ETRA Principal Technology Risk Analyst, External Audit

3 months ago


Durham, United States Fidelity Investments Full time
Job Description:

The Role

The External Audit Center of Excellence within Fidelity's Enterprise Technology Risk and Analytics (ETRA) group is seeking a passionate, driven, and experienced professional to help us oversee the technology areas of external audit engagements. You will enhance and run the external audit oversight program activities focused on key technology areas including DevOps, Cloud and Technology Operations. In addition, you will perform proactive risk assessments and develop control strategies for emerging technologies including AI/Machine Learning and Snowflake data services. To accomplish this, you will work closely with technology support teams, Enterprise Cybersecurity (ECS), Enterprise Infrastructure (EI), Cloud and Platform Engineering (CAPE), BU Technology partners, BU Operations Risk, and Fidelity's external auditors. The role can be based in Merrimack, Boston, Smithfield, North Carolina, or Westlake, and will report to the External Audit Center of Excellence Lead.

The Team

External Audit Center of Excellence oversees the management and execution of technology audit engagements (e.g., SOC 1, SOC 2, control attestations) for the Enterprise. External audit certifications are critical to Fidelity's institutional businesses, and our key focus is protecting the interests of our clients, customers, and Fidelity's brand by overseeing the effectiveness of technology controls through successful completion of external audit certifications. The CoE collaborates closely with the business units, technology leaders and operational risk teams develop best in class standards and practices for external audits and build the roadmaps for future technology and business requirements.

The Expertise and Skills You Bring
  • 5-9 years' experience in information technology auditing, information technology risk, cyber security, or controls assurance roles
  • Bachelor's degree in Computer Science, Information Systems, Technology, or a related field of study preferred
  • Demonstrated technical abilities in multiple areas including technology infrastructure and application controls, cloud, cyber security, and access management
  • Experience or knowledge of CI/CD technologies, automated code build and deployments pipelines/orchestration solutions
  • Experience performing risk assessments, control assessments, IT Audits or implementing Cybersecurity controls for large scale financial service organizations
  • Experience supporting or conducting SOC 1 or control attestation audit engagements preferred but not required
  • Professional technology risk certification (CISSP, CISA, CISSP, CRISC, CISM) and/or Cloud Certification(s) (CCSP, CCSK, AWS) preferred
  • Your love of solving complex problems, and comfort with ambiguous situations, and your ability to help solution innovative ways to mitigate risk and develop controls using your analytical and critical thinking skills
  • Your process orientation and understanding of operations and technology enabling you to provide support in the analysis, development, and monitoring of controls
  • Experience with Cloud security and controls and cloud technology environments (AWS/Azure, PaaS, SaaS)
  • Knowledge of industry standards, frameworks, and methodologies, such as SOC 1, SOC 2, ISO27001, HITRUST
  • You have excellent verbal and written communication skills enabling you to prepare and present findings clearly and concisely
  • You demonstrate a proven sense of ownership, accountability, and a commitment to achieving objectives
  • Your ability to build and maintain collaborative working relationships to craft and assist in the execution of appropriate controls design and monitoring
The Value You Deliver
  • Leading external auditor readiness engagements and readiness assessments and providing timely status updates to management
  • Planning and coordination of audit cycles with external auditors and internal stakeholders
  • Facilitating requests from external auditor and monitoring to ensure timely completion
  • Performing technology risk assessments and developing control strategies, including documenting controls, identifying potential gaps and/or inconsistencies and making sound recommendations for improvement and/or mitigation.
  • Providing technical assistance on risk related systems issues, and serving as a liaison with technology and risk teams to track external audit findings, perform issues follow-up, consulting and action plans with owners and issue resolution
  • Assessing the various information technology risks that the business faces in its operations and implementing action plans, policy and procedural changes for risk avoidance and mitigation.
  • Evaluating control maturity by performing control design and operating effectiveness reviews and peer reviewing as needed.
  • Assist with conducting Cloud Risk assessments and readiness reviews for applications and workloads migrating to the public Cloud environment.


