within and outside of BSC with the ability to educate others on complex disciplines

Your Work

In this role, you will:

  • Be responsible for performing and leading transactional quality review audits with limited or no supervision
  • Have expert knowledge of transactional quality assurance audit principles and methodology; considered a subject matter expert in multiple functional areas
  • Support risk assessments and development of audit plans for data and AI governance areas
  • Review controls over AI-enabled business processes, including data sourcing, model outputs, decisioning logic, and human oversight mechanisms
  • Leads corrective/ preventive action planning related to transactional audits
  • Assess design and operating effectiveness of controls related to intellectual property (IP) protection, including source code repositories, model artifacts, proprietary algorithms, and data assets
  • Perform audits of DevSecOps pipelines, including CI/CD tooling, automated testing, code promotion, and segregation of duties across development environments
  • Evaluate risks related to use of open-source software, third-party libraries, and external AI services, including licensing compliance, security vulnerabilities, and data leakage
  • Analyze risks associated with data used in software and AI development, including data governance, quality, lineage, privacy, and regulatory compliance (e.g., HIPAA data considerations)
  • Assess AI governance frameworks, including intake, approval, ethical review, monitoring, incident management, and model retirement processes
  • Research issues and shares the findings of that work with varying groups effectively (executives, managers, line staff, etc.)
  • Develop and maintains productive client and staff relationships through individual contacts and group meetings
  • Be proficient in either operational, financial or IT auditing, but not yet an expert. Work still needs oversight to be released and reviewed by Management
  • Work to achieve operational targets with direct impact on BSC departmental results
  • Be responsible for entire projects or processes within BSC annual audit program
  • Communicate with parties within and outside of BSC with the ability to educate others on complex disciplines, At the Blue Cross and Blue Shield Association (BCBSA), we provide business strategy, technical support and consulting expertise to 36 Blue Cross and Blue Shield companies across the nation, employing more than 1,000 of the best strategic thinkers in the industry. We are a Brand manager that sets quality control standards for the 36 independent companies that use the Blue Cross and Blue Shield Brands, and we serve as a trade association that represents these Blue companies. It is through our involvement that the Blues companies share a united vision and strategy while also benefiting from the local strength of all member companies.

Requirements

  • Requires a bachelor’s degree or equivalent experience
  • Requires a minimum of 5 years of prior related experience
  • Basic competence and knowledge with support from others of: Financial Accounting and Finance Concepts, Managerial Accounting, Regulatory, Legal and Economics, Quality Framework, Ethics and Fraud, Information Technology, Governance, Risk and Controls, Organizational Theory and Behavior
  • Working knowledge of AI tools, models, and platforms (e.g., generative AI, ML systems), including associated risks, controls, and governance consideration
  • Strong analytical and problem-solving skills
  • Advanced knowledge of auditing typically obtained through advanced education combined with experience
  • May have practical knowledge of project management
  • Certified Information Systems Auditor (CISA), Advanced in AI Audit (AAIA), Certified Information Systems Security Professional (CISSP), Certified Internal Auditor (CIA) and/or Certified Secure Software Lifecycle Professional (CSSLP) highly desired, Accounting Standards and Regulations, Algorithms, Analysis Skills, Artificial Intelligence (AI), Auditing, Business Processes, CISA - Certified Information Systems Auditor, CISSP - Certified Information Systems Security Professional, Certified Internal Auditor (CIA), Computer Security, Continuous Deployment/Delivery, Continuous Integration, Corrective Action, Cross-Functional, Customer Relations, Data Modeling, Data Processing, Develop and Maintain Customers, Economics, Finance, Financial Accounting, Financial Audit, HIPAA (Health Insurance Portability and Accountability Act), Incident Management, Information Technology/Systems Audit, Intellectual Property (IP), Internal Audit, Internet Security, Legal, Licensing Compliance, Machine Tool, Management Strategy, Open Source, Privacy Regulations, Problem Solving Skills, Process Modeling, Project/Program Management, Quality Assurance, Regulatory Compliance, Risk Analysis, Risk Management, Software Development, Software Development Lifecycle (SDLC), Source Code/Configuration Management (SCM), Team Player, Technical Leadership, Test Automation

About the company

Blue Cross and Blue Shield Association

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:36 min

Choosing between managed AI platforms and custom governance

Péter Farkas Péter Farkas · Europe 2026 Virtual

2:37 min

Tracing the evolution from early AI to generative AI

Mike Mike · World Congress 2025

1:34 min

Transitioning from traditional software development to artificial intelligence consulting

Patrick Schnell Patrick Schnell · Coffee With Developers

3:03 min

Career evolution in data engineering and AI platforms

Maria Apazoglou · Coffee With Developers

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all