Senior Technology Risk Auditor
DICK'S Sporting Goods · Coraopolis, PA · 3 wk ago
On-siteAccountingFull-time
About the Role
As Dick’s Sporting Goods continues to grow and invest in its technology ecosystem, we’re expanding our Internal Audit team with several new Technology Internal Audit roles. These positions are part of our ongoing focus on strengthening our partnership with Technology to provide assurance and insights as they build for what’s next. The Senior Technology Risk Auditor will be a key member of the Internal Audit department and will evaluate the effectiveness of internal processes and controls to mitigate technology, security, and business risks.
Responsibilities
- Technology and Integrated Audits
- Performs general technology and integrated audits, with a focus on infrastructure, cloud environments, application audits, application controls, and/or interface controls.
- Performs risk assessments and documents processes for audit areas.
- Identifies relevant risks to the applicable audit and determines the extent of testing procedures.
- Partners with auditees to document process and data flows for areas under audit.
- Schedules and holds walkthrough meetings with auditees.
- Drafts request lists for audits and manages requests, including follow-ups.
- Executes audit fieldwork to consider inherent risks of the processes audited.
- Assists in root cause analyses and exposure checks for issues identified.
- Communicates with audit contacts on requests, follow-up questions, and observations.
- Develops or strengthens relationships with auditees.
- Communicates audit results and recommendations for improvement through formal reports and presentations.
- Implementation Audits
- Performs the above activities for system implementations and technology modernization programs, focusing on agile development methodologies, development controls, program management, integration, data conversion/validation, and testing controls.
- Sarbanes-Oxley (SOX) and Internal Control Testing
- Interacts with auditees to understand technology processes and internal controls.
- Executes defined test steps to evaluate controls, including technology general controls, application/interface, entity-level, and enterprise risk management.
- Prepares exception support and examples for findings and improvement opportunities.
- Performs detailed audit testing, including root cause analyses, and assesses exposure or residual risk.
- Communicates audit results and recommendations for improvement to management.
- On-Site Store and Distribution Center Audits
- Performs on-site physical inventory observations and other audit procedures at various stores.
- Assists the financial/operational audit team in performing Distribution Center audits.
- Communicates audit findings and recommendations for improvement to management via audit reports and closing meetings.
Requirements
- Bachelor's Degree in Information Systems Management, Data Science, Cybersecurity, or Audit.
- 3-5 years of experience, including 3+ years of technology audit, cybersecurity, or risk experience; public accounting or consulting experience preferred.
- Understanding of Technology Risk Assessment, SOX, general technology controls, system implementation risks/controls, data governance, cybersecurity controls, and privacy risks.
- Experience auditing in various technology environments: Azure, Windows, Unix, Oracle, SQL Server Database, and/or iSeries.
- Technical audit knowledge of infrastructure, cloud, application controls, interface controls, control frameworks (e.g., PCI DSS, NIST, COSO), and development methodologies.
- Ability to perform root cause analysis and understand risk exposure.
- Proven ability to adapt to change.
- Excellent relationship-building skills with a strong client-service focus.
- Ability to travel up to 15% of the time.
Virtual Requirements
- Cameras must be on during all virtual interviews.
- AI tools are not permitted to be used by the candidate during any part of the interview process.
- Offers are contingent upon a satisfactory background check, which may include ID verification.