• Minimum of 4-5 years of IT auditing and systems experience with a focus on information security and cyber security controls (e.g., NIST Cyber Security Framework controls)
• Solid knowledge of audit procedures and technical security and control standards usually obtained through related work experience and a four year degree program is required to perform system audits
• Solid understanding of Information Technology General Controls (ITGC) and non-ITGCs (e.g., Configuration Management, Vendor Management)
• Solid understanding of Information Technology Service Management (ITSM) controls (e.g., Incident Management, Problem Management)
• Skills as needed to perform testing of design and operational effectiveness of application controls (e.g., Interface Controls)
• Knowledge of the operations, functions, and objectives of interfacing areas is required to properly audit operations, services, systems, workflow, and operational impact on other areas
• Operates independently; has in-depth knowledge of business unit/function
• Knowledge of systems software applications and databases common to the mainframe and distributed environments, such as UNIX, iSeries, and Windows is a plus
• Understanding of networks, routers, and firewalls is also a plus
• Certified Information System Audit (CISA) certification is preferred. Additional certifications such as Certified Information Systems Security Professional (CISSP), or other related certifications is a plus