Sr IT Auditor
University of RochesterAbout the role
As a community, the University of Rochester is defined by a deep commitment to Meliora - Ever Better. Embedded in that ideal are the values we share: equity, leadership, integrity, openness, respect, and accountability. Together, we will set the highest standards for how we treat each other to ensure our community is welcoming to all and is a place where all can thrive.
Job Location (Full Address):
Remote Work - New York, Albany, New York, United States of America, 12224Opening:
Worker Subtype:
RegularTime Type:
Full timeScheduled Weekly Hours:
40Department:
100034 University AuditWork Shift:
UR - Day (United States of America)Range:
UR URG 114Compensation Range:
$86,482.00 - $129,723.00The referenced pay range represents the minimum and maximum compensation for this job. Individual annual salaries/hourly rates will be set within the job's compensation range, and will be determined by considering factors including, but not limited to, market data, education, experience, qualifications, expertise of the individual, and internal equity considerations.
Responsibilities:
GENERAL PURPOSEDevelops, directs, plans and evaluates internal audit programs for the organization's information systems and related procedures to ensure compliance with the organization's policies, procedures and standards. Audits information systems applications to ensure that appropriate controls exist and that information produced by the system is accurate. Advises others on information systems, internal controls and security procedures. Prepares reports and recommendations for management on the results of information systems audits.
ESSENTIAL FUNCTIONS
- Conducts annual audits and risk assessments of the University's related to a wide array of information systems areas.
- Evaluates the University's compliance with the standard requirements and assessment procedures.
- Completes the applicable report for the assessment and attestation of compliance, obtains any required signatures, and submits annually to the University's acquiring bank.
- Plans and leads meetings with clients to discuss the goals and objectives of the audit, with a focus on business processes and internal controls.
- Develops audit procedures geared toward helping business units achieve objectives and identifies areas of exposure that may prevent objectives from being met while allowing for a broad range of coverage to maximize impact. Promotes the ability to provide advisory services through continuous communication with management.
- Executes internal control risk assessments and develops customized audit strategies for the client under audit.
- Creates a plan for the scope, timing, and resources needed to complete assigned audit projects and presents to leadership. Obtains, analyzes, and appraises evidentiary data as a basis for an informed, objective opinion on the overall efficiency and effectiveness of management's internal controls, business processes, and ability to meet goals and objectives.
- Prepares formal reports expressing opinions on the adequacy and effectiveness of activities performed. Makes presentations to leadership prior to and at the conclusion of audits, addressing deficiencies and explaining recommended effective actions.
- Uses technology to support audit projects. Identifies, clarifies, and researches problems to find the best solutions. Performs independent analysis and reasoning with attention to detail, while challenging the culture and status quo to generate new ideas.
Other duties as assigned.
MINIMUM EDUCATION & EXPERIENCE
- Bachelor's degree and 3 years of relevant experience required or equivalent combination of education and experience
KNOWLEDGE, SKILLS AND ABILITIES
- Knowledge of network architecture, servers, databases, and cloud environments required
- Knowledge of data management practices, including data governance, protection, and privacy relevant to regulations such as HIPAA and GDPR required
- Knowledge of standards and best practices for cybersecurity protocols, including firewalls, intrusion detection, and encryption techniques required
- Knowledge of IT governance / control frameworks and standards (e.g., COBIT, HITRUST, NIST, ISO) required
- Proven experience in IT auditing or risk management, with a focus on assessing IT controls and cybersecurity required
- Proven experience in performing audits of IT systems, applications, and data security practices required
- Familiarity with Systems Development Life Cycle (SDLC) required
- Understands internal controls, business processes, auditing procedures
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s