{"21634238":{"jobPath":"/jobs/21634238/chief-compliance-officer","source":"naylor","job":"21634238","jobTitle":"Chief Compliance Officer"},"21644777":{"jobPath":"/jobs/21644777/security-guard","source":"naylor","job":"21644777","jobTitle":"Security Guard"},"21600937":{"jobPath":"/jobs/21600937/senior-it-auditor","source":"naylor","job":"21600937","jobTitle":"Senior IT Auditor"},"21568027":{"jobPath":"/jobs/21568027/it-audit-manager","source":"naylor","job":"21568027","jobTitle":"IT Audit Manager"},"21649577":{"jobPath":"/jobs/21649577/security-officer","source":"naylor","job":"21649577","jobTitle":"Security Officer"},"21649334":{"jobPath":"/jobs/21649334/assistant-director-it-audit","source":"naylor","job":"21649334","jobTitle":"Assistant Director - IT Audit"},"21645371":{"jobPath":"/jobs/21645371/senior-analyst-it-client-support","source":"naylor","job":"21645371","jobTitle":"Senior Analyst, IT Client Support"},"21648028":{"jobPath":"/jobs/21648028/it-liaison-and-support-lead","source":"naylor","job":"21648028","jobTitle":"IT Liaison and Support Lead"},"21623566":{"jobPath":"/jobs/21623566/senior-internal-audit-data-analyst","source":"naylor","job":"21623566","jobTitle":"Senior Internal Audit Data Analyst"},"21521706":{"jobPath":"/jobs/21521706/it-audit-division-director","source":"naylor","job":"21521706","jobTitle":"IT Audit Division Director"},"21636806":{"jobPath":"/jobs/21636806/senior-it-and-data-analytics-internal-auditor","source":"naylor","job":"21636806","jobTitle":"Senior IT and Data Analytics Internal Auditor"},"21647199":{"jobPath":"/jobs/21647199/chemistry-and-biochemistry-it-consultant-information-technology-consultant-career","source":"naylor","job":"21647199","jobTitle":"Chemistry and Biochemistry IT Consultant (Information Technology Consultant - Career)"},"21644707":{"jobPath":"/jobs/21644707/it-support-assistant-hourly-smart-support-tech","source":"naylor","job":"21644707","jobTitle":"IT Support Assistant (Hourly) - Smart Support Tech"},"21644801":{"jobPath":"/jobs/21644801/it-purchasing-associate-its-university-at-albany","source":"naylor","job":"21644801","jobTitle":"IT Purchasing Associate - ITS - University at Albany"},"21620258":{"jobPath":"/jobs/21620258/technology-audit-manager","source":"naylor","job":"21620258","jobTitle":"Technology Audit Manager"},"21647715":{"jobPath":"/jobs/21647715/deputy-manager-security","source":"naylor","job":"21647715","jobTitle":"Deputy Manager - Security"},"21647189":{"jobPath":"/jobs/21647189/governance-coordinator","source":"naylor","job":"21647189","jobTitle":"Governance Coordinator"},"21623479":{"jobPath":"/jobs/21623479/director-of-government-relations","source":"naylor","job":"21623479","jobTitle":"Director of Government Relations"},"21649207":{"jobPath":"/jobs/21649207/museum-security-guard-part-time","source":"naylor","job":"21649207","jobTitle":"Museum Security Guard (Part-Time)"},"21648711":{"jobPath":"/jobs/21648711/information-security-architect-ent","source":"naylor","job":"21648711","jobTitle":"Information Security Architect - ENT"},"21649526":{"jobPath":"/jobs/21649526/lead-data-center-it-specialist","source":"naylor","job":"21649526","jobTitle":"Lead Data Center IT Specialist"},"21647548":{"jobPath":"/jobs/21647548/program-manager-regulatory-affairs-risk-management-irvine-ft-days","source":"naylor","job":"21647548","jobTitle":"Program Manager, Regulatory Affairs - Risk Management, Irvine - FT Days"},"21644798":{"jobPath":"/jobs/21644798/assistant-professor-of-cybersecurity-game-design-cehc-university-at-albany","source":"naylor","job":"21644798","jobTitle":"Assistant Professor of Cybersecurity & Game Design - CEHC - University at Albany"},"21649442":{"jobPath":"/jobs/21649442/vice-president-information-technology-services-cto-information-services-admin-ft-day","source":"naylor","job":"21649442","jobTitle":"Vice President, Information Technology Services (CTO) - Information Services Admin - FT - Day"},"21649200":{"jobPath":"/jobs/21649200/assistant-professor-of-government-american-politics","source":"naylor","job":"21649200","jobTitle":"Assistant Professor of Government (American Politics)"}}
Reporting to the Director of Audit & Advisory Services, the Assistant Director - IT Audit is responsible for assessing, evaluating and making recommendations to management regarding the effectiveness of information technology (IT) risk management, governance, and internal controls inherent in the processes and activities of the University.
