Job Description
The IT / SOC Audit Associate/Senior Associate is responsible for delivering a full range of attest
services to our clients, as well as all phases of assigned projects and engagement management for
multiple clients. Responsibilities include the overall completion of system and organization controls
(SOC) 1 and 2, Type I and II, HIPAA, GDPR, NIST, readiness and examination engagements.
- Essential Duties and Responsibilities:
- Excellent verbal and written English communication skills: clear, concise, professional
- Strong analytical and basic research skills
- Solid understanding of AICPA standards and reporting requirements
- Knowledge of internal controls, security, privacy, audit, and control frameworks (e.g.,
- SOC 2, SOC 1, NIST 800-53 / 171, HIPAA, etc.), and relevant professional standards and regulations
- Solid organizational skills, especially the ability to meet project deadlines with a focus on details
- Ability to successfully multi-task while working independently or within a remote group environment
- Proven ability to work in a deadline-driven environment and manage multiple projects simultaneously
- Execute assigned client engagements from start to completion with minimal supervision
- Manage the day-to-day aspects of assigned engagements, including managing multiple work streams simultaneously and re-prioritizing tasks when unanticipated issues arise
- Evaluate and test client-related business processes and information technology controls and understand areas of risk for each
- Apply current knowledge of information technology trends and systems processes to identify security and risk management issues, as well as other opportunities for overall
- process improvement
- Work well with internal team members and client personnel to successfully execute each engagement
- Maintain professionalism and rapport with the client. Proactively interact with key client management to manage expectations, help ensure client satisfaction, meet client deadlines, and resolve any problems
- Proactively interact with key client management to gather information, resolve problems, and make recommendations risk reducing control improvements
- Exercise judgment and discretion related to conducting audit work
- Promote an ethical and risk-aware culture at the company
- Experience:
- Title is dependent on Experience
- Associate (1-3 years)
- Senior Associate (3-5 years)
- Experience working within a public accounting or internal auditing environment
- Experience performing IT general controls and application control reviews
- Experience working with an offshore audit team (desired, but not required)
- Experience working with GRC Platforms such as Vanta, Drata, Secureframe, etc. (desired, but not required)
- Other Knowledge, Skills & Abilities:
- Knowledge of internal controls, security, privacy, audit, and control frameworks (e.g.,
- SOC 2, SOC 1, NIST 800-53, HIPAA, GDPR, etc.), and relevant professional standards and regulations
- Knowledge of cloud infrastructure management, DevOps and CI/CD, system access management, vulnerability management, and encryption systems management desired
- In process or interest in pursuing a CISA, CISSP, or similar professional designation
- Exceptional client service and communication skills with a demonstrated ability to develop and maintain outstanding client relationships
- Ability to manage multiple engagements and competing priorities in a rapidly growing, fast- paced, interactive, results-based environment
- Strong time management and self-motivational skills, coupled with excellent verbal, written, and presentation skills
- Excellent analytical, organizational and project management skills
- Strong computer skills including proficiency in Microsoft Office, Salesforce, and other cloud- based applications
- Ability to work additional hours as needed to meet project deadlines
- Ability to work independently (100% Remote Position)
- Team player and can do attitude
- Education:
- Bachelorβs degree in accounting, computer science, information systems or other related discipline
- License/Certifications:
- CPA, CISA, CISM, CRISC, CGEIT, CISSP or other relevant certification (preferred)
- Software:
- Proficient in the use of Microsoft Office Suite, Google Suite, Salesforce, and other mainstream cloud-based applications and tools
- Exposure to various operating systems and databases
- Familiarity with DevOps, CI/CD, SaaS, PaaS, IaaS environments, major ERP platforms
Apply tot his job
Apply To this Job