Analyst IT Auditor
Makati City - Philippines
Job Summary
The IT Audit & SOX Compliance Analyst will be a key member of Hersheys Global Internal Audit team supporting the organizations efforts to maintain a strong control environment ensure SOX 404 compliance and strengthen IT and cybersecurity risk management practices across global operations.
In this role you will partner with business finance and IT stakeholders worldwide to assess the effectiveness of IT General Controls (ITGCs) application controls cybersecurity controls and financial reporting processes. You will participate in global audit engagements control readiness assessments SOX activities and special projects related to technology risk cybersecurity and operational assurance.
This is a fully remote position based in the Philippines. Occasional office presence may be required when senior leadership or executive management visit the local office. The role follows a mid-shift schedule (2:00 PM to 11:00 PM) and may require up to 5% international travel.
- Execute SOX 404 testing for IT General Controls (ITGCs) and application controls across assigned business processes and functions.
- Partner with Internal Controls teams and business stakeholders to provide guidance on control execution documentation quality evidence requirements and remediation plans.
- Support quarterly and annual SOX compliance activities including walkthroughs readiness reviews management assistance requests and coordination with external auditors.
- Serve as a resource for SOX enablement tools such as Workiva and ServiceNow providing support and guidance to business users.
- Evaluate the readiness and effectiveness of key IT General Controls and application controls.
- Identify risks impacting financial reporting governance business continuity cybersecurity and regulatory compliance.
- Collaborate with IT and business stakeholders to understand processes assess controls communicate findings and recommend practical remediation actions.
- Maintain audit project plans and provide timely updates on project progress risks and dependencies.
- Prepare concise executive-level reporting to communicate key risks and recommended improvements.
- Participate in global IT audit engagements including infrastructure security application security vulnerability management and cybersecurity reviews.
- Support Internal Audits annual IT risk assessment process by identifying emerging technology and cybersecurity risks.
- Execute audit procedures using recognized frameworks such as COBIT COSO and NIST.
- Document audit work in accordance with IIA standards and internal audit methodology.
- Develop recommendations that strengthen controls and mitigate identified risks.
- Assess the design and operating effectiveness of controls related to:
- User access management
- Segregation of duties
- Change management
- Operating system and database security
- Interface controls
- Data integrity and transmission controls
- Third-party service provider risk management
- Prepare audit findings and reports for management and senior leadership.
- Support special projects including cybersecurity assessments system implementation reviews third-party risk reviews data analytics initiatives and other management requests.
- Bachelors Degree in Accounting Information Technology Information Systems Computer Science Cybersecurity or a related field.
- Minimum of 2 years of experience in IT Audit Cybersecurity Audit IT Compliance SOX 404 testing Internal Audit or related areas.
- Experience performing IT controls testing risk assessments audit procedures and control evaluations.
- Exposure to system implementation reviews and enterprise technology environments is preferred.
- Strong understanding of:
- IT General Controls (ITGCs)
- Application Controls
- SOX 404 compliance and testing
- Risk and control frameworks
- Working knowledge of COBIT COSO NIST or similar frameworks.
- Experience with ERP systems such as SAP Microsoft Dynamics NetSuite or similar platforms is an advantage.
- Ability to prepare audit documentation and communicate findings effectively.
- Strong preference for CISA (Certified Information Systems Auditor).
- CPA (Certified Public Accountant) highly preferred.
- Additional certifications such as CIA CRISC or other relevant audit and risk credentials are advantageous.
- High integrity and strong professional ethics.
- Excellent communication and stakeholder management skills.
- Strong analytical thinking problem-solving and decision-making abilities.
- Ability to independently manage multiple priorities in a global environment.
- Strong collaboration and influencing skills with stakeholders across all organizational levels.
- Commitment to continuous learning and professional development.
- Flexibility to work in a mid-shift environment and support a global business.
This role performs assigned audit tasks and recurring processes that support the evaluation of financial operational and basic IT controls. The position follows established procedures to complete testing gather evidence and document results under general supervision. It identifies routine issues within defined audit areas and prepares clear structured workpapers. The role contributes to audit planning and risk assessment by compiling information and supporting analysis.
1. Execute Assigned Audit Testing Across Financial Operational and IT Controls
The role performs defined audit and SOX 404 testing steps by strictly following established procedures. It gathers evidence through walkthroughs and validation activities without modifying test design. It documents outcomes clearly to support senior reviewer evaluation.
2. Prepare Workpapers and Organize Documentation for Reviewer Evaluation
The role prepares accurate workpapers that detail testing performed evidence obtained and initial results. It identifies routine issues such as process deviations or missing documentation. It organizes materials to support the development of audit observations by senior team members.
3. Compile Data to Support Risk Assessments and Planning
The role collects data and performs preliminary reconciliation activities to support risk assessment of financial operational and IT processes. It identifies recurring issues or exceptions that may inform later stages of testing. It compiles information into structured formats for use by senior auditors in audit planning.
4. Assist With Fraud Detection and Compliance Testing Under Guidance
The role performs assigned steps to identify anomalies exceptions or deviations from compliance requirements. It flags potential indicators of fraud and escalates them to senior auditors for further evaluation. It documents findings to support additional testing or review.
5. Support Follow-Up and Remediation Validation Activities
The role assists with follow-up testing to determine whether corrective actions were implemented as designed. It follows established procedures to validate updated controls or processes within assigned areas. It summarizes results for senior team members to incorporate into broader remediation analyses.
1 years
Required Experience:
IC
About Company
Here at Hershey, our purpose is to make more moments of goodness for consumers around the world.