What You Can Expect In This RolePlay a vital role in providing independent and objective assurance over the company's IT systems, controls and security. Contribute to a dynamic and collaborative team, performing a variety of IT audit engagements, consulting and advisory projects.
What You'll Do In This Role• Lead and execute assigned IT audit engagements, from planning to reporting, ensuring adherence to professional standards and methodologies (i.e. NIST, ISO 27001).
• Evaluate the design and effectiveness of IT controls related to cybersecurity, data privacy, system access and change management.
• Analyze IT systems and data using various tools and techniques to identify vulnerabilities, security gaps and potential risks.
• Collaborate with IT and business stakeholders to understand systems, identify areas for improvement and provide value-added recommendations.
• Contribute to consulting and advisory projects related to IT risk management, cybersecurity and data governance.
• Participate in recurring regulatory activities related to IT controls and compliance with consideration for relevant industry regulations such as (National Association of Insurance Commissioners (NAIC) model laws and state insurance regulations.
• Assist with the preparation of written reports for senior leadership and the Board of Directors; develop recommendations for corrective actions to improve operations.
• Build and maintain strong relationships with IT and business stakeholders at all levels.
• Actively participate in team meetings, training sessions and professional development activities.
• Proactively research and assess the impact of emerging technologies and cybersecurity threats on the company's IT environment.
• Commitment to embrace Sammons Financial Group Companies shared values (Accountability, Connection, Openness, Respect and Integrity).
• As stated within the Company Attendance and Punctuality policy, regular attendance is required and expected in order to meet the business service levels and workflow demands.
• Participate in other initiatives and/or projects as necessary.
What We're Looking For- Bachelor's Degree in Accounting, Finance, Management Information Systems or related field Preferred
- 0-2 years' experience in IT audit, IT security, or a related field Preferred
- Strong technical skills in areas such as network security, operating systems, databases and cloud computing
- Knowledge of cybersecurity frameworks (i.e. NIST and ISO 27001), data privacy regulations (i.e. GDPR and CCPA) and security terminology, concepts, IT general controls, standards and practices
- Knowledge of common insurance industry systems, internal controls, policies, procedures, regulations and laws
- Knowledge of the Standards for the Professional Practice of Internal Auditing and the Code of Ethics developed by the Institute of Internal Auditors
- Excellent communication, both written and verbal, and interpersonal skills
- A desire to learn and apply new technologies and data analysis techniques
- Demonstrate thoughtful and innovative approaches to addressing challenges and opportunities, while exemplifying courage to speak up and empowerment to drive change within the workplace
- Proven ability to prioritize multiple tasks and allocate time as needed; ability to adapt to change and learn quickly
- High level of initiative and ability to work independently
- Demonstrated ability to apply critical thinking skills in analyzing processes and systems
- Certified Internal Auditor, Certified Public Accountant, Certified Information Systems Auditor or other relevant designation Preferred
- Some travel to other office locations required.
Other Requirements• Criminal background check required.
Salary Range InformationUSD $61,622.00 - USD $115,540.00 /Yr. Range includes data points from multiple labor markets. Specific range is dependent on the labor market where the incumbent will be hired to perform the position. Starting salary is dependent on candidate qualifications and experience. For a narrower salary range specific to your labor market, please inquire.