The Assistant Director will serve as a subject matter expert in evaluating IT risk, governance, and controls. The Assistant Director leads the IT audit program which has been established to evaluate the system and process controls to ensure the confidentiality, integrity, and availability of the university's information assets and data. To meet the program's objectives, the Assistant Director will examine the University's IT infrastructure, systems, processes and technology-dependent operations.
The Assistant Director will lead high-impact audit projects and advisory engagements, and deliver strategic insights to University leadership. Our cross-functional approach to auditing involves close collaboration between IT and Operational audit areas. In this capacity, the Assistant Director will need to be familiar with the mission and strategy of the University and is expected to generate value-added recommendations that enhance the University's overall operations. The role requires strong leadership, project management, communication skills, and significant exposure to Senior Management throughout the organization.
The Assistant Director will participate in IT risk assessments, identify emerging IT risks, be familiar with complex systems and IT transformation projects, and maintain the IT audit universe which informs the development of the annual enterprise risk-based IT Audit Plan.
The Assistant Director is expected to:
Perform and oversee professional audit work, individually and as a team leader, in conducting reviews of assigned organizational activities in accordance with both IIA and departmental standards.
Plan and execute IT audit projects designed to provide an assessment of internal control processes and operational performance.
Prepare detailed plans for performing individual audits including the identification of key IT risks and controls, determination of audit objectives, and development of an appropriate audit program. Use knowledge of the current environment and industry trends to identify potential issues and risks.
Under minimal supervision, develop clear, concise, accurate, and complete audit work papers to support findings and recommendations, and write clear and concise reports for management.
Conduct or assist in the performance of special projects or studies, including risk assessments, fraud investigations, audit department policy updates, and due diligence reviews.
Participate in University-wide initiatives, bringing a risk and controls perspective to institutional planning, transformation, and technology strategy.
Oversee engagements with external auditors, as needed, ensuring quality, consistency, and timeliness in deliverables.
Assist the Director with resource planning and organizational strategy to meet department and University needs.
MINIMUM QUALIFICATIONS
Knowledge and skills required for this position are normally acquired through a bachelor's degree in Management Information Systems, Information Security/Assurance, Computer Science, or a related discipline plus at least five years or more in IT Auditing, IT Risk and Compliance, and\or Information Security. Master's degree is a plus.
Proficiency with data analytics using Excel, Tableau, Cognos, or PowerBI is preferred.
Proficient with Microsoft Office applications including Word, Excel, Power Point, and Visio.
Project management skills with demonstrated experience in meeting project timelines and deliverables and the ability to handle multiple project assignments simultaneously.
Excellent written and verbal communication skills, effective report writing, and comfort presenting complex findings to both technical and non-technical audiences.
Strong analytical and problem-solving skills.
Proven ability to build relationships and influence across diverse group of stakeholders.
Understanding of the Institute of Internal Auditor's International Professional Practices Framework, COSO Framework, and/or other professional internal control guidance.
