Harrisburg, PA, US
23 hours ago
IT Audit Analyst
Company :Highmark HealthJob Description : 

JOB SUMMARY

This job is actively involved in the execution of audit activities related to  information technology, security, system implementations, and data privacy to determine whether Highmark Health and its subsidiaries' network of risk management, control, and governance processes, as designed and operated by management, are adequate and functioning. Assesses whether the processes and controls provide reasonable assurance that information technology and security risks are identified and managed, and that significant financial, operational, and protected information is secure, accurate, reliable, and processed timely. Determines and recommends improvements in the implementation of business process and systems changes and project management controls. Prepares reports for management summarizing the results of the audit and/or project, including providing recommendations on improvement opportunities. Interfaces and assists the independent auditors during external audit assessments, where necessary.  Executes the IT Assurance and Advisory programs aligned with the overall Internal Audit strategy. Must comply with the Health Insurance Portability Accountability Act of 1996 (HIPAA) as it pertains to disclosures of protected health information (PHI) as described in the Notice of Privacy Practices and Privacy Policies and Procedures. As a component of job roles and responsibilities, employees in this role may have access to covered information, cardholder data, or other confidential customer information which must be protected at all times.  In connection with this responsibility, employees in this role must adhere to all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy.

ESSENTIAL RESPONSIBILITIES

Assist with identifying and assessing the organization’s key information technology, security, and data privacy risk areas.Plan and executes information technology, security, system implementation, and data privacy audit activities across Highmark Health enterprise while maintaining independence and adhering to professional inductry standards. Produce high-quality audit work papers, ensuring satisfactory documentation of results.Effectively communicate with customers, supervisors, and subject matter experts to deliver on requests and tasks in a timely manner, and to ensure clarity on project status, deadlines, and deliverables throughout the project lifecycle.  Assist with the process to close-out and finalize audits / projects, including the identification and assessment of issues, development of audit reports, and review of supporting documentation and workpapers in accordance with Departmental standards Contribute with maintaining a positive working environment through the building of solid relationships with team members.Coordinate with independent auditors in executing audit procedures for the organization, where necessary.Other duties as assigned or requested.

EDUCATION

Required

Bachelor's Degree in Accounting, Finance, Business Administration, Information Technology, Computer Science, or related field

Substitutions

None

Preferred

None

EXPERIENCE

3 years of Information Systems auditing OR 3 years in auditing and an Information Systems related discipline, such as Information Security, Systems Development, etc.

Preferred

Familiarity with a wide variety of computer application platforms, including but not limited to: Oracle, SQL Server, DB2, RACF, Linux, and Windows.Cybersecurity/ IT risk assurance expertiseExperience with Archer Governance, Risk, and Compliance (GRC) suite of products

LICENSES OR CERTIFICATIONS

Required

None

Preferred

Certified Information System Audit (CISA)Certified Internal Audit (CIA)Certified Public Accountant (CPA)

SKILLS

Knowledge of internal audit functions, particularly as applied to information technology and data securityAbility to apply auditing (GAAS), accounting  (GAAP) and/or IS industry standards to the evaluation of systems environments and processes (i.e., data center operations, information security, input, output and processing controls, back-up and recovery, business contingency planning, systems development, and the implementation of advanced technologies)Effective resource and project planning, decision making, results delivery, team building, and staying current with relevant technology and innovationOral and written communication skills when interfacing and collaborating with clients, peers, and management to develop solutions, emphasizing a client-based focus to understand and respond appropriately to business requirementsStrong relationship building skillsSelf-starter with the ability to work under pressure independently and as part of a teamAbility to think strategically and act proactively to create strong trust and confidence with business unitsAbility to interact, build credibility and long-term relationships with senior management to understand the company’s culture, strategic direction, and goals.Ability to manage multiple projects, meet deadlines while ensuring quality and exceeding client expectations. ​

LANGUAGE REQUIREMENT (other than English)

None

TRAVEL REQUIRED

0%-25%

PHYSICAL, MENTAL DEMANDS, AND WORKING CONDITIONS

Position Type

Office Based

Teaches / trains others regularly

Frequently

Travel regularly from the office to various work sites or from site-to-site

Rarely

Works primarily out-of-the office selling products/services (sales employees)

Never

Physical work site required 

No

Lifting: up to 10 pounds

Constantly

Lifting: 10 to 25 pounds

Occasionally

Lifting: 25 to 50 pounds

Rarely

Disclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.

Compliance Requirement: This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies.


As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times.  In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy. 

Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements.

Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their race, color, religion, sex, national origin, sexual orientation/gender identity or any other category protected by applicable federal, state or local law. Highmark Health and its affiliates take affirmative action to employ and advance in employment individuals without regard to race, color, religion, sex, national origin, sexual orientation/gender identity, protected veteran status or disability.

Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their race, color, age, religion, sex, national origin, sexual orientation/gender identity or any other category protected by applicable federal, state or local law. Highmark Health and its affiliates take affirmative action to employ and advance in employment individuals without regard to race, color, age, religion, sex, national origin, sexual orientation/gender identity, protected veteran status or disability. 

EEO is The Law

Equal Opportunity Employer Minorities/Women/Protected Veterans/Disabled/Sexual Orientation/Gender Identity (https://www.eeoc.gov/sites/default/files/migrated_files/employers/poster_screen_reader_optimized.pdf)

We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact number below.

For accommodation requests, please contact HR Services Online at HRServices@highmarkhealth.org

California Consumer Privacy Act Employees, Contractors, and Applicants Notice

Confirm your E-mail: Send Email