Knowledge of IT processes including cloud security and databases
Familiarity with AICPA/IIA standards and COSO/COBIT frameworks
Strong communication and project management skills
Attention to detail and ability to incorporate feedback
Responsibilities
Conduct IT operational audits and manage project timelines
Execute test procedures and document findings in workpapers
Collaborate with teams on root cause analysis and remediation
Lead walkthroughs with control owners and document ITGC test results
Communicate and validate deficiencies with stakeholders
Maintain awareness of ITGC status and follow up on remediation actions
Identify opportunities for process improvements using AI tools
Benefits
Opportunities for professional development and continuing education
Work in a dynamic environment with access to emerging technologies
Collaborative team culture focused on innovation
Flexibility in managing work projects and timelines
Access to audit tools and resources for enhancing audit quality
Full Job Description
Requisition Number: 29639
Position Summary
The Senior IT Auditor conducts IT operational audits (e.g., Cloud Security, Vulnerability Assessment, SDLC, BCP/DR) and SOX ITGC compliance audits across the UGI enterprise. This role requires strong project management skills, proactive verbal and written communication, and a willingness to leverage emerging technologies including AI-powered tools to enhance audit quality and efficiency.
Key Responsibilities
IT Operational Audits (40%)
Develop risk and control matrices, audit approaches, and test procedures. Manage project timelines, coordinate with stakeholders, and proactively communicate status and deadlines to audit management.
Execute test procedures and create concise, precise workpapers. Verify accuracy of all work product-including control owner assignments and data references-before submitting for review.
Validate exceptions with auditees, collaborate on root cause analysis and remediation. Align with audit management on approach and messaging before drafting deliverables. Initiate discussions when timelines are at risk.
Provide guidance to team members and lead project elements as needed.
SOX ITGC Compliance (40%)
Schedule and lead walkthroughs with control owners to understand IT processes and the control environment. Execute ITGC test procedures and document conclusions in workpapers.
Communicate and validate deficiencies with auditees, external auditors, and the audit team. Align with management before changing stakeholder commitments or deadlines.
Maintain ongoing awareness of ITGC status throughout the SOX cycle by communicating regularly with KPMG, control owners, and the Internal Controls & Compliance Team. Follow up on remediation actions.
Innovation & AI Adoption (5%)
Identify opportunities to enhance audit processes through automation and AI tools (e.g., Claude, data analytics platforms). Champion continuous improvement.
Other & Administrative (15%)
Ad hoc projects, audit tool administration, time reporting, one-on-ones, and CPE requirements.
Professionalism Expectations
Communicate verbally with confidence-raise issues, ask questions, and engage in discussion rather than relying solely on email.
Acknowledge assignments promptly, provide timelines, and keep management informed through regular verbal check-ins and written updates without requiring follow-up.
Prepare stakeholder-ready deliverables tailored to the audience.
Receive feedback constructively and apply it consistently to future work, demonstrating measurable improvement.
Qualifications
Required:
Bachelor's degree
3+ years IT audit experience (operational audits and SOX)
2+ years SOX ITGC experience
Knowledge of IT processes: network, cloud security, OS, applications, databases, information security
Knowledge of AICPA/IIA standards, COSO, and COBIT frameworks
Working knowledge of common OS (Windows, UNIX/Linux), databases (SQL, Oracle), and ERP systems (SAP, JDE, Sage 100)
Strong verbal and written communication skills-able to lead discussions, present findings, and engage stakeholders at all levels
Attention to detail with disciplined self-review of work product
Ability to internalize feedback and carry lessons into future work
Preferred:
IT operational audit experience (Cloud Security, Vulnerability Assessment, SDLC, BCP/DR)
CISA, CIA, or CISSP certification
Energy/Utilities industry experience
Familiarity with AuditBoard and data analytics tools
Experience with AI-powered audit and productivity tools
French and/or German language skills
About UGI Corporation
UGI Corporation is a holding company that operates through its subsidiaries in the energy distribution, storage, and services industries. The company's subsidiaries include UGI Utilities, AmeriGas, and UGI International. UGI Utilities provides natural gas and electric service to customers in Pennsylvania. AmeriGas is the largest retail propane marketer in the United States. UGI International distributes liquefied petroleum gas in Europe. UGI Corporation was founded in 1882 and is headquartered in King of Prussia, Pennsylvania.