Certifications:

Category:

Information Technology

Fidelity's working model blends the best of working offsite with maximizing time together in person to meet associate and business needs. Currently, most hybrid roles require associates to work onsite all business days of one assigned week per four-week period (beginning in September 2024, the requirement will be two full assigned weeks).

  • Durham, United States Fidelity TalentSource LLC Full time

    Job Description:Position Description: Performs end-to-end analysis and design of participant portfolio Web applications for Workplace investing Netbenefits applications. Provides analysis leadership on complex systems analysis projects, often across subsystems and companies, in a matrix organization. Consults with business users to develop recommendations...

  • Portfolio Risk Analyst

    3 months ago


    Durham, United States Self-Help Full time

    WHO We Are: Self-Help started in 1980 with a focus on economic inequality, especially in communities that have faced systemic barriers in building wealth. At the core of what Self-Help does is a drive to create and protect ownership and economic opportunity. In other words, we're committed to economic justice! Economic Justice means that all communities...


  • Durham, North Carolina, United States The Clorox Company Full time

    Position Overview The Internal Audit Assistant Manager serves as a vital risk management partner, dedicated to aiding the International business unit in recognizing and addressing a diverse array of risks. This role encompasses: Business Risks: Identifying potential threats to operational efficiency and effectiveness. Financial Risks: Evaluating financial...

  • Cybersecurity Analyst

    1 month ago


    Durham, United States Latino Credit Union Full time

    Job DescriptionJob DescriptionDescription:The Cybersecurity Analyst will safeguard LCCU's enterprise networks, systems, and applications against cyber threats. Will play a critical role in the security and integrity of LCCU's digital assets, ensuring the trust and confidentiality of LCCU's sensitive data and assets. Cybersecurity Analyst will...

  • Accountant II

    2 weeks ago


    Durham, United States North Carolina Central University Full time

    Working Title Accountant II (Financial Analyst)Position Number 600691Appointment Type Permanent - Full TimeTenure Track NoFTE 1 = 40 hours/week, 12 monthsIf time limited, duration datePosition OverviewPrimary Function of Organizational UnitThe Comptroller’s Unit (CU) is an accounting organization that performs detailed analysis and compiles the financial...


  • Durham, North Carolina, United States The Clorox Company Full time

    About The RoleThe Assistant Manager Internal Audit is a trusted risk advisor charged with supporting the International business unit in identifying and managing a wide range of business, financial, technology, compliance, and operational risks.Key ResponsibilitiesSupport the International business unit in identifying and managing business, financial,...

  • Analyst, IT

    3 weeks ago


    Durham, United States tapwage Full time

    School of Medicine Established in 1930, Duke University School of Medicine is the youngest of the nation's top medical schools. Ranked sixth among medical schools in the nation, the School takes pride in being an inclusive community of outstanding learners, investigators, clinicians, and staff where interdisciplinary collaboration is embraced and great...


  • Durham, United States Cree Full time

    Internal Audit Leader Position Overview: As the Internal Audit Leader, you will be the guiding force reporting to the Audit Committee of the Board of Directors, partnering closely with the CFO to navigate the intricate landscape of our operations and financial records. Your mission? To uncover discrepancies, enhance controls, and drive meaningful change...

  • Analyst, IT

    3 weeks ago


    Durham, North Carolina, United States tapwage Full time

    School of MedicineEstablished in 1930, Duke University School of Medicine is the youngest of the nation's top medical schools. Ranked sixth among medical schools in the nation, the School takes pride in being an inclusive community of outstanding learners, investigators, clinicians, and staff where interdisciplinary collaboration is embraced and great ideas...


