IT CPM Sr. Specialist - IT Audit and Controls-INF0001WS

Sorry, this job was removed at 2:24 p.m. (CST) on Monday, June 28, 2021
Find out who's hiring in Chicago.
See all Cybersecurity + IT jobs in Chicago
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.



Headquartered in the heart of downtown Chicago, CNA is a leading commercial and specialty insurer, offering a diverse range of insurance products including Workers Compensation, Property, General Liability, Professional Liability, Cyber Insurance, Surety, and Warranty. We are one of the world leaders in underwriting non-medical professionals, from lawyers and accountants to architects and management consultants.

Continuous Process Monitoring (CPM) Program

The CPM team’s goal is to monitor all IT processes and related controls and assure that controls are operating as intended and control failures are identified timely and communicated to key stakeholders for proper mitigation before they pose a risk to the organization. The CPM program has been developed within CNA’s first line of defense with the CPM activities embedded within IT processes and management-level controls. The program is implemented for controls in CNA’s process risk and control (PRC) framework as identified by control and process owners and other stakeholders.

The program also facilitates audits support for the CNA Technology organization. Regulatory related audits such as SOX, SOC1, HIPPA, NYDFS, State Examiners, OFAC, Privacy laws, etc.

Job Summary

Information Technology Sr. Specialist – IT Audit and Controls will assist in implementing and monitoring IT controls to meet regulatory, compliance and operational needs of the organization. The Senior Specialist will be responsible with operational and regulatory audit support and collaboration between Technology and Auditors (Internal and External) during an audit engagement. The work will include managing audits, evaluating internal controls, reviewing audit evidences prior to submission to the auditors, communicating audit issues to management, creating of memo supporting audit outcomes, identifying and evaluating emerging areas of organizational risk.

The Senior Specialist leads in monitoring the performance of these controls throughout the year to ensure they meet the agreed upon control objectives and address the necessary risks. The position will be responsible for implementing and reviewing controls periodically as well as providing detailed reports to control and process owners and the IT leadership. To make impactful difference, the results will be driven by taking initiatives, critical thinking, engaging and collaborating with stakeholders and leadership at all levels. The dynamic environment provides opportunities for consistent learning helping realize true potential and career growth.

The Senior Specialist will also be responsible with managing and following up on all open audit issues, tracking and reporting on remediation status to the executive leadership.

Essential Duties and Responsibilities

Performs a combination of duties in accordance with departmental guidelines:

· Provide oversight and coordination of the annual SOC / SOX audit engagement by serving as the liaison and point of contact between Technology, Internal Audit and External Audit. Engagement involves planning, day to day management of audit engagement activities, collaboration with various Technology Groups, Internal Audit, External Audit and Managed Service Providers, status update meetings, reporting and managing exceptions and remediation. Provide management with timely recommendations that reduce risks and monitor progress in implementing controls recommendation

· Conduct IT reviews of systems, applications and IT processes. Perform review of IT processes and controls under the oversight of the Director; including identifying areas where technology units should consider changes to improve efficiency. Execute various other reviews of IT management policies and procedures such

as change management, business continuity planning/ disaster recovery and information security to ensure that controls surrounding these processes are adequate.

· Provide Technology staff and Third party vendors appropriate guidance on IT risk management matters, particularly on applications, operations management, strategy and infrastructure security.

· Evaluate IT general computing controls and provide value added feedback. Test compliance with those controls.

· Serves as a primary driver of the communication of IT CPM change management processes and project management. Develops a systematic methodology for communicating results to ensure that key personnel are informed and can provide feedback. Prepare and report results to executives, process owners and other stakeholders.

· Proactively provides content associated with the education and awareness of policies standards control procedures and IT Operational responsibilities across our organization. Responds to needs and feedback accordingly.

· Detects issues related to the operation of in-scope controls to ensure the effective operation of IT processes and controls for audit purposes. Develops remediation action plans to enable IT Controls & Quality Governance Team to provide attestation of CPM Program Compliance; also responsible for reporting of common control procedures and effectiveness.

· Manage and follow up on open audit issues resulting from audit findings and periodically report and present to the executive leadership on the remediation status of the findings.

· Work closely with key business partners across the enterprise and ensure that second and third line of defense teams are informed of the outstanding risks.

Reporting Relationship

Typically reports to Director or above.

Skills Knowledge & Abilities

· Solid understanding of IT infrastructure, security and application controls, operating models, methodology and approaches. Expert knowledge of internal auditing, internal controls, risk management and understanding of internal control environments within IT and some business functions.

· Experience with multiple technology domains including aspects of Windows, Mainframe, Unix and/or database administration, software development and networking.

· Ability to multi-task on assignments, prioritize and deliver on routine tasks and assigned projects.

