Summary:
FirstBank Internal Audit provides independent, objective assurance and advisory services designed to add value and improve the organization’s operations. Internal Audit helps the organization accomplish its objectives by applying a systematic, disciplined, risk-based approach to evaluate and improve the effectiveness of governance, risk management, and control processes.
The Senior IT Internal Auditor is an intermediate Internal Audit contributor responsible for independently executing assigned IT audit sections, evaluating technology and security evidence, developing audit conclusions, supporting issue development, and contributing to clear, objective, evidence-based reporting, while providing non-supervisory guidance to Staff Auditors as assigned but without formal people-management responsibility.
Regulatory and Professional Standards Alignment:
This role supports FirstBank Internal Audit’s alignment with the Global Internal Audit Standards and applicable Federal Reserve supervisory expectations, including SR 13-1 / CA 13-1 and SR 03-5, by contributing to a risk-based, independent, objective, competent, and adequately documented internal audit function. For the IT Audit domain, responsibilities also consider applicable FFIEC Information Technology Examination Handbook guidance, including information security, architecture, infrastructure and operations, business resilience, Development, Acquisition, and Maintenance, cybersecurity, Technology Service Provider oversight, data governance, privacy, customer information safeguards, and related IT control expectations commensurate with role level.
Essential Duties and Responsibilities:
- Execute assigned IT audit engagements or audit sections, including information security, IT general controls, application controls, infrastructure, operations, cybersecurity, privacy, customer information safeguards, business resilience, data governance, Technology Service Provider oversight, third-party technology risk, Development, Acquisition, and Maintenance, project governance, and special audits, in accordance with Global Internal Audit Standards and FirstBank Internal Audit methodology.
- Perform risk-based IT audit procedures, including risk assessment, walkthroughs, process and control documentation, control testing, technical evidence evaluation, system-generated data analysis, configuration and log review, and documentation of results.
- Evaluate technology risks, control design, operating effectiveness, compensating controls, root causes, and improvement opportunities, and escalate potential findings and recommendations to Internal Audit leadership for review before discussion with business owners, as appropriate.
- Prepare clear, accurate, objective, constructive, timely, and evidence-based workpaper documentation, issue summaries, and draft report content that support IT audit conclusions and identify areas requiring corrective action.
- Apply strong working knowledge of IT risk and control concepts, audit methodology, banking technology operations, information security, cybersecurity, regulatory expectations, and financial services industry practices.
- Provide non-supervisory guidance to Staff Auditors on audit methodology, technology control testing, evidence sufficiency, documentation expectations, and issue development.
- Support IT audit planning activities, including preliminary risk identification, process scoping input, issue validation, follow-up activities, continuous monitoring, emerging technology risk awareness, and coordination with operational audit teams, as assigned.
- Maintain confidentiality of Bank, customer, employee, technology, security, and control information as required by law, regulation, professional standards, and Bank policy.
- Model sound IT audit judgment, communicate status and issues timely, support consistent workpaper quality, and help Staff Auditors understand methodology expectations without assuming formal supervisory responsibility.
- Perform other duties and responsibilities as assigned by Internal Audit leadership, consistent with the role’s senior auditor level, independence requirements, and FirstBank policies.
Education and Experience:
- Generally 4+ years of relevant audit, information technology, information security, banking, risk, compliance, technology operations, data analytics, or control experience may be considered based on demonstrated IT audit judgment, technology control evaluation skills, regulatory awareness, workpaper quality, and readiness to perform senior-level responsibilities.
- Bachelor’s degree in information systems, computer science, cybersecurity, data analytics, accounting, finance, business, risk management, or another role-relevant field required.
- CISA preferred; CIA, Security+, CISSP, CISM, CRISC, CDMP, CompTIA Data+, or other role-relevant financial services, technology, information security, risk, compliance, accounting, or control certifications are beneficial. Progress toward a relevant certification is encouraged for employees who have not yet obtained one.
- Financial institution, public company, regulated industry, IT operations, information security, internal audit, external audit, risk management, compliance, technology, analytics, or control experience is beneficial.
Skills and Abilities
- Ability to apply audit methodology in a banking technology environment, including evaluating IT process-level risks, control design and operating effectiveness, regulatory expectations, issue remediation, and evidence sufficiency across assigned IT audit areas.
- Strong working knowledge of IT general controls, cybersecurity risk, information security governance, privacy and customer information safeguards, data classification, access management, privileged access, change management, vulnerability management, incident response, backup and recovery, business continuity, disaster recovery, Technology Service Provider oversight, third-party technology risk, data governance, Development, Acquisition, and Maintenance, system implementation controls, cloud services, APIs, automation, zero trust concepts, and technology architecture themes.
- Ability to manage assigned work, deadlines, priorities, documentation quality, and escalation responsibilities in a changing technology and regulatory environment.
- Ability to effectively work both independently and as part of a team contributing to a positive and dynamic culture of partnership and collaboration.
- Ability to apply professional skepticism, sound judgment, integrity, confidentiality, independence, and objectivity in technology audit work.
- Ability to read, interpret, analyze, and evaluate policies, procedures, standards, laws, regulations, supervisory guidance, business process documentation, technical evidence, data, and control information.
- Ability to communicate clearly, professionally, and constructively with business partners, technology management, information security, risk management, Internal Audit leadership, external auditors, regulators, and other stakeholders.
- Commitment to continuous learning, audit quality, regulatory awareness, professional development, and FirstBank policies and procedures.
Learn more about this Employer on their Career Site
