The IT Audit, Cybersecurity & Risk Experienced Consultant role supports Baker Tillyβs Risk Advisory practice by helping clients assess and manage information technology risk across cybersecurity, governance, compliance, and internal controls. The position includes IT control assessments, internal audit execution, HITRUST engagements, and executive reporting in a client-facing environment.
Role Focus
In this hybrid role based in Southfield, MI, you will help clients identify and manage technology risks by applying industry frameworks, evaluating processes and controls, and communicating actionable findings. Work spans cybersecurity, IT strategy and governance, regulatory and compliance requirements, and business continuity.
Responsibilities
- Partner with client executives and management teams to understand business operations and help identify and manage financial and operational risks within business systems so technology risks are appropriately managed.
- Build knowledge of client businesses and industries through direct engagement while contributing across multiple areas of an engagement.
- Apply independent and strategic thinking to assess client systems and risks, and develop recommendations for business and process improvements aligned with client operations and objectives.
- Support clients with strategic business guidance, including assistance with implementing new processes and controls to address key risks.
- Assess, manage, and optimize information technology risk across cybersecurity, IT strategy and governance, regulatory and compliance requirements, and business continuity.
- Review clientsβ processes and controls against industry frameworks to identify gaps in design and execution, and communicate issues and recommendations.
- Assist with audit programs and the execution of internal audits and IT control assessments, including areas such as IT strategy and governance; IT operations, business continuity and disaster recovery; cybersecurity; third-party risk; ITGC and application controls; SOC reporting; HITRUST engagements; and regulatory and compliance requirements.
- Draft executive summaries and final reports for client delivery, and document and review engagement work papers using industry-accepted internal audit methodologies.
- Serve as a business advisor by building relationships and communicating effectively to deliver strong client service.
- Continue developing knowledge across technology environments, platforms, applications, and tools/utilities.
- Participate in external and internal education, training, and cross-training opportunities to support skill growth and ongoing career development.
- Use entrepreneurial networking skills to build relationships internally and externally with clients.
- Participate in team activities that encourage work-life balance.
Required Qualifications
- 4 year degree
- One (1) year of experience
- Bachelorβs degree in management/computer information systems, computer science, accounting information systems, computer engineering, industrial engineering, or related program.
- Excellent analytical, technical, and problem-solving skills with strong attention to detail.
- Exceptional verbal and written communication, collaboration, and time management skills.
Preferred Qualifications
- CISA, CISSP, CISM, CIA, or CPA certification(s)
- 1+ year(s) experience with IT audit or cybersecurity, with prior experience performing SOX and SOC audits preferred
- Experience performing HITRUST engagements preferred; open to candidates willing to obtain HITRUST Certification in the future
- Experience as a client-serving professional for a consulting firm desired
- Cloud audit experience and certifications preferred
Tools and Technologies
- HITRUST
- HITRUST Certification
- ITGC
- SOC reporting
- SOX
Compensation and Benefits
Salary range: USD 52,779 - 99,530 per yearly.
- In Minneapolis, MN: $70,000 to $99,530
- In Milwaukee, WI: $52,779 to $94,790
- In Southfield, MI: $70,000 to $99,530
Actual compensation is influenced by factors including applicant skills, prior experience, qualifications, degrees/certifications, work arrangements, and geographic location. A comprehensive compensation and benefits package is available to eligible employees.
Education and Experience
This role requires a 4 year degree and one (1) year of experience.