Jobs and Careers
FR

Sr. IT Compliance Analyst

Fresenius Group
United StatesRemotefull_timeVerifiedPosted 14 Jun 2024

About the role

This is a remote position in Eastern Time Zone.

    PURPOSE AND SCOPE:

    The Sr. IT Compliance Analyst plays a crucial role in supporting Digital Technology & Innovation (DTI) by managing IT global audits (SOX, Internal, External), IT controls, and issue management programs on a global scale. As a core member of the Governance, Risk, and Compliance (GRC) team, this position is integral to maintaining robust IT-related processes. Reporting to the Senior Director, Global DTI, the IT Compliance Analyst drives critical audit program management, annual IT control testing, monitoring, metrics, and ensures compliance across the enterprise. 

    Sr. IT Compliance Specialist - IT Focus:

    • Audit Lifecycle / Program Support: Manage and support global IT audit programs, including internal and external audits, through all phases: communication, scoping, documentation requests, control testing, fieldwork, management response, metrics, and issue remediation. Function as a compliance knowledge resource for IT general systems and controls.

    • Relationship Management: Develop and maintain relationships with IT leadership, teams, and business stakeholders through open and frequent communication. Partner with auditees and internal/external auditors to facilitate audit processes.

    • Control Testing and Assurance: Prepare for IT audits by conducting control testing and assurance activities. Support control owners in reviewing access to applications and systems for appropriateness. Update control testing procedures to gather sufficient evidence for audit observations. Verify that control designs (TOD) meet business objectives and support SOX audits.

    • Control Performance and Enhancement: Perform IT control testing (ITGC and ITAC) to ensure control performance aligns with compliance objectives (TOE). Identify opportunities to enhance internal controls cost-effectively, addressing IT infrastructure, systems, applications, security, operations, and processes. Follow up on audit observations and issues until remediation evidence is obtained.

    • Frameworks and Compliance: Maintain control designs for frameworks such as NIST CSF, NIST 800, ISO-27001, SOX, HIPAA, & GDPR. Apply sound judgment in evaluating controls. Challenge IT customers on risk identification and control adequacy. Stay current on best practices and guidance for achieving security compliance.

    • Collaboration and Communication: Oversee and communicate the portfolio of IT-related audits and issues. Collaborate with DTI, Global Internal Audit, and Information Security to ensure consistent communication of controls and risks. Promote security best practices across all business units and departments.

    • Knowledge and Compliance: Maintain strong knowledge of control frameworks and IT best practices. Build and sustain strong relationships with personnel across all business units. Adhere to the Code of Business Conduct and all applicable company policies, procedures, local, state, and federal laws and regulations. Preferred experience as a former Big 4 IT auditor or in IT risk management within the Financial Services industry. Proven experience in IT governance, risk, and controls, including governance frameworks. CISA, CISSP, CRISC, or other relevant certification(s) desired.

     
    PRINCIPAL DUTIES AND RESPONSIBILITIES:

    • Responsible for facilitating IT management’s documentation updates and completion of management assessment for all in-scope FMC IT processes. 
    • Work with IT compliance management to ensure appropriately designed controls are implemented for all in-scope entities and divisions and perform testing to validate their operating effectiveness throughout the fiscal year.
    • Facilitate regular meetings with IT management to plan the documentation updates and testing of SOX IT controls.
    • Analyze SOX testing results, making recommendations to facilitate management’s remediation and/or identification of mitigating controls for all FMC IT deficiencies.
    • Responsible for performing and facilitating access certifications of financially significant systems, including segregation of duties testing.
    • Supports IT compliance management as the principal interface with the external auditor IT Audit function and the FMC IT functions regarding SOX IT matters.
    • Assists management in preparing periodic SOX 404 reporting to the FMCKGaA SOX 404 Steering Committee.
    • Performs the annual SOX 404 scoping exercise to determine if there are any changes to IT data centers, applications or related processes which should be considered to determine what is in scope for SOX 404 purposes.
    • Perform IT control assessments of any new entities, divisions and processes deemed material to the financial reporting process or in the scope of the external audit.  Work with local IT management to develop a

    Apply for this role

    Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

    Apply Now →Generate Application Kit

    Free account required — sign up in 30s

    Company

    Fresenius Group

    View company profile →