Director, IT Controls and Compliance
Located:
Arlington
SummaryThis role oversees IT risk, controls, and compliance activities, including documenting and testing ITGCs, application controls, and system interfaces. The position partners with business and IT teams to identify control gaps, manage remediation efforts, support system implementations, and assist with internal and external audits.
The ideal candidate has 7+ years of IT audit, risk, controls, or compliance experience, 3+ years of leadership experience, and a relevant certification such as CISA or CPA. Strong knowledge of IT controls, audit methodologies, ERP systems, and risk-control documentation is required, along with strong analytical, project management, and communication skills.
General Description Duties & Responsibilities- Develop, review and actively participate in the walkthrough of significant business and IT processes/applications and ensure documentation is accurate and reflects relevant risk, key controls, and current process.
- Create documentation (risk control matrices, narratives, flowcharts) and identify areas where control enhancements and/or documentation improvements are needed. Review and/or perform testing for key IT general controls (ITGCs), IT application controls (ITACs), interfaces.
- Review identified ITGCs, ITACs and/or interface deficiencies and work with process owners to identify an appropriate solution/remediation plan. Follow-up on and track remediation activities to verify appropriate resolution.
- Review SOC 1 report evaluations to ensure exceptions are appropriately addressed and that appropriate complementary controls are in place and operating effectively.
- Partner with business process and application owners on system conversions or implementation to provide future state controls design, and pre-go-live validation.
- Facilitate improvement of the IT risk and control environment by increasing the awareness and knowledge of compliance requirements, and identifying ways to streamline or improve the control environment without increasing overall risk;
- Prioritize control projects based on severity of risk and non-compliance. Assist the internal audit team in delivering requests from external auditors and consultants.
QualificationsRequired experience- 7+ years of experience working in IT audit, risk and controls, and compliance, preferably in public accounting, large company IT audit, or IT advisory/consulting
- Holds a relevant certification (CPA, CISA, etc.)
- 3+ years of team leadership experience
- Experience with ERP systems, preferably SAP
- Solid understanding of IT frameworks and audit methodologies
- Proven background in designing and implementing IT controls or experience performing IT audits
- Strong ability to lead the design and documentation of IT general controls, including creating RCMs, performing walk throughs and developing process narratives or flow charts
- Strong managerial, verbal and written communication, project management, analytical, and interpersonal skills
- Ability to effectively prioritize and execute tasks
- Strong attention to detail with an analytical mind on IT processes and outstanding problem-solving skills
- Experience with continuous process improvement, innovative governance, risk and compliance solutions
- Demonstrated teamwork and collaboration in a professional setting
Required Education- Bachelor's degree in computer science, risk management or related technical field
Salary Range$187,000 - $220,000