IT Risk & Control Audit Specialist
PriceSmart · San Jose
Job description
About the role
The IT Risk & Control Audit Specialist evaluates technology risks and controls across the organization, focusing on audit readiness, control effectiveness, access, change management, data integrity, and finance‑supporting processes. The role partners with internal and external audit teams to ensure compliance with internal policies and regulatory requirements.
Key responsibilities
- Perform IT risk and control assessments, identifying inherent and residual risks and monitoring controls on a defined schedule.
- Conduct process and control reviews to evaluate design and operating effectiveness of key IT controls, identifying gaps and improvement opportunities.
- Apply IT audit fundamentals to review IT General Controls, user access, change management, data integrity, and related evidence.
- Coordinate with Internal Audit during annual IT reviews, handling information requests, validating evidence, and supporting walkthroughs.
- Manage external IT audit activities, ensuring evidence, deliverables, and timelines meet audit requirements.
- Administer access review campaigns for critical systems and applications, ensuring timely completion and documentation.
- Maintain the IT Risk and Control Matrix, mapping risks, controls, owners, frequencies, and evidence.
- Review new technology initiatives to identify applicable IT risks and support control implementation before deployment.
- Document control workflows, risk assessments, audit evidence, and remediation actions in an audit‑ready format.
- Monitor emerging technology risks, escalating material gaps and supporting practical remediation actions.
Required profile
- Experience performing IT risk and control assessments and monitoring key controls.
- Proven ability to conduct process and control reviews, identifying gaps and recommending improvements.
- Familiarity with IT General Controls, user access management, change management, and data integrity concepts.
- Experience coordinating internal and external audit activities, including evidence collection and walkthrough support.
- Ability to administer access review campaigns and maintain risk/control documentation.
- Strong analytical skills to monitor emerging technology risks and support remediation planning.
- Collaboration skills to work with Enterprise Risk Management, Internal Controls, Business Continuity, Finance, and IT stakeholders.
Required skills
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Costa Rica.
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 1 month ago
Expires 3 weeks from now
30 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
PriceSmart
San Jose