Job Description
Internal Audit has an outstanding opportunity for a Senior IT Auditor to join their team.
About this Opportunity.
About this Opportunity
Reporting to the IT Audit Manager, the Senior IT Auditor is responsible for planning and performing independent, risk based audit, assurance and consulting activities related to IT internal processes, controls, risk management and governance activities within the University of Washington, while adding value and improving IT operations. The Senior IT Auditor is expected to have internal IT audit experience and to demonstrate proficiency in applying independent judgment in performing internal audit work which conforms to professional standards.
In addition, the Senior IT Auditor performs computer forensics, data analytics, and provides IT support for Internal Audit, including maintaining our servers, installing software upgrades, performing test of backup/recovery, and updating of security plans and department policies and procedures.
This position will primarily support the completion of IT audits in the healthcare space.
Requires an extensive and in-depth knowledge of IT control objectives (COBIT, NIST, OWASP) and IT audit techniques, as well as multiple platforms and complex computing environments.
Requires knowledge of all aspects of IT operations, not just one particular area. This would include controls over governance, risk assessments, incident response, logical access, device and data security, computer operations and change management, backup and recovery, application controls, network operations, servers, personal computers and other devices that connect to our systems, and cybersecurity.
Participates in the review of major UW systems implementations such as our new Workday Financial Reporting system or Epic systems.
Works with and reports to multiple levels of management across the UW, and will be expected to communicate technical issues/concerns in a manner that can be understood by all.
Requires discussion and handling of highly sensitive and/or confidential issues.
Work assigned to Senior IT Auditors is expected to be carried out with limited supervision. The complexity and size of audit assignments vary.
Key Responsibilities
Audit Examinations (75%)
Independently performs information security and IT operations audits and/or advisory services across a broad range of systems and technologies including but not limited to: information security, vulnerability management, application controls, network infrastructure, databases, operating systems, IT general controls, pre and post system implementation, development operations, cloud software and platforms, disaster recovery, and incident response.
Prepares IT audit plan for each audit assignment that ensures effective audit coverage based on an assessment of potential risks and exposures.
Design detailed audit work programs (in many cases customized for the environment), conduct interviews, document and analyze processes/compliance with applicable federal/state laws and University policies, and apply critical thinking to evaluate risks and controls and assess the results of audit testing.
Consistently document relevant facts and information to support the work performed and conclusions drawn so other reviewers can follow the auditor's logic and methodology.
Develop audit findings, determine root causes, and develop relevant and achievable recommendations based on leading practice, the risk profile of the client and the UW.
Effectively communicate audit results, both verbally and in writing, so they are persuasive, placed in the appropriate context, and understood by the recipient. Prepare professional audit reports summarizing findings, recommendations, and management responses.
Perform follow-up reviews to ensure that recommendations are implemented to appropriately address risks identified.
Conduct audits in accordance with professional and departmental standards. Complete work on time and within budget with limited instructions, yet know when to seek guidance from supervising manager when circumstances warrant. May work on audits independently as part of a team project.
Partner with other auditors to provide guidance and assistance in using computerized audit techniques to extract and analyze data from complex computer systems or in performing evaluations of IT controls.
Utilize appropriate tools to conduct computer forensics in support of audits or investigations.
Guidance and Consultation (15%)
Consult with University departments on new system development processes to ensure that appropriate controls are included in the design of planned applications and systems.
Critically apply insights and knowledge of IT and information security to enable clients to solve complex institutional problems while effectively managing risks.
Serve on University committees as requested.
Keep current on technical IT, security, accounting, auditing and government pronouncements.
Participate in University wide risk assessments and Internal Audits quality and process improvement program as requested.
IT Support for Internal Audit (10%)
Coordinate maintenance of server utilized by Internal Audit, including applying appropriate patches.
Review, recommend, and install software upgrades related to electronic workpaper software utilized by Internal Audit.
Perform periodic tests of backup/recovery.
Review and periodically update security plan and department IT policies and procedures.
Required Qualifications
To be considered for this opportunity your application must demonstrate you meet both the minimum qualifications and additional qualifications listed below. Equivalent education and/or experience may substitute for minimum qualifications except when there are legal requirements, such as a license, certification, and/or registration.
Minimum Qualifications
Applicants who do not meet these qualifications WILL NOT be forwarded to the Hiring Department.
Bachelor's degree
Minimum of five years of audit experience, to include at least three years of IT audit experience or technical equivalent experience.
Professional certification such as CISA, CISSP, or CISM.
Additional Qualifications
Ability to independently design and perform IT audits and new systems implementation reviews of information systems in a multi-platform computing environment.
Strong understanding of IT internal controls.
Outstanding analytical, interpersonal and written communication skills.
Ability to communicate effectively with individuals at all organizational levels.
Preferred Qualifications
Master’s Degree in IT, security, auditing, accounting or related discipline.
Familiarity with NIST Cybersecurity framework, CIS18, and PCI standards.
Experience using computerized audit techniques to extract and analyze data from complex computer systems or in performing evaluations of IT controls such as SQL, Tableau, ACL.
Experience using IT forensics tools.
Higher Education and/or healthcare audit experience.
Working Conditions
About the Team
Internal Audit is a primary tool of the Board of Regents to ensure financial, operational and compliance integrity. Other auditors examine specific functions, activities, or areas of risk, but the scope of Internal Audit encompasses all of these areas. Current levels of frequent, significant and costly compliance issues in healthcare, higher education, and IT emphasize the importance of the internal audit function. The success and reputation of Internal Audit rest with the work performed by the Principal, Senior and Staff Auditors.
Compensation, Benefits and Position Details
Pay Range Minimum:
$96,000.00 annual
Pay Range Maximum:
$120,000.00 annual
Other Compensation:
Benefits:
For information about benefits for this position, visit https://www.washington.edu/jobs/benefits-for-uw-staff/
Shift:
First Shift (United States of America)
Temporary or Regular?
This is a regular position
FTE (Full-Time Equivalent):
100.00%
Union/Bargaining Unit:
Not Applicable
About the UW
Working at the University of Washington provides a unique opportunity to change lives – on our campuses, in our state and around the world.
UW employees bring their boundless energy, creative problem-solving skills and dedication to building stronger minds and a healthier world. In return, they enjoy outstanding benefits, opportunities for professional growth and the chance to work in an environment known for its diversity, intellectual excitement, artistic pursuits and natural beauty.
Our Commitment
The University of Washington is committed to fostering an inclusive, respectful and welcoming community for all. As an equal opportunity employer, the University considers applicants for employment without regard to race, color, creed, religion, national origin, citizenship, sex, pregnancy, age, marital status, sexual orientation, gender identity or expression, genetic information, disability, or veteran status consistent with UW Executive Order No. 81 .
To request disability accommodation in the application process, contact the Disability Services Office at 206-543-6450 or [email protected] .
Applicants considered for this position will be required to disclose if they are the subject of any substantiated findings or current investigations related to sexual misconduct at their current employment and past employment. Disclosure is required under Washington state law .