Main responsibilities:
ITGC Testing
- Perform test the design and operating effectiveness of IT General Controls for SOX in-scope systems.
- Test logical access controls, including user provisioning, modification, termination, authentication, privileged access, and periodic access reviews.
- Test change management controls, including change authorization, testing, production migration, emergency changes, and segregation of development and deployment duties.
- Test computer operations controls, including job monitoring, interfaces, backups, restoration, incident management, and other applicable IT operations processes.
Evidence, Sampling and Workpapers
- Obtain complete populations and coordinate sample selection in accordance with the approved testing methodology and external auditor requirements.
- Review tickets, approvals, access listings, configuration screenshots, system logs, change records, monitoring reports, SOC reports, and other supporting evidence.
- Validate Information Produced by the Entity (IPE), including report source, parameters, period, filters, date and time, row counts, and completeness and accuracy.
- Prepare clear, accurate, and audit-ready workpapers documenting procedures performed, attributes tested, evidence references, exceptions, and conclusions.
- Maintain testing status, evidence, and results in the designated SOX platform or approved repository.
Exception and Deficiency Support
- Identify control gaps, evidence deficiencies, and operating exceptions; discuss factual observations with control owners and escalate potential deficiencies.
- Support root-cause discussions, remediation planning, and retesting while maintaining tester independence from control execution and remediation ownership
Audit and Stakeholder Coordination
- Coordinate with application owners, infrastructure and security teams, business process owners, consultants, internal audit, and external auditors.
- Support external audit reliance by responding to questions, providing traceable evidence, and completing required testing templates.
- Provide accurate status updates on testing progress, exceptions, dependencies, and overdue items.
Quality and Continuous Improvement
- Apply the approved SOX testing methodology consistently and complete assigned work within agreed timelines.
- Identify opportunities to improve test procedures, evidence requirements, templates, and testing efficiency.
Education
Required: Bachelor's degree in Information Technology, Computer Science, Information Systems, Accounting, Finance, or a related field. Preferred: CISA, CRISC, CIA, CISSP, CPA, CA, or a comparable professional certification.
Knowledge & experience required (To perform satisfactorily in this job what types of experience is required)
- 3-5 years of experience in IT audit, ITGC testing, SOX compliance, internal audit, or external audit, preferably in a multinational or Big Four environment.
- Strong knowledge of SOX ITGC domains: logical access, privileged access, user access reviews, change management, computer operations, interfaces, backups and restoration, and third-party/SOC reliance.
- Experience assessing control design and operating effectiveness, selecting samples, evaluating exceptions, and writing clear audit conclusions.
- Experience validating IPE and system-generated reports for completeness and accuracy.
- Ability to review technical evidence from production environments, including configuration extracts, access listings, tickets, approvals, logs, and monitoring reports.
- Working knowledge of technologies such as SAP ECC/S/4HANA, Active Directory/Entra ID, ServiceNow, CyberArk, SailPoint, Oracle/SQL databases, Windows/Linux, and cloud platforms. AuditBoard or a comparable SOX tool is preferred.
- Understanding of COSO, COBIT, segregation of duties, IT risk, and control concepts.
- Strong analytical, documentation, communication, and stakeholder-management skills; able to manage multiple assignments and deadlines independently.
- Fluent business English.