  • Durham, United States Latino Community Credit Union Full time

    The Cybersecurity Analyst will safeguard LCCU’s enterprise networks, systems, and applications against cyber threats. Will play a critical role in ensuring the security and integrity of LCCU’s digital assets, ensuring the trust and confidentiality of LCCU’s sensitive data and assets. Sr. Information Security Analyst works closely with the management,...


  • Durham, North Carolina, United States Self-Help Full time

    About the RoleWe are seeking a highly skilled Portfolio Risk Analyst to join our Durham team at Self-Help. As a key member of our Commercial Lending Asset Quality team, you will play a critical role in reviewing the credit risk of assigned loan portfolios through analysis and relationship building.Key ResponsibilitiesAnalyze the risk for assigned loan...


  • Durham, North Carolina, United States City of Durham, NC Full time

    Salary: $65, $101,920.00 Annually Location: Durham, NC Job Type: Full time with benefits Remote Employment: Flexible/Hybrid Department: Public Works Position OverviewWork, Serve, Thrive. With the City of DurhamAdvance your career while contributing positively to the community. Compensation Range: $61,450 - $87,000 Working Hours: 7:30 a.m. - 4:00 p.m. The...


  • Durham, North Carolina, United States City of Durham Full time

    Position Overview:The City of Durham is seeking a dedicated Senior Systems Analyst to enhance our Water Management Department. This role is pivotal in ensuring the seamless operation of our technology systems that support essential water and sewer services for our community.Key Responsibilities:- Provide expert analysis and project management for technology...


  • Durham, North Carolina, United States Cree Full time

    Job DescriptionInternal Audit LeaderPosition Overview:As the Internal Audit Leader at Cree, you will be the guiding force reporting to the Audit Committee of the Board of Directors, partnering closely with the CFO to navigate the intricate landscape of our operations and financial records. Your mission is to uncover discrepancies, enhance controls, and drive...


  • Durham, United States Fidelity TalentSource LLC Full time

    Job Description:Position Description:Develops and maintains automated tests and in-house software utilities through hand-coded test automation, using SQL, XML, HTML, JavaScript, Java, and Python. Tests distributed applications at multiple layers of the technology stack, using Web Services testing tools and frameworks -- Junit, TestRunner, Selenium (TestNG),...


  • Durham, United States Fidelity TalentSource LLC Full time

    Job Description:Position Description: Develops and maintains automated tests and in-house software utilities through hand-coded test automation, using SQL, XML, HTML, JavaScript, Java, and Python. Tests distributed applications at multiple layers of the technology stack, using Web Services testing tools and frameworks -- Junit, TestRunner, Selenium (TestNG),...


  • Durham, United States Crescens Full time

    Job Title: Disaster Recovery Analyst Location: Durham ,NC Duration: 11+ monthsDescription : Our client seeks a contract resource to act in the role of Disaster Recovery Analyst. This role is responsible for developing, implementing, maintaining, communicating, and managing the governance and execution of the business continuity disaster recovery management...


  • Durham, United States Fidelity TalentSource LLC Full time

    Job Description:Position Description:\u00A0\u00A0Works with architect team to design and develop the web application -- e2e flow. Develops front -end applications using Angular, Bootstrap, and other UI rich components -- Tree table and live rate bar. Develops REST API's in Java and .Net Core to perform CRUD operations from UI using Spring Boot with Tomcat....


  • Durham, United States Fidelity TalentSource LLC Full time

    Job Description:Position Description:\u00A0\u00A0Works with architect team to design and develop the web application -- e2e flow. Develops front -end applications using Angular, Bootstrap, and other UI rich components -- Tree table and live rate bar. Develops REST API's in Java and .Net Core to perform CRUD operations from UI using Spring Boot with Tomcat....


  • Durham, North Carolina, United States Eli Lilly and Company Full time

    At Lilly, we unite caring with discovery to make life better for people around the world. We are a global healthcare leader headquartered in Indianapolis, Indiana. Our employees around the world work to discover and bring life-changing medicines to those who need them, improve the understanding and management of disease, and give back to our communities...