Norfolk Southern IT / Information System Auditor in Atlanta, Georgia
The Information Systems Internal Auditor provides independent assessments of the control environment over IT infrastructure, systems, and data through the execution of risk analysis, control evaluation, and innovative audit testing procedures. The IS Auditor focuses on the secure and effective deployment and operation of technology in support of corporate objectives and regulatory requirements. IS Auditor activities include developing risk-based audit programs, identifying recommendations that help mitigate risks and provide continuous improvement in processes and controls, communicating results, and following up on issues reported.
Depending on the career level, some or all of the following key responsibilities will apply:
- Independently performs assigned audit testing and concludes on the effectiveness of controls, identifying control gaps and exceptions and evaluating the potential impact
- Demonstrates the ability to multi-task by clearly documenting the results of testing on more than one audit concurrently
- Prepares audit reports and work papers to ensure adequate documented evidence exists to support audit opinions and conclusions
- Conducts IT integrated audits with operational, compliance, financial, and investigative audit teams, as assigned
- Accurately interprets collected evidence to effectively identify, recommend, and report improvement opportunities for processes and controls
- As appropriate, identifies opportunities for continuous improvement related to the use of technology
- Prepares well-written and timely audit reports which communicate audit issues and related recommendations in both technical and non-technical terms to management
- Demonstrates development in technical and analytical skills to understand new and existing technologies, including cyber security, IT general controls and software development practices
- Demonstrates technical understanding of data analysis concepts and practices
- Develops an awareness of changes in IT audit practices, regulatory requirements, and IT Risk frameworks to understand their impact to Auditing (e.g. NIST Cyber, CSC, COBIT, ISO2700x)
Minimum Level: Less than 1 year
Preferred Level: 3-5 years
Preferred Level: Bachelor's Degree (Any)
- Computer Science, Information Systems, Business Administration, Accounting, Finance
Licenses / Certifications:
- Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP)
- Working knowledge of operational, compliance and IS auditing techniques
- Broad IT knowledge in infrastructure technologies, application development and support, and emerging technologies
Skills and Abilities:
- Communication Skills, Analyzing Problems, Behaving Professionally, Adaptive Thinking and Agile Learner
Shift Work: No
Weekend Work: No
Travel Required: 3 - 5 Days per Month
Norfolk Southern Corporation(NYSE: NSC) is one of the nation’s premier transportation companies. Its Norfolk Southern Railway Company subsidiary operates approximately 19,500route milesin 22 states and the District of Columbia, serves every major container port in the eastern United States, and provides efficient connections to other rail carriers. Norfolk Southern operates the most extensive intermodal network in the East and is a major transporter of coal, automotive, and industrial products.
We are a team of more than 25,000 employees working together to maintain our reputation as "The Thoroughbred of Transportation". As an industry leader, Norfolk Southern offers a competitive salary and an excellent benefits package.
Norfolk Southern is an equal opportunity employer including veterans and disabled.