• Plan, coordinate, and execute SOX walkthroughs and testing for IT general controls, IT application controls, automated controls, key reports, and related control activities.
• Perform and document tests of design and tests of operating effectiveness, including evaluation of control attributes, evidence, exceptions, and conclusions.
• Prepare and maintain accurate, review-ready documentation, including process narratives, system and control descriptions, process maps, risk and control matrices, support requests, testing workpapers, and issue documentation.
• Work directly with control owners, IT and business stakeholders, external auditors, and professional services firms to schedule walkthroughs, obtain evidence, resolve questions, and complete testing on time.
• Evaluate control design and operating effectiveness; identify deficiencies, root causes, risks, and practical recommendations; and support remediation tracking and validation.
• Lead assigned SOX or IT audit workstreams from planning through final conclusions with limited supervision, escalating scope, quality, timing, and control issues promptly.
• Participate in risk assessments, audit planning, scoping, and special projects involving technology, cybersecurity, privacy, cloud and SaaS environments, system implementations, acquisitions, and emerging risks.
• Execute planned technology, compliance, privacy, cybersecurity, operational, or other assurance projects in accordance with Internal Audit methodology and applicable professional standards.
• Use data analytics and audit tools to identify trends, anomalies, population completeness issues, and areas for increased audit focus.
• Develop, test, and scale repeatable analytics, automation, and AI-enabled approaches that improve audit efficiency, documentation quality, evidence review, or control coverage.
• Apply approved AI tools responsibly: protect confidential information, validate outputs against source evidence, document appropriate use, and ensure that human judgment remains primary for audit conclusions.
• Review selected work of staff or less-experienced auditors, provide constructive feedback, share templates and practical knowledge, and help build team capability.
• Track multiple projects, milestones, evidence requests, review comments, and deliverables; communicate status, blockers, and decisions clearly to Internal Audit leadership.
• Build collaborative and trusted relationships across regions and functions while maintaining Internal Audit’s objectivity and independence.
• Stay current on SOX, ICFR, IIA standards, technology risk, cybersecurity, privacy, data analytics, automation, and AI developments relevant to the role.