· Strong communication and interpersonal skills to work effectively and foster teamwork with peers on project teams and other functional areas inside and outside of IT along with the ability to communicate effectively with technical and non-technical audiences.

· Ability to work with little supervision on assignments requiring technical complexity and confirmation with minimal guidance. Ability to lead meetings with all level of managements.

· Maintain technical competence by ongoing training, seeking development opportunities and applying new knowledge to daily work assignments.

 

Education & Experience

· Bachelor’s Degree or equivalent with preferable concentrations in Management Information Systems, Computer Science, Information Security, Data Analytics or related discipline.

· Typically a 3+ related experience in public accounting, related industry or field.

· CISA, CRISC, CGEIT, CISSP certification is a plus.

· Exposure to IT standards (e.g. ISO 27001, PCI-DSS), frameworks (e.g. COBIT, NIST, ITIL), technical systems and emerging technologies.

 

 

*LI-KC1

 

 

EEO Statement: All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Job

 Information Systems

Primary Location

United States-Illinois-Chicago

Organization

 Tech-Quality and Governance

 

 

 

Read Full Job Description
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

Technology we use

  • Engineering
  • Product
  • Sales & Marketing
    • JavaLanguages
    • JavascriptLanguages
    • KotlinLanguages
    • PerlLanguages
    • PythonLanguages
    • RLanguages
    • SqlLanguages
    • jQueryLibraries
    • jQuery UILibraries
    • ReactLibraries
    • Node.jsFrameworks
    • SpringFrameworks
    • AccessDatabases
    • DB2Databases
    • Microsoft SQL ServerDatabases
    • MySQLDatabases
    • OracleDatabases
    • PostgreSQLDatabases
    • Google AnalyticsAnalytics
    • ConfluenceManagement
    • JIRAManagement
    • Microsoft ProjectManagement
    • SalesforceCRM
    • SendGridEmail
    • MarketoLead Gen

Location

Located in the heart of the loop, CNA’s headquarters are at 151 N Franklin. With close proximity to both L and Metra stations.

An Insider's view of CNA

How would you describe the company’s work-life balance?

Work-life balance has always been a priority for me. It always will be. CNA’s hybrid working model allows me to not only maximize collaboration with my peers but also take advantage of increased flexibility by combining remote and in-office work. I’m empowered to take control of my schedule based on what works best for me and my team.

Alison Massey

Agile Scrum Master Consultant

How does the company support your career growth?

Throughout my five-year career, I’ve seen CNA value creating thinking and continuous learning. My managers actively encourage me to pursue rewarding professional development opportunities. Those opportunities have had a direct impact on my career growth. At CNA, the opportunities are endless and your career aspirations matter.

Alaina Cole

Underwritting Specialist

What unique initiatives do you have that encourage innovation?

We have an Innovation program and team that designs processes to encourage creative thinking and capture ideas across CNA. In addition to collaborating with and learning from world-class technology partners, we also host events such as our Innovation Summit and Hackathon, which bring winning competition ideas to life in real products and services.

Keith Zhang

Architecture Consulting Director

What's the biggest problem your team is solving?

A primary focus of my team is reducing the time-to-market associated with machine learning models. By leveraging cutting-edge cloud services and streamlining processes, we’re enhancing the model development lifecycle. That enhancement allows us to use efficient, effective predictive analytics when making business decisions.

Ryan Gulden

Senior AI/ML Engineer

What are CNA Perks + Benefits

CNA Benefits Overview

One of the many advantages of working at CNA is the benefits program we offer you and your eligible dependents,
beginning on the first day of your employment. The program features a variety of plans that provide health care
benefits, well-being, disability and survivor protection, and 401(k) savings, among others. Below are highlights
of the offerings.

Culture
Volunteer in local community
Partners with nonprofits
Open door policy
OKR operational model
Open office floor plan
Flexible work schedule
Remote work program
Diversity
Dedicated diversity and inclusion staff
Diversity employee resource groups
Health Insurance & Wellness Benefits
Flexible Spending Account (FSA)
Disability insurance
Dental insurance
Vision insurance
Health insurance
Life insurance
Wellness programs
Financial & Retirement
401(K)
401(K) matching
Company equity
Employee stock purchase plan
Performance bonus
Charitable contribution matching
Child Care & Parental Leave Benefits
Generous parental leave
Family medical leave
Adoption Assistance
Vacation & Time Off Benefits
Generous PTO
Paid holidays
Paid sick days
Office Perks
Relocation assistance
Onsite gym
Professional Development Benefits
Job training & conferences
Tuition reimbursement
Lunch and learns
Online course subscriptions available

More Jobs at CNA

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about CNAFind similar jobs like this