Description of Major Duties:
• Coordinates and supports information technology audits conducted by internal and external oversight organizations, including GAAP/Single Audit, the Pennsylvania Auditor General, Attorney General, Bureau of Audits, and other regulatory entities.
• Reviews documentation and technical evidence to determine compliance with applicable laws, regulations, policies, and security standards.
• Evaluates information security and technology controls against established frameworks, including NIST Cybersecurity Framework (CSF), NIST Special Publication 800-53, ISO 27001, and Commonwealth security policies.
• Identifies control deficiencies, documents findings, and recommends corrective actions to reduce organizational risk.
• Assists business and technical stakeholders in preparing audit responses and collecting supporting evidence.
• Tracks audit findings, validates corrective actions and reports remediation status and residual risk to management.
• Supports development and maintenance of automated workstreams for audit management, compliance tracking, and evidence collection.
• Develops dashboards, metrics and executive reports regarding audit trends, compliance posture and remediation progress.
• Performs risk-based assessments to prioritize audit activities and evaluate control effectiveness.
• Assists in developing audit procedures, compliance documentation, metrics, and management reports.
• Participates in continuous improvement initiatives related to governance, risk management, and internal controls.
• Performs related work as assigned.