Senior Auditor, Global IT Audit
Shanghai, CHINA IT development
Job description
JOB DESCRIPTION:
WHAT YOU’LL DO
· Lead and execute Information Systems audits throughout Abbott's international and domestic organizations.
· Assess the design and development of security solutions and their adherence to applicable policies and comply with information security requirements.
· Prepare and present audit findings to senior management.
· Maintain comprehensive historical audit work paper documentation that fully supports reported audit results, leveraging established department tools and standards.
· Proactively communicate with key stakeholders regarding audit status, findings and other relevant issues.
· Stay abreast of current and emerging security risks. Research new technologies, understand existing processes, and reference recognized standards and frameworks.
· Work collaboratively with others on the Corporate Audit team to proactively assess organizational IT risks and ensure effective audit coverage.
· Identify control gaps and other areas of heightened risk exposure related to governance, risk management and internal controls within IT processes.
· Design and deliver achievable meaningful recommendations for management to mitigate the identified risks.
EDUCATION AND EXPERIENCE YOU’LL BRING
Required
· BA/BS degree in Business, Computer Science, Management Information Systems or related field, or equivalent practical experience.
· 3-5 years of related experience with a top-tier consulting or public accounting firm in one of the following two areas required:
· Execution of Information Systems audits, including Application, Platform or General IT Controls;
· Conducting information security assessments or implementing information security controls.
· Strong interpersonal and communication skills in English are required.
· 45-70% travel to Abbott's International and Domestic locations required.
Preferred
· Experience with auditing major ERP systems (i.e. SAP, BPCS, Oracle)
· Experience with auditing IaaS, PaaS, SaaS services and solutions
· Deep insight of best practice standards and frameworks, such as ISO 27001/2 and NIST.
· Understanding of network and system security technology and practices across major-computing areas.
· Experience with Technology Risk Management / IT Audit function in Enterprise organizations.
· Certifications such as CISPP, CHPS, CISA, CISSP, CISM, CRISC, CIPP.
· Manufacturing and/or international business experience.
· Foreign language skills.
The base pay for this position is
N/A
In specific locations, the pay range may vary from the range posted.
JOB FAMILY:
Information Risk & Quality Assurance
DIVISION:
FIN Corporate Finance
LOCATION:
China > Shanghai : 388 W. Nanjing Road, Ciros Plaza
ADDITIONAL LOCATIONS:
WORK SHIFT:
Standard
TRAVEL:
Not specified
MEDICAL SURVEILLANCE:
Not Applicable
SIGNIFICANT WORK ACTIVITIES:
Not Applicable