Senior IT Audit Manager
Cleveland, TN - USA
Job Summary
This Sr. IT Audit Manager is accountable for planning organizing and staffing the examinations and evaluations of the adequacy and effectiveness of the organizations IT applications and related infrastructure for all domestic and international company operations. This position will work closely with the Corporate Audit Global Team and our external auditors throughout the annual SOX engagement. Additionally this position will ensure IT Audit and Financial Audit are properly aligned through broader transformative audit engagements. This position will be responsible for input on the annual IT audit plan identifying impactful and value-add projects to the organization and then subsequently managing the execution of those projects. This position will be viewed as a subject matter expert to the entire IT organization in the space of IT audit considerations IT controls and IT risks and their impact to the organization especially as it relates to digital transformation activities.
This position is responsible for the hiring and training of IT auditors to ensure that the technical proficiency and educational background is appropriate for the audits to be performed as well as assuring the promotability of staff members within the company. Additionally this position is responsible for assessing the resources / specialized skills needed within the IT Audit team to further expand the scope of work and impact the department can provide to the organization. This position is also responsible for developing and maintaining productive working relationships with company personnel assessing audit clients satisfaction and proactively maintaining contact with the audit client throughout the year.
This position is responsible for suggesting and implementing improvements to the Corporate IT Audit process. Improvements should focus on key IT risks emerging technology risks and providing value to the organization. The ability to provide assurance of quality audits and reports to meet audit standards demonstrate strong leadership and organizational skills develop action plans that include measurable achievements update IT audit plans frequently strong interpersonal skills and the ability to work with all levels of management is critical to the success of this position.
This position is not hybrid/remote and will be located at our Global Headquarters in Cleveland OH.
This position is also eligible for bonus based on performance and subject to the terms of the Companys applicable plans.
Because this role involves access to confidential financial information the Company has determined that a review of criminal history is necessary to protect the business and its operations and reputation and to provide similar protections for its clients and potential investments.
Responsibilities
CORE RESPONSIBILITIES AND TASKS
Execute annual Sarbanes-Oxley compliance program
Utilize strong partnerships with management to influence business and IT partners and ensure adequate control documentation is in place working to actively enhance relationships with key stakeholders.
Stay up to date on current guidance and methodologies; and proactively align with external auditors on any changes.
Implement best practices to streamline approach to reduce costs and improve efficiencies
Proactively seek out opportunities to drive efficiencies in this process while maintaining strong quality
Coordinate the audit of internal controls over financial reporting / ITGCs with internal stakeholders and external auditors
Partner and manage the relationship with external auditors to effectively assess ITGC application and infrastructure related controls
Oversee the completion of process walkthroughs and test of controls
Manage the accumulation and assessment of internal control deficiencies identified; and proactively partner with Management and external auditors in remediating / mitigating issues identified to limit interruption to the business
Manage and lead initiatives surrounding system implementations and related control considerations / documentation
Drive accountability with IT owners to further enhance education surrounding key controls and their related importance to the environment
Appropriately delegate the execution and detail review of workpapers to individuals on the team in an effort to best utilize efforts in higher-risk / impact areas
Develop a solid understanding of SWs divisions in-scope IT applications and broader business acumen in order to continuously identify opportunities for compliance improvement
Plan and execute international and domestic audits over IT applications and ERP systems assist in reviews over enterprise-wide business processes as well as plan and execute IT focused audits (i.e. cybersecurity ICS system conversions other one-off audits etc.).
Continue developing strong business relationships with key stakeholders across strategic IT areas throughout the various divisions / functions. Identify opportunities to act as a consultant to the audit client while strengthening the overall control environment and working to provide value-add cost savings and process / compliance improvement findings.
Provide guidance to assist Supervisors / Leads during the scoping / planning process to appropriately utilize critical thinking in developing a tailored audit program specific to the risks within the clients environment audit subject at hand. Further provide guidance to the team in high-risk areas which are to be emphasized in the audit scope.
Oversee the Leads in charge of the execution of fieldwork to drive effective and efficient procedures
Align with IT leadership on impactful findings and navigate the exit conference with local and corporate management.
Own internal audit reports and memos to ensure issues are clearly described and recommendations are
reasonable and in accordance with Company with Management to co-develop action plans that are clear concise and appropriately address the issue. Continue to partner with Management on the timely remediation of issues identified.
Obtain understanding around all components of system conversions to perform accurate SDLC assessments (i.e. data conversions key control mapping testing phases (i.e. SIT FUT UAT etc.) security design requirements etc.).
Manage Coach and Develop Team Members
Provide training to internal audit team as opportunities present themselves or training needs are identified. Further ensure to proactively train the team as IA requirements or external auditor requirements change.
Acquire and develop audit personnel with high potential for future growth within the Corporate IT Audit Department; or placement in other IT and/or supervisory positions throughout the Company
Evaluate skill set requirements / background needed as S-W Internal Audit requirements change in order to adapt with the current needs of the department.
Departmental Planning
Prioritize and set schedules and budgets for Direct Assistance work SOX Operational Internal Audits and other special projects.
Provide inputinto the preparation of an annual audit plan and complete a rolling IT Risk Assessment to assist in identifying value-add audit opportunities to the organization by utilizing an expansive knowledge of IT considerations and known areas/processes that are ripe for audit consideration. Work with Director Internal Audit to create the IT audit plan.
Identify ad hoc audit opportunities throughout the IT landscape to respond to emerging risks / requests from business and IT management.
Effectively communicate to appropriate audience professionally and timely including audit concerns changes to plans frequent communication with Director Internal Audit on progress issues etc.
Manage and participate in special assignments as deemed necessary by Senior Director Internal Audit; VP Corporate Audit Loss Prevention and Security; management; and/or the Audit Committee to provide senior management with the necessary levels of assurance.
Qualifications
POSITION REQUIREMENTS
Required:
Bachelors degree in Information Technology Management Information Systems Cybersecurity Accounting Finance
8 years of prior IT Audit work experience (strong preference of experience with Big 4 audit firm or public company internal audit team)
3 years of experience managing a team
Experience in leading SOX testing and audit related projects
Extensive experience with managing audit projects and working directly with external auditors and management resolving issues and improving processes
Must be legally authorized to work in the United States without sponsorship now or in the future for employment visa status
Must be at least eighteen (18) years of age
Preferred:
Advanced degrees or certifications (MBA CISA CISSP CPA CIA etc)
Advanced understanding of general accounting SOX COSO NIST COBIT or other audit frameworks
Prior experience in the Manufacturing Industry
Advanced experience with Databases (Oracle) Operating Systems (Linux Windows etc.) and broader IT Security matters
Travel: 10%
Required Experience:
Manager
About Company
At Sherwin-Williams, our purpose is to inspire and improve the world by coloring and protecting what matters. Our paints, coatings and innovative solutions make the places and spaces in our world brighter and stronger. Your skills, talent and passion make it possible to live this purp ... View more