Summary
The Specialist, IT Risk and Compliance is responsible for ensuring the IT Controls are working as designed and Compliance is met. The incumbent is able to interact with internal and external stakeholders and provide support and guidance around IT policies, risk and compliance.
Detailed Description
Performs tasks such as, but not limited to, the following :
- Maintains IT SoX controls testing monitoring based on the IT SoX requirements.
- Participates in the IT Risk assessments around data in scope for SoX and Crown Jewels
- Provide guidance on IT controls improvements and implementation, assisting with the IT controls updates and re-design
- Participates on IT compliance projects and ensures team members are provided with timely and accurate project information and status updates.
- Participates in the audit process - enforces compliance measures to ensure audit readiness and assists internal and external auditors with the audits.
- Leadership - provides performance feedback on team members as well as instructs and supervises the work of IT Student Interns.
- Assists with policy and process changes to ensure the documents are up to date
- Interfaces with the business and IT teams where required to apply IT controls and / or improvements to the existing IT controls.
Knowledge / Skills / Competencies
In-depth knowledge of the IT General Controls framework process.Excellent technical knowledge in specialized domains.Knowledge of team budget and tracking mechanismsAbility to provide assistance around ITGC to individuals outside the immediate work unit / team.Knowledge of Celestica's technology, business and IT strategies.Knowledge of IT analysis, design and development.Proficient in IT SecurityProficient in Risk Mitigation and Business ControlsProficient in Data Management and AnalyticsProficient in Delivering Initiatives within the Operating ModelIntermediate level of understanding in Project ManagementIntermediate level of understanding in Architecture and Solution IntegrationProficient in Business PartneringIT Penetration TestingProficient in IT Risk ManagementProficient in IT SoX ComplianceIT Security ArchitectureIT Compliance Standards and best practicesAbility to work in a team environmentChange Management and project management skillsExcellent resource management and prioritization skills.Excellent analytical skillsExcellent verbal and written communication skillsKnowledge of IT SoX audit framework and requirementsKnowledge of IT audit procedures and techniquesPhysical Demands
Duties of this position are performed in a normal office environment.Duties may require extended periods of sitting and sustained visual concentration on a computer monitor or on numbers and other detailed data. Repetitive manual movements (e.g., data entry, using a computer mouse, using a calculator, etc.) are frequently required.Typical Experience
4 to 6 years of relevant experience.Typical Education
Bachelors Degree or consideration of an equivalent combination of education and experience. Up to 6 years of experience with IT general controls or / and security best practices.Available security courses around security and compliance. Working towards CISO certificationEducational Requirements may vary by Geography.Notes
This job description is not intended to be an exhaustive list of all duties and responsibilities of the position. Employees are held accountable for all duties of the job. Job duties and the % of time identified for any function are subject to change at any time.
Skills Required
Risk Mitigation, Data Management, itgc, It Security