Sr. IT Auditor

Posted:
9/6/2024, 12:40:13 AM

Location(s):
Columbus, Ohio, United States ⋅ Ohio, United States

Experience Level(s):
Senior

Field(s):
IT & Security

McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve – we care.

What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow’s health today, we want to hear from you.

Job Title – Sr. IT Auditor

Working Location - Columbus Ohio (Hybrid)

Current Need

The Senior IT Auditor position at CoverMyMeds helps lead our efforts to ensure CMM has a comprehensive, world-class implementation of information security controls. You will help innovate an information security practice responsible for IT governance, risk, and compliance that makes it easy to do the right thing while enabling the unique, empowered culture at CoverMyMeds.

Position Description

The Senior IT Auditor will assist the Audit Director in assessment and presentation of information technology controls and audit of the company, including the integration of security and compliance perspectives into strategic planning, issue identification and remediation activities. This position will be continually learning from industry resources and real-world experience and improving the CoverMyMeds IT governance, risk and compliance program. They will help to build strategic goals and objectives and help drive them to completion which will include navigating other priorities, goals, and helping educate others on what security and compliance means to them.

Key Responsibilities

  • Lead and assist with the execution and maintenance of annual SOC2, SOC1, SOX, and HIPAA audits.

  • Serve as a subject matter expert on IT governance, risk, compliance, and security.

  • Be a strategic partner to control owners, second line of defense, and business leaders.

  • Partner with IT Control Owners to resolve control failures identified through risk assessments, internal/external audits, or information security assessments.

  • Document policies and procedures for Information Technology processes.

  • Apply problem-solving skills to enhance audited processes.

  • Collect and manage compliance evidence for internal and external inspections.

  • Educate and support associates on information security controls and compliance requirements.

  • Collaborate with technology teams to establish and document IT controls.

  • Assist business partners in planning responses to control deficiencies.

  • Oversee, monitor, and report on remediation activities for security and compliance issues.

  • Cultivate a culture of shared responsibility for security.

  • Mentor team members on information security and compliance best practices.

  • Advocate for continuous improvement across the organization.

  • Develop, track, and analyze metrics to measure success, making necessary adjustments.

Minimum Requirements: 7+ years of experience with IT Controls related to SOX, SOC, HIPAA and/or a combination of IT support focused on leading cross-functional teams.

Critical Skills

  • 7+ years of experience with IT Controls related to SOX, SOC, HIPAA and/or a combination of IT support focused on leading cross-functional teams.

  • Experience supporting customer and/or 3rd party (external) audit engagement.

  • Able to lead teams and complex projects, specifically audits, using both internal and external resources to accomplish goals.

  • High level of written and oral communication skills.

  • Strategic thinker, able to understand and help architect audit-ready technology and business processes.

  • Applies advanced principles, theories, and concepts in the areas of audit, IT governance, risk and compliance.

  • Contributes to the development of innovative principles and ideas to continuously improve the IT governance, risk and compliance activities and efficiencies of the team.

Additional Knowledge & Skills

  • Consensus builder, able to move both technical and non-technical people to action.

  • Experience communicating and presenting to external auditors and/or third parties.

  • Passionate about continuous learning and certification in industry best practices.

  • Ability to work and thrive in a highly creative, collaborative, and dynamic environment.

  • Experience reviewing and applying the NIST cybersecurity framework.

  • Ability to effectively communicate technical concepts to non-technical people including the creation of content and assets.

  • Due to extensive experience, willing and able to get involved in developing, mentoring or coaching others.

  • Being a Senior position, able to serve as organization spokesperson on specialized projects or programs.

  • Relevant certifications (e.g., CIA, CISA, CISSP, CRISC, PMP) or progress toward becoming certified; healthcare industry experience is a plus.

Education : Four-year technical degree or equivalent

Candidate must be authorized to work in the U.S, now or in the future, without the support from McKesson.

We are proud to offer a competitive compensation package at McKesson as part of our Total Rewards. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered. For more information regarding benefits at McKesson, please click here.

Our Base Pay Range for this position

$98,300 - $163,800

McKesson is an Equal Opportunity Employer

 

McKesson provides equal employment opportunities to applicants and employees and is committed to a diverse and inclusive environment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, age or genetic information. For additional information on McKesson’s full Equal Employment Opportunity policies, visit our Equal Employment Opportunity page.

 

Join us at McKesson!