Position: IT General Controls ITSOX Audit
Location: Tabor Plains, NJ - Onsite
Duration: Long Term
Skills
Mandatory Skills : GRC Risk Assessment
Job description:
Activities
Liaise with business teams to ensure a comprehensive understanding of business processes and the mapped IT controls and testing procedures.
Perform ITcontrol Assessment in a timely manner validate the test artefacts and ensure that the test was performed correctly and ensure assessment is closed within time frame.
Perform SOX report analysis identify gaps and highlight remediation measures if any.
Ensure Compliance SLA adherence and timely Audit Support and manage External Audits.
Drive and meet compliance program milestones such as SOX NIST ISO.
Customer delivery mindset and very Strong Project management skills.
Act as trusted advisor to the client and drive IT Risk compliance office to manage the entire Audit Compliance Risk Management Program.
Stakeholder Management to communicate IT GRC issues and explaining those in Business language to Key member of the GRC Program at the Client.
Conduct workshop sessions with the business and control owners and provide walkthrough of the Management Communication and participating in all GRC related meetings and status reporting.
Skills and expertise
Should have 8 years of experience in IT GRC with a good understanding of regulations standards including but not limited to SOX compliance NIST 80053 SOC2 and ISO 27001 GDPR.
Exposure to IT GRC tools like Service Now OneTrust Risk Recon Microsoft eDiscovery among others.
Expertise in Security principles Controls Testing Test of design and test of effectiveness Privacy regulations like complying to GDPR PII information etc Policy Procedures and Standards.
Expertise in Security Risk Compliance Audit Management.
Technology stacks
One Trust Risk Recon Microsoft eDiscovery Power BI MS Excel.
Education
Essential
University degree Bachelors degree or equivalent experience in computer science information systems mathematics statistics or related field
Any one Security Certifications among ISO 27001 CISA CISM CEH CISSP CRISC CGEIT CISSP CCSK.