|
ESSENTIAL DUTIES AND RESPONSABILITIES: (Other duties may be assigned)
- Lead the comprehensive assessment of technology and operational risks, ensuring timely identification of control gaps and opportunities for improvement within the IT environment.
- Act as a strategic advisor to business leaders by communicating risks, trends, and opportunities related to IT & Operations, fostering a strong culture of compliance and risk management.
- Design, develop, and execute the annual IT & Operations audit plan, ensuring alignment with auditing standards, strategic priorities, and the organization's risk profile.
- Define and establish audit objectives, scope, methodological approach, and procedures, ensuring efficient, risk-based coverage of technology and operational processes.
- Oversee and collaborate with IT and operations process owners to ensure the effective implementation of corrective action plans, following up on the remediation of findings and control gaps.
- Independently evaluate the soundness, effectiveness, efficiency, and proper application of IT & Operations controls, including key and regulatory controls (e.g., SOX), as applicable.
- Lead the preparation and issuance of audit reports, ensuring clear conclusions, actionable recommendations, and visibility of critical matters to senior management and key stakeholders.
- Monitor and maintain up-to-date knowledge of regulatory requirements, standards, and best practices applicable to IT & Operations, ensuring proper integration into audit processes.
- Manage responses to deviations, exceptions, or escalations related to internal controls, ensuring appropriate documentation and effective communication with stakeholders.
- Drive continuous improvement in audit methodologies, tools, and practices to enhance the efficiency and overall impact of the IT & Operations Audit function.
- Ensures execution of all key controls including but not limited to SOX controls for role as per assigned roles within established procedures and within approved delegation of authority and authorized limits. Responds to and reviews all escalations or deviations that may be brought to his or her attention. Reports any exceptions to established internal controls and documents any employee.
|