Working knowledge of security and technology frameworks (e.g., NIST, COBIT).
Certification as CISA, CITP, CISSP, CISM preferred, or working towards same.
Demonstrated experience leading complex IT audits and advisory engagements in complex, decentralized, and matrixed organizations.
High degree of professionalism, integrity, and accountability.
Experience managing and mentoring audit teams.
KEY RESPONSIBILITIES & ACCOUNTABILITIES
1) IT Audits:
As a team lead or individually, perform IT audits to provide an assessment of systems, processes and strategies for adherence with internal controls, and to determine that adequate policies and procedures exist to support operations.
As a team lead or individually, identify audit objectives and scope for each review, develop audit programs, perform interviews and testwork, develop clear and concise audit work papers to support findings and recommendations, and write clear and concise reports to management.
As a team lead or individually, manage and perform audits including, but not limited to, the following areas: General IT Controls, Data Security & Privacy, IT Compliance, IT Risk Assessments, IT Governance, and IT Operational Assessments.
As a team lead or individually, conduct integrated audits which evaluate IT, operational, and financial controls. Work collaboratively with fellow members of the Audit & Advisory Services team.
Perform pre-implementation reviews for new or modified application systems to assess application, data integrity and security controls. Demonstrate and apply a thorough understanding of complex information systems.
Participate in ongoing IT risk assessment, identifying emerging IT risk, maintaining the IT audit universe. Continuously assess the evolving IT risk landscape and keep current the IT audit universe and risk assessment model to inform IT audit priorities and resource allocation.
Audit work performed must adhere to the Institute of Internal Audit's (IIA) Standards for the Professional Practice of Internal Auditing. Through the course of performing audits, identify process improvement opportunities, as needed, and work with Audit & Advisory Services management on ongoing quality assurance efforts.
Develop and maintain relationships with Information Technology Services management.
2) Advisory and Special Projects:
Lead or individually contribute to advisory projects, including pre-implementation system reviews, strategic technology initiatives, data governance programs, and resiliency/risk-response planning.
Participate and contribute to University-wide initiatives.
Perform advisory engagements, special reviews and confidential internal investigations, as assigned.
3) Supervisory, Professional Development and Lifelong Learning:
Seek ways to continuously develop professionally through attendance at seminars, in-house training sessions, professional exams/certification, and self-study.
Carry forward information gathered into executing the audit plan.
Foster a culture of continuous improvement and learning within the department.
Supervise and evaluate the work of staff on projects. Provide opportunities to cross-train staff on audit activities and methodologies.
Assist the Director with assessing staff resources to ensure delivery of timely and high-quality audit projects, advisory support, and investigations.
Position Type
Legal and Regulatory Administration
Additional Information
Northeastern University considers factors such as candidate work experience, education and skills when extending an offer.
Northeastern has a comprehensive benefits package for benefit eligible employees. This includes medical, vision, dental, paid time off, tuition assistance, wellness & life, retirement- as well as commuting & transportation. Visit https://hr.northeastern.edu/benefits/ for more information.
All qualified applicants are encouraged to apply and will receive consideration for employment without regard to race, religion, color, national origin, age, sex, sexual orientation, disability status, or any other characteristic protected by applicable law.
Compensation Grade/Pay Type: 111S
Expected Hiring Range: $86,490.00 - $122,163.75
With the pay range(s) shown above, the starting salary will depend on several factors, which may include your education, experience, location, knowledge and expertise, and skills as well as a pay comparison to similarly-situated employees already in the role. Salary ranges are reviewed regularly and are subject to change.
Founded in 1898, Northeastern University is a private research university located in the heart of Boston. Northeastern is a leader in worldwide experiential learning, urban engagement, and interdisciplinary research that meets global and societal needs. Our broad mix of experience-based education programs?our signature cooperative education program, as well as student research, service learning, and global learning?build the connections that enable students to transform their lives. The University offers a comprehensive range of undergraduate and graduate programs leading to degrees through the doctorate in nine colleges and schools.