IT Audit Senior

UHY LLP
St. Louis, MO, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Working hours
Regular working hours
Job source

Tech stack

Business Systems Cyber Security Information Systems Information Technology Audit Information Systems Security Architecture Professional Information Technology

Job description

As a Technology Risk and Compliance (TRC) Senior, you will focus on helping clients understand and mitigate their technological and cybersecurity risks, in addition to building and maintaining positive client relationships. The TRC team’s service offerings include SOC 1®, SOC 2®, PCI, ISO 27001, HIPAA, and many other IT risk and control frameworks. There are numerous consulting opportunities related to assessing IT and cybersecurity risks for multi-national and local clients. You will build fundamental knowledge and technical skills to be successful in the growing field of Information Technology Risk and Compliance services., IT Control Attestations

  • Work directly with IT Audit Managers and clients to gain an understanding of the client’s IT systems, infrastructure, and control environmentApply that understanding to a variety of IT risk and control frameworks such as SOC, PCI, HIPAA, ISO, FFIEC, NIST, CIS Security and many others *

IT Risk Assessments Understand the clients and their stakeholders to assist with an independent assessment of their IT risks and be involved with developing various types of reports and presentations to stakeholders *

IT Risk Assessments Understand the clients and their stakeholders to assist with an independent assessment of their IT risks and be involved with developing various types of reports and presentations to stakeholders *

Controls Testing: Working directly with IT Audit Managers to develop and follow audit plans to evaluate the design and operational effectiveness of client controls *

Documentation: Clearly document the procedures, results of tests, and conclusions performed during control testing *

Training and Support:

  • Work with junior level staff and interns to provide training and support throughout the course of engagements.Review their work and provide feedback *

Quality control Ensure quality control procedures are being executed under direction of engagement supervisor, and perform thorough self-review of all work prior to submission *

Administration

  • Track time and maintain designated chargeable hours for the year

Supervisory responsibilities

  • You will supervise IT Audit Staff and interns throughout engagements. You will review their work and provide feedback to the staff and to the IT Audit Managers

Work environment

  • Work is conducted in a professional office environment with minimal distractions

Physical demands

  • Prolonged periods of sitting at a desk and performing work in front of a computer screen for long periods of time
  • Must be able to lift up to 15 pounds at a time

Travel required

  • Some travel is required. The TRC team meets twice a year at various offices in the county.
  • Some client travel may be required.

Requirements

Do you have experience in Technical training?, Do you have a Bachelor’s degree?, * Bachelor’s degree in accounting, information systems, or similar with an interest in information technology

  • A minimum of 2 - 4 years of related internal audit and IT audit experience

  • Must have a desire to work toward achieving one or more of the following certifications:
  • Certified Public Accountant (CPA)
  • Certified Information Systems Auditor (CISA): ISACA’s globally recognized cornerstone certification for IS, audit, control, assurance, and security professionals who control, monitor, and assess an organization’s information technology and business systems
  • Certified Information Systems Security Professional (CISSP): An independent information security certification governed by the International Information Systems Security Certification Consortium, also known as ISC², which provides security training to information assets
  • Certified Information Security Manager (CISM): ISACA’s certification program for those who manage, design, oversee, or assess an enterprise’s information security

Benefits & conditions

Pulled from the full job description

  • 401(k)
  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance, POSITIVE WORK ENVIRONMENT

Enjoy a collaborative and supportive work environment where teamwork is valued.

ATTRACTIVE COMPENSATION PACKAGES

Our compensation is competitive and tailored to reflect the role, qualifications, and expertise of each individual.

COMPREHENSIVE BENEFIT PACKAGE

Access comprehensive benefits including group health insurance, dental and vision coverage, 401(k) retirement plans, and generous paid time off (PTO) allowances.

About the company

UHY is one of the nation’s largest professional services firms providing audit, tax, consulting and advisory services to clients primarily in the dynamic middle market. We are trailblazers who bring our experience from working within numerous industries to our clients so that we can provide them with a 360-degree view of their businesses. Together with our clients, UHY works collaboratively to develop flexible, innovative solutions that meet our clients’ business challenges. As an independent member of UHY International, we are proud to be a part of a top 20 international network of independent accounting and consulting firms.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

4:30 min

Solving impossible enterprise problems instead of retrofitting applications

Dona Sarkar +1 · Coffee With Developers

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

2:43 min

Auditing third-party technical quality and team skill profiles

Loïc Carbonne Loïc Carbonne · WWC 2024

2:28 min

Preventing sensitive information disclosure in RAG systems

Deepu Deepu · WWC 2025

Videos

See all

Related articles

See all