Benefits:
- Competitive salary
Location
Remote
Remote
Experience Level
Entry–Mid Level (1 or more years of experience)
Entry–Mid Level (1 or more years of experience)
Role Overview
The ITGC Consultant supports the IT Risk and Control Program within the Information Security organization. This role focuses on executing IT General Controls (ITGC) testing, including evidence review, testing documentation, status reporting, and risk analysis. Additionally, the consultant supports cybersecurity maturity assessments, technology risk activities, and SOX-related testing requests as project needs arise.
The ITGC Consultant supports the IT Risk and Control Program within the Information Security organization. This role focuses on executing IT General Controls (ITGC) testing, including evidence review, testing documentation, status reporting, and risk analysis. Additionally, the consultant supports cybersecurity maturity assessments, technology risk activities, and SOX-related testing requests as project needs arise.
Key Responsibilities
ITGC Testing & Controls Assessment
• Execute testing of IT General Controls (ITGCs) across assigned applications, systems, and technology processes.
• Perform testing of control design and operating effectiveness, reviewing control descriptions and underlying technology risks.
• Request, collect, review, and validate supporting evidence from control owners to ensure controls operated as designed.
• Prepare complete, accurate, and audit-ready workpapers, documenting testing procedures, evidence reviewed, results, and conclusions.
• Identify control gaps, exceptions, and deficiencies, escalating issues appropriately and conducting remediation validation testing.
• Execute testing of IT General Controls (ITGCs) across assigned applications, systems, and technology processes.
• Perform testing of control design and operating effectiveness, reviewing control descriptions and underlying technology risks.
• Request, collect, review, and validate supporting evidence from control owners to ensure controls operated as designed.
• Prepare complete, accurate, and audit-ready workpapers, documenting testing procedures, evidence reviewed, results, and conclusions.
• Identify control gaps, exceptions, and deficiencies, escalating issues appropriately and conducting remediation validation testing.
IT Risk & Control Program Support
• Support the ongoing execution of the IT Risk and Control Program, assisting with technology risk assessments and control evaluations.
• Analyze control results, identify potential security risks, and maintain testing trackers, status reports, and supporting records.
• Report on control effectiveness, testing status, exceptions, and remediation progress to meet established timelines.
• Support the ongoing execution of the IT Risk and Control Program, assisting with technology risk assessments and control evaluations.
• Analyze control results, identify potential security risks, and maintain testing trackers, status reports, and supporting records.
• Report on control effectiveness, testing status, exceptions, and remediation progress to meet established timelines.
Cybersecurity Maturity & SOX Support
• Support cybersecurity maturity assessments by gathering documentation, evaluating current-state controls, and documenting risks and recommendations.
• Assist with IT SOX control testing, walkthroughs, evidence collection, and remediation follow-up for SOX-relevant applications and infrastructure.
• Respond to SOX-related audit requests and coordinate with technology control owners.
• Support cybersecurity maturity assessments by gathering documentation, evaluating current-state controls, and documenting risks and recommendations.
• Assist with IT SOX control testing, walkthroughs, evidence collection, and remediation follow-up for SOX-relevant applications and infrastructure.
• Respond to SOX-related audit requests and coordinate with technology control owners.
Required Qualifications
• 1 or more years of professional experience in IT General Controls (ITGC), IT Audit, Technology Risk, Cybersecurity Risk, or IT SOX.
• Hands-on experience testing technology controls and evaluating control design and operating effectiveness.
• Demonstrated ability to collect, evaluate, and validate supporting control evidence.
• Proven capability to prepare clear, defensible testing documentation and workpapers.
• Knowledge of common IT control domains, including logical access, user provisioning, privileged access, change management, computer operations, and security controls.
• Ability to work independently in a fully remote environment, taking ownership of deliverables with minimal supervision.
• 1 or more years of professional experience in IT General Controls (ITGC), IT Audit, Technology Risk, Cybersecurity Risk, or IT SOX.
• Hands-on experience testing technology controls and evaluating control design and operating effectiveness.
• Demonstrated ability to collect, evaluate, and validate supporting control evidence.
• Proven capability to prepare clear, defensible testing documentation and workpapers.
• Knowledge of common IT control domains, including logical access, user provisioning, privileged access, change management, computer operations, and security controls.
• Ability to work independently in a fully remote environment, taking ownership of deliverables with minimal supervision.
Preferred Qualifications
• Prior IT SOX testing experience and exposure to cybersecurity maturity assessments.
• Familiarity with established cybersecurity, IT control frameworks, and GRC tools.
• Experience working alongside Internal Audit, external auditors, Information Security, or Technology Risk teams.
• Experience documenting control deficiencies and tracking remediation plans.
• Relevant professional certifications or progress toward certifications (e.g., CISA, Security+, CRISC).
• Prior IT SOX testing experience and exposure to cybersecurity maturity assessments.
• Familiarity with established cybersecurity, IT control frameworks, and GRC tools.
• Experience working alongside Internal Audit, external auditors, Information Security, or Technology Risk teams.
• Experience documenting control deficiencies and tracking remediation plans.
• Relevant professional certifications or progress toward certifications (e.g., CISA, Security+, CRISC).
Core Skills & Attributes
• Strong analytical, problem-solving, and risk-assessment skills with exceptional attention to detail.
• Excellent written and verbal communication skills to interact with control owners and program leadership.
• High accountability, self-sufficiency, and time-management capabilities to manage multiple assignments and meet deadlines.
• Professional demeanor with a strong commitment to producing high-quality workpapers.
• Strong analytical, problem-solving, and risk-assessment skills with exceptional attention to detail.
• Excellent written and verbal communication skills to interact with control owners and program leadership.
• High accountability, self-sufficiency, and time-management capabilities to manage multiple assignments and meet deadlines.
• Professional demeanor with a strong commitment to producing high-quality workpapers.
This is a remote position.
Established in 2004, Smart Tech Skills is a top technology and professional services firm specializing in innovative technologies.
Headquartered in Marlborough, MA, the company effectively addresses clients’ technology needs nationwide, making advanced technology management easier.
Headquartered in Marlborough, MA, the company effectively addresses clients’ technology needs nationwide, making advanced technology management easier.
(if you already have a resume on Indeed)
