What are the responsibilities and job description for the IT Auditor position at Lamar University?
JOB DESCRIPTION/RESPONSIBILITIES:
- Plans and performs IT audits to:
- assess whether internal controls over information resources and related technology are adequate to ensure that confidential data (student, academic, financial, and operational) is protected from unauthorized use, access, or manipulation;
- determine whether the information technology infrastructure is adequately protected from intentional or unintentional access, loss, damage, or destruction;
- determine whether the governance, risk management, and control processes over information resources and related technology facilitate the production of reliable financial, academic, and operating information;
- identify the effective extent to which information resources and related technology can be recovered in support of the continuity of operations in the event of a business disruption; and
- measure the level of compliance involving information resources and associated technology with TAC 202, FISMA, NIST, FERPA, HIPAA, PCI, and other applicable state and federal requirements, industry standards, and best practices.
- Identifies risks, develops recommendations to mitigate risks, prepares organized, accurate and competent work papers that clearly document and support conclusions regarding audit objectives, and facilitates the communication of audit results through preparing written draft reports and making oral presentations to management.
- Performs special projects and consulting activities as needed.
- Assists with the administration of the Internal Audit file server.
- Engages in frequent contact with other Office of Internal Audit personnel, University personnel, TSUS personnel, and personnel at other state agencies.
- Performs other related duties as assigned.
- Working Conditions: Normal office environment; occasional daytime travel between office and campuses; less than five percent (5%) overnight travel (training, conferences, etc.). If telecommuting arrangement is established, travel to the Lamar components for one week at a time is expected quarterly with more frequent travel if deemed necessary.
- Bachelor’s degree with a major in management information systems, computer science, accounting, or related financial or information technology discipline.
- Bachelor’s degree in another field with three (3) years of experience in information technology/systems or management information systems may be substituted.
Additional Desired Qualifications:
- Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA), Certified Information Systems Security Professional (CISSP), Certified in Risk and Information System Control (CRISC) or Certified Public Accountant (CPA).
- Advanced degree in information systems, accounting, or related disciplines.
- A minimum of four (4) years IT auditing experience or related industry experience.
OTHER SPECIFICATIONS:
- Strong analytical, organizational, written/verbal communication, interpersonal, and relationship building skills.
- Proven ability to work with all levels of management and staff.
- Ability to converse with IT personnel and communicate technical information to non-technical audiences.
- Strong project management skills.
- Proficiency with the Microsoft Office productivity suite.
- Proven ability to work independently and as part of a team.
- Working understanding of fundamental information technology control concepts.
- Ability to learn and assimilate new information systems and applications quickly.
- Solid employment and/or academic performance history.
- Experience auditing information technology in higher education or in Texas state government.
- Experience in application control audits and a familiarity and understanding of management information systems.
- Versed in the application of professional auditing standards.
- Working knowledge of Texas statutory requirements applicable to public universities.
- Working knowledge of NIST 800.53 Information Technology Controls.
- Exposure to Texas Administration Code (TAC) 202.70 – 202.76.
- Familiarity and experience in using TeamMate or similar electronic work paper system.
- Working knowledge of Active Directory.
- Experience with Banner ERP.
- Working knowledge of server management.
- Experience in evaluating multiple server operating systems (Windows and Linux environments).
- Exposure to computer forensics and analysis.
- Experience using data analysis software (ACL, IDEA, TeamMate Analytics, etc.).
- Familiar with relational and non-relational database administration.
- Experience with Oracle and/or MS SQL.
- Experience writing and reading SQL scripts to extract data.
- Experience in developing reports for data extracts and ‘continuous monitoring’.
- Experience in network management controls encompassing both wired and wireless environments, including all associated devices (firewalls, routers, switches, etc.).
- Familiarity with various network management monitoring applications.
- Familiarity with controls over website development and content management systems.
- Other relevant industry experience.
INFORMATION ABOUT THE TEXAS STATE UNIVERSITY SYSTEM AND LAMAR CAMPUSES
Lamar University is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability or protected veteran status.
Lamar University is proud to provide employment preference to veteran applicants in accordance with Texas 805 Government Code, Section 657.003.
Applications and nominations may be submitted via U.S. Mail or email to:
- The Texas State University System is a tobacco-free/drug free workplace.
- A criminal history background check is required for finalist(s) under consideration for this position.
- The Texas State University System is an “at will” employer.
- If hired, you will be required to complete the federal Employment Eligibility Verification form, I-9. You will be required to present acceptable, original documents to prove your identity and authorization to work in the United States. Information from the documents will be submitted to the federal E-Verify system for verification.