IT Risk & Controls Senior Consultant - Federal Advisory - Financial Services
GuidehouseAbout the role
Job Family:
IT Risk & Controls Consulting
Travel Required:
Clearance Required:
What You Will Do:
The IT Risk and Internal Controls Senior Consultant will support stakeholder engagement and technical delivery for efforts supporting Financial Services-related government agencies. Role includes supporting IT projects specifically with executing OMB Circular A-123 Appendix A and Appendix D assessments, supporting financial statement audit readiness, and remediation audit deficiencies specifically in response to IT/system deficiencies.
This is an ideal role for someone with an IT audit background who is looking to utilize their skills to support clients internally as a senior consultant rather than as an external auditor.
The IT Risk and Internal Controls Senior Consultant will have a role in working directly with clients and other organizational stakeholders supporting IT internal control efforts, leading walkthrough meetings, preparing approaches and methodologies, and managing several staff. Day-to-day tasks include some or all of the following:
Perform rigorous assessments of IT controls using industry-standard guidance and leading practices.
Perform walkthrough interviews and maintain communication with a variety of client stakeholders, including system personnel such as system and database administrators.
Request, obtain, review, and analyze a variety of artifacts to assist in executing IT controls testing such as security plans, SOPs, system screenshots, and system configuration settings.
Evaluate the design and operating effectiveness of IT controls using provided artifacts, industry-standard guidance, leading practices, and professional judgment.
Professionally document the results of IT controls test work in a consistent and high-quality manner that would allow a reviewer to repeat the test and reach the same conclusion.
Summarize and communicate IT controls assessment procedures and results to a variety of client stakeholders, including senior leadership personnel.
Plan and execute day-to-day activities of IT controls assessments individually and for the team.
Work with client personnel to understand and analyze known IT control weaknesses, identify root causes, and develop detailed, robust remediation plans.
Provide subject matter expertise to client personnel on all matters relating to IT controls and responding to ad-hoc IT controls requests from client personnel.
What You Will Need:
Ability to obtain and maintain a Federal Public Trust.
Bachelor's Degree.
Minimum three (3) years of demonstrated experience in IT controls, audit, assessment, or remediation.
Knowledge of FISCAM and NIST SP 800-53.
Ability to clearly articulate the differences, similarities, and relationships of FISCAM, NIST SP 800-53 and NIST SP 800-53A to client personnel.
Ability to clearly articulate NIST SP 800-37 revision 2 framework to client personnel.
Ability to identify IT risks based on the system’s operating environment, developing mitigating controls to address the risks, and clearly articulating them to client personnel.
What Would Be Nice To Have:
Master's Degree.
Certified Information Systems Auditor (CISA) or equivalent IT certification.
Demonstrates knowledge and experience in IT risk and controls through IT audits, IT control assessments, and IT security reviews. Demonstrates a working knowledge of IT audit, the FISCAM, and other relevant federal information assurance laws, regulations, and guidance.
Experience with AICPA Statement on Standards for Attestation Engagement 18Experience performing IT audits, OMB Circular A-123 or similar internal control assessments, and/or remediating and implementing IT controls is preferable. Experience testing or remediating some or all of the following IT controls topic areas is preferable:
Access and account management, including authorization, provisioning, recertification, and separation.
Segregation of duties, including identifying and defining segregation of duties risks and conflicts, preventive and detective segregation of duties c
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s