IT Audit, Senior Associate
Who we are looking for:
Are you a talented professional looking for a challenging and fulfilling opportunity to grow along with a global industry leader? Are you interested in identifying and helping to mitigate complex application and infrastructure risks? Do you want to be part of a global dynamic team that works hard, but has fun doing it? If so, then we may have the solution for you. Why this role is important to us:
The team you will be joining plays an important role in the overall success of the organization. Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. To make that happen we need teams like yours to help navigate employees and the organization as a whole. In your role you will strive for cutting-edge solutions, that are straightforward and scalable. You will help us build resilience and execute day to day deliverables at our best. Join us if making your mark in the financial services industry from day one is a challenge you are up for. What you will be responsible for:
As IT Auditor - IT Infrastructure and Application Professional - Senior Associate you will be
• Independent advisors-advising management on risks related to strategic initiatives and process and systemic changes
• Subject matter and controls experts-providing knowledge and experience in key risk areas
• Efficiency specialists-identifying inefficiencies in risk management and control design
• Problem-solving partners-looking ahead to help management envision future risks and opportunities Do you love thinking analytically? Are you passionate about using your technical knowledge to navigate complex business, operational and technology challenges? As a key member of the team, you will:
What we value:
- Work as part of an international team with global stakeholders in new and changing situations where there may not always be a readily apparent solution.
- Perform the planning, assessment, testing and issue validation phases of audits covering IT governance, systems infrastructure, information security, application controls, and operational activities.
- Perform independent and objective assessments of risks and controls to improve risk management practices.
- Assess systems and supporting controls for compliance with laws, regulations, company policies and meet business needs.
- Recommend control improvements to mitigate key risks.
- Influence change and provide insights on business initiatives, including system implementations.
- Prepare audit work papers to ensure compliance with the division's risk-based audit methodology.
- Have exposure to emerging technologies including crypto / blockchain
- Use your excellent writing skills to succinctly communicate complicated technical issues in business terms.
- Ability to manage complexity, to effectively prioritize multiple tasks and work independently in non-routine situations.
- Professional curiosity and willingness to learn new technologies and processes.
- Strong analytical, interpersonal, organizational, research, and communication (verbal and written) skills
- Good understanding of the role of first, second and third line of defense.
- Interest in obtaining or already holds industry recognized certifications (e.g. CISA, CISSP, CISM, Cloud+, etc.) and a willingness to continue to learn and grow.
- Fluency in English - written and spoken.
- Resiliency and Business Continuity Management
- Ability and willingness to travel up to 20%
Experience or interest in auditing technology-related areas such as:
- Enterprise security controls frameworks
- Enterprise application development models (i.e., waterfall, rapid prototyping, agile, etc.,)
- Perimeter/Internal Security Technologies (Firewalls, Intrusion Detection and Prevention Systems)
- Data Loss Prevention technologies and support processes
- Network Segmentation and Separation Solutions
- Identity and Access Management/Privileged Access Management/Adaptive Authentication Solutions
- Platform and Configuration Hardening Practices
- IT incident and problem management
- Threat Intelligence and Insider Threat Detection
- Vulnerability Scanning and Penetration Testing
- Security Incident and Event Management (SIEM) Technologies
- Cyber Incident and response
- Public Cloud Security
- Financial services operational processes and technology
- Automated business process controls
University degree in information systems, computer science, accounting or related field; advanced degree in information technology, cyber security or systems engineering preferred. About State Street What we do.
State Street is one of the largest custodian banks, asset managers and asset intelligence companies in the world. From technology to product innovation we're making our mark on the financial services industry. For more than two centuries, we've been helping our clients safeguard and steward the investments of millions of people. We provide investment servicing, data & analytics, investment
research & trading and investment management to institutional clients. Work, Live and Grow.
We make all efforts to create a great work environment. Our benefits packages are competitive and comprehensive. Details vary in locations, but you may expect generous medical care, insurance and savings plans among other perks. You'll have access to flexible Work Program to help you match your needs. And our wealth of development programs and educational support will help you reach your full potential. Inclusion, Diversity and Social Responsibility.
We truly believe our employees' diverse backgrounds, experiences and perspective are a powerful contributor to creating an inclusive environment where everyone can thrive and reach their maximum potential while adding value to both our organization and our clients. We warmly welcome the candidates of diverse origin, background, ability, age, sexual orientation, gender identity and personality. Another fundamental value at State Street is active engagement with our communities around the world, both as a partner and a leader. You will have tools to help balance your professional and personal life, paid volunteer days, matching gift program and access to employee networks that help you stay connected to what matters to you.