Jobs and Careers
HA

Director of IT Internal Audit

Hagerty
USA-Remote, United States, United StatesRemotefull_timeVerifiedPosted 23 Jan 2025

About the role

As Director of IT Internal Audit, you will have the responsibility of supporting the SVP of Internal Audit on the execution of the strategy and for day-to-day activities of the Internal Audit and Sarbanes Oxley related to IT systems and controls, with a specific focus on technology, SOX compliance, ISO standards, and cybersecurity. This role is critical in ensuring that the company’s IT infrastructure, processes and controls meet regulatory requirements, operational efficiencies and protect Hagerty brand; particularly within the insurance regulatory environment and non-insurance business (i.e., media, auctions and events).

The Director of IT Internal Audit will plan, conduct fieldwork, report on internal audit engagements and provide guidance and coaching to IT audit team members. In this role you will collaborate with audit leadership is develop annual risk assessment and plan, budgeting, preparation for audit committee presentation and lead the daily execution of the IT SOX and Audit plans including resource allocation, administration, testing and reporting.  

Internal Audit Services at Hagerty is continuing to mature to provide high value, independent, proactive insights, to innovate with technology, and to develop and be a source of top talent, offering an atmosphere for both personal growth and professional growth. The scope includes, but is not limited to, all finance and accounting, vendor management, IT, HR and Risk Management.

The position will be a critical risk partner within the organization while maintaining independence and will ensure that the engagement IT audit staff is performing in accordance with industry best practices, regulatory requirements and company policies and procedures.

Ready to get in the driver’s seat? Join us! 

What you’ll do

Audit Planning and Execution:

  • Develop and implement a risk-based IT audit plan that addresses the highest risk and complexities facing the organization including evaluation of core strategic initiatives.
  • Evaluate resource allocation throughout the year to effectively and efficiently.
  • Conduct IT audits focusing on IT governance, application controls, cybersecurity, data privacy, and compliance with SOX and ISO 27001 internal audit requirements. 
  • Support risk based integrated audit approach when existing enterprise-wide audit engagement.
  • Evaluate the adequacy and effectiveness of IT controls, including those related to financial reporting (SOX), data integrity, security standards, and operational continuity.

Technology and Cybersecurity Oversight:

  • Assess and audit the company’s cybersecurity measures, particularly those protecting sensitive customer data and financial transactions in insurance and lending platforms.
  • Review the security and integrity of IT systems supporting auction car sales, including payment processing, customer data protection, and online auction platforms.
  • Provide guidance on adopting and maintaining industry best practices in cybersecurity, ensuring compliance with regulatory requirements.

SOX Compliance:

  • Collaborate with business and financial audit leaders to develop ensure there is a unified SOX 404 approach.
  • Ensure IT controls are designed and operating effectively to meet SOX 404 requirements, particularly those affecting financial reporting and data accuracy.
  • Collaborate with the finance and IT departments to evaluate and test IT general controls (ITGCs) and automated controls within financial applications.
  • Support external auditors in their assessment of the company’s SOX compliance, addressing any identified control deficiencies.
  • Direct day to day aspects of the Company’s SOX Program as it relates to IT with implementation the longer a long-term vision of transition core testing and administrative activities to management. 
  • Develop Sarbanes Oxley IT policies, procedures, and work standards by applying the appropriate SOX methodologies using SEC requirements and PCAOB guidance.

Regulatory Compliance:

  • Ensure IT audit activities align with regulatory requirements specific to the insurance industry, such as those mandated by state insurance departments and the NAIC.
  • Audit IT systems and processes to ensure they support compliance with lending regulations, including those related to consumer data protection and financial transactions.
  • Monitor emerging regulations and industry standards that impact IT controls and adjust audit plans accordingly.
  • Lead internal audits and gap assessments to identify areas for improvement in ISO compliance, particularly in IT processes supporting regulated financial activities.
  • Incorporate

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Hagerty

View company profile →