IT Audit & Controls Analyst

The Smart
United States
29 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Experience required
1 year minimum
Working hours
Regular working hours
Job source

Tech stack

Software Documentation Cyber Security Information Technology Audit Smartsuite User Provisioning Software IT General Controls (ITGC)

Job description

The ITGC Consultant supports the IT Risk and Control Program within the Information Security organization. This role focuses on executing IT General Controls (ITGC) testing, including evidence review, testing documentation, status reporting, and risk analysis. Additionally, the consultant supports cybersecurity maturity assessments, technology risk activities, and SOX-related testing requests as project needs arise., ITGC Testing & Controls Assessment

  • Execute testing of IT General Controls (ITGCs) across assigned applications, systems, and technology processes.
  • Perform testing of control design and operating effectiveness, reviewing control descriptions and underlying technology risks.
  • Request, collect, review, and validate supporting evidence from control owners to ensure controls operated as designed.
  • Prepare complete, accurate, and audit-ready workpapers, documenting testing procedures, evidence reviewed, results, and conclusions.
  • Identify control gaps, exceptions, and deficiencies, escalating issues appropriately and conducting remediation validation testing.

IT Risk & Control Program Support

  • Support the ongoing execution of the IT Risk and Control Program, assisting with technology risk assessments and control evaluations.
  • Analyze control results, identify potential security risks, and maintain testing trackers, status reports, and supporting records.
  • Report on control effectiveness, testing status, exceptions, and remediation progress to meet established timelines.

Cybersecurity Maturity & SOX Support

  • Support cybersecurity maturity assessments by gathering documentation, evaluating current-state controls, and documenting risks and recommendations.
  • Assist with IT SOX control testing, walkthroughs, evidence collection, and remediation follow-up for SOX-relevant applications and infrastructure.
  • Respond to SOX-related audit requests and coordinate with technology control owners.

Requirements

  • 1 or more years of professional experience in IT General Controls (ITGC), IT Audit, Technology Risk, Cybersecurity Risk, or IT SOX.
  • Hands-on experience testing technology controls and evaluating control design and operating effectiveness.
  • Demonstrated ability to collect, evaluate, and validate supporting control evidence.
  • Proven capability to prepare clear, defensible testing documentation and workpapers.
  • Knowledge of common IT control domains, including logical access, user provisioning, privileged access, change management, computer operations, and security controls.
  • Ability to work independently in a fully remote environment, taking ownership of deliverables with minimal supervision.

Preferred Qualifications

  • Prior IT SOX testing experience and exposure to cybersecurity maturity assessments.
  • Familiarity with established cybersecurity, IT control frameworks, and GRC tools.
  • Experience working alongside Internal Audit, external auditors, Information Security, or Technology Risk teams.
  • Experience documenting control deficiencies and tracking remediation plans.
  • Relevant professional certifications or progress toward certifications (e.g., CISA, Security+, CRISC)., * Strong analytical, problem-solving, and risk-assessment skills with exceptional attention to detail.
  • Excellent written and verbal communication skills to interact with control owners and program leadership.
  • High accountability, self-sufficiency, and time-management capabilities to manage multiple assignments and meet deadlines.
  • Professional demeanor with a strong commitment to producing high-quality workpapers.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

1:58 min

Measuring productivity gains from agent-assisted code refactoring

Dr. Alexander Wachtel Dr. Alexander Wachtel +1 · World Congress 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:43 min

Auditing third-party technical quality and team skill profiles

Loïc Carbonne Loïc Carbonne · World Congress 2024

1:32 min

The danger of unverified assumptions in critical systems

Luís Ventura Luís Ventura · World Congress 2024

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all