Job Description
The Senior Information Technology (IT) Auditor is responsible for executing RPM's global IT internal audit activities, including testing of IT general controls (ITGCs) supporting internal control over financial reporting (ICFR), information security audits, technology-focused operational audits, and reviews of significant system and ERP implementations. This role performs higher-risk and more complex audit procedures, assists in audit planning and reporting, and supports the development of Staff Auditors during engagements. The position works closely with IT Audit management, Corporate and Group IT personnel, and external auditors while bringing sound technical judgment, strong audit execution skills, and the ability to assess IT risks and controls with limited supervision, towards the successful execution of RPM's global Internal Audit plan.
Responsibilities
Execute and Support IT Audit Activities
• Perform risk-based IT audits across RPM's global operations.
• Evaluate control design and operating effectiveness via walkthroughs, testing, evidence review, and clear documentation of procedures and conclusions in accordance with department standards.
• Identify and assess control deficiencies, draft practical observations and recommendations, and communicate progress, findings, delays, or other matters requiring management attention.
• Manage assigned work across multiple engagements, meeting established quality standards, milestones, and deadlines with limited supervision.
Support SOX, External Audit Reliance, and Remediation
• Assist IT Audit management with risk assessment, engagement planning, scope development, fieldwork coordination, and closing discussions.
• Work directly with subsidiary IT teams to obtain supporting documentation.
• Coordinate with external auditors under the supervision of IT Audit management and respond promptly to review comments and requests for additional information.
• Perform follow-up testing, evaluate remediation evidence, track corrective-action progress, and escalate unresolved or inadequately remediated issues.
• Support recurring control certification and other internal control activities, as assigned.
Collaborate and Develop Team Capability
• Build productive relationships with Internal Audit colleagues and Corporate, Group, and operating company IT personnel throughout planning, fieldwork, reporting, and follow-up.
• Share technical knowledge and contribute to improvements in audit methodology, testing approaches, work-paper quality, and departmental practices.
• Provide day-to-day guidance, technical support, and coaching to Staff IT Auditors and interns during engagements.
• Maintain knowledge of relevant developments in information technology, cybersecurity, internal auditing, internal controls, and applicable frameworks and regulatory requirements.
• Participate in department training initiatives and management meetings, and support communications regarding IT audit results and insights, as appropriate.
Qualifications
Experience
• 5-8 years of progressive experience in IT internal audit, external IT audit, information technology, cybersecurity, technology risk, public accounting, or a related assurance field preferred.
• Experience evaluating ITGCs and supporting SOX or other internal control requirements preferred.
• Demonstrated ability to evaluate risks and controls, document well-supported conclusions, manage assigned work with limited supervision, and meet established deadlines.
• Experience with information security, technology, or system implementation audits is a plus.
• Experience in a global, decentralized, or publicly traded organization is a plus.
Education & Certifications
• Bachelor's degree in information systems, information technology, cybersecurity, computer science, or a related field required (additionally in accounting or business is a plus).
• Master's degree in a relevant field is a plus.
• Relevant professional certification, such as CISA, CIA, or CPA, is preferred; active pursuit of a certification is encouraged.
Technical Expertise
• Solid understanding of IT risks, IT general controls, internal controls, and IT auditing concepts, including control design and operating effectiveness
• Working knowledge of relevant internal control and information security frameworks, such as COSO and NIST.
• Ability to assess IT processes, systems, risks, and controls and reach sound, evidence-based conclusions with limited guidance.
• Experience with Optro/AuditBoard or similar audit/GRC management platforms preferred.
• Proficiency in Microsoft Excel, Word, and PowerPoint required; experience with data analytics or other technology-enabled audit techniques is a plus.
Leadership & Skills
• Strong written and oral communication skills, including the ability to document and present audit results clearly and professionally.
• Self-motivated and able to work independently, manage competing priorities, and collaborate effectively within small teams.
• Strong analytical and problem-solving skills, attention to detail, professional integrity, and sound judgment regarding escalation.
• Ability to coach junior auditors and build productive relationships with technology, finance, and business stakeholders.
• Adaptable when working across diverse systems, business operations, and international environments, with a willingness to travel.
Benefits and Compensation
• The employee will be eligible to participate in all applicable corporate benefit programs which include a defined benefit pension plan, a company-matched 401(k), medical and dental plans, group life and disability plans, and employee assistance program. The employee will also be eligible for paid vacation, PTO, paid holidays, and tuition reimbursement. Employee will be eligible for annual merit increases and bonus.