Back to search
PriceSmart Linkedin · Posted 13d ago

IT Risk & Control Audit Specialist

San Jose

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

PURPOSE OF JOB:

The IT Risk & Control Audit Specialist evaluates technology risks and controls across the IT environment, with particular focus on IT audit readiness, control effectiveness, access, change management, data integrity, and technology processes that support Finance and other critical business functions. The role performs control reviews, coordinates audit activities and evidence, identifies control gaps, and supports remediation to help ensure compliance with internal policies and established control requirements.


KEY RESPONSIBILITIES:

• Perform IT risk and control assessments by identifying, assessing, and evaluating inherent and residual risks and monitoring controls according to established frequencies.

• Conduct process and control reviews to evaluate the design and operating effectiveness of key IT controls and identify control gaps or opportunities for improvement.

• Apply strong IT audit fundamentals when reviewing technology processes, systems, and controls, including IT General Controls (ITGC), user access, change management, data integrity, and control evidence.

• Partner with Internal Audit during annual IT reviews by coordinating information requests, validating evidence, supporting walkthroughs, and following up on identified observations.

• Coordinate external IT audit activities to ensure required evidence, deliverables, timelines, and audit phases are completed accurately and in accordance with audit requirements.

• Support control activities for technology that enables Finance and other critical business processes, including applications, interfaces, access, changes, and data integrity.

• Administer access review campaigns and support the timely completion, validation, and documentation of reviews for critical systems and applications.

• Maintain and support the IT Risk and Control Matrix, ensuring risks, controls, owners, frequencies, evidence, and related policies are appropriately mapped and documented.

• Review new technology initiatives and projects to identify applicable IT risks and control requirements and support the implementation of controls before deployment.

• Document control workflows, risk assessments, audit evidence, and remediation activities in a clear and audit-ready manner.

• Monitor emerging technology risks and control issues, escalating material gaps and supporting stakeholders in defining practical remediation actions.

• Partner with Enterprise Risk Management, Internal Controls, Business Continuity, Finance, and IT stakeholders on control-related initiatives and required evidence.


OTHER TASKS

• Perform ongoing surveillance of key controls defined in the Risk, Activity, Control and Monitoring matrix.

• Support the enhancement of the IT control framework and related policies, procedures, and documentation.

• Track control deficiencies and remediation actions through completion and maintain appropriate supporting evidence.

• Support Business Continuity activities by ensuring technology recovery evidence is properly maintained and available for review.

• Assist with risk and control assessments for new technologies, projects, and significant process changes.

• Support corporate risk and control initiatives led by Enterprise Risk Management and Internal Controls.

• Perform other position-related duties as requested by management.




MINIMUM REQUIRED EDUCATION AND/OR FORMAL TRAINING, YEARS OF EXPERIENCE, COMPETENCIES, SKILLS AND/OR SPECIFIC KNOWLEDGE

• Bachelor’s degree in information technology, Computer Science, Accounting, Auditing, Risk Management, or a related field preferred; equivalent combination of education and relevant experience may be considered.

• Minimum 4 years of relevant experience in IT audit, IT risk and controls, IT compliance, technology controls, or a closely related discipline.

• Solid understanding of IT audit and control fundamentals, with the ability to assess evidence, identify control gaps, and communicate findings clearly.

• Experience working with audit teams, control owners, and business stakeholders, including Finance, Internal Audit, or similar functions.

• Strong organizational skills, attention to detail, and accuracy in documentation and evidence management.

• Ability to work independently while collaborating effectively with technical and business teams.

• Ability to communicate professionally and confidently with stakeholders at different organizational levels, including Finance and Audit leadership.

Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search