Purpose of Position:
The Senior Auditor (VP) is responsible for independently leading and executing risk-based internal audit assignments across operational, financial, regulatory compliance, information technology (IT), information systems (IS), cybersecurity, and integrated audit areas. The role performs audit planning, risk assessment, control evaluation, testing, documentation, and reporting with minimal supervision while serving as a trusted advisor to management on risk management, governance, regulatory compliance, technology controls, and process improvement opportunities.
This position also plays a key role in leveraging data analytics and technology-enabled auditing techniques, supporting Audit Committee reporting, coordinating regulatory requests, and providing expertise related to IT governance, information security, cybersecurity, system implementations, and automated controls.
This is an individual contributor role and does not have direct people management responsibilities.
Essential Job Functions:
- Applies knowledge of banking operations, technology environments, information systems, cybersecurity risks, and regulatory requirements to develop and maintain risk assessments and contribute to the annual audit planning process.
- Obtains and documents an understanding of business processes, technology platforms, system interfaces, data flows, and supporting controls to identify and evaluate risks and the effectiveness of related internal controls.
- Develops risk and control matrices (RCMs), audit programs, testing strategies, and audit procedures for operational, financial, compliance, IT, IS, cybersecurity, and integrated audits with minimal supervision.
- Performs operational, financial, compliance, information technology, cybersecurity, and substantive testing procedures for internal audits, regulatory examinations, external audit support, and Sarbanes-Oxley (SOX) compliance activities.
- Evaluates the design and operating effectiveness of key controls, including automated controls, application controls, IT general controls (ITGCs), information security controls, cybersecurity controls, and data governance controls.
- Assesses technology-related risks involving infrastructure, cloud services, cybersecurity, third-party providers, system implementations, logical access, user provisioning, change management, data protection, and business continuity.
- Partners with business and technology stakeholders obtain audit evidence, conduct interviews, and evaluate processes and control environments.
- Ensures audit assignments are appropriately documented, accurate, complete, and completed within budget and established timelines.
- Prepares clear, concise, and well-supported audit reports, issue summaries, and other written communications with minimal supervision.
- Resolves review notes, management inquiries, and audit-related requests promptly and professionally.
- Serves as a department resource on data analytics, continuous monitoring, technology-enabled auditing, artificial intelligence (AI) applications, and audit automation techniques.
- Utilizes data analytics tools and techniques to identify risk indicators, analyze large data populations, improve audit efficiency, and enhance audit coverage.
- Maintains effective working relationships with Internal Audit Management, business line management, technology teams, external auditors, regulators, and other stakeholders.
- Provides timely communication to Internal Audit Management regarding audit progress, emerging risks, control deficiencies, cybersecurity concerns, and significant issues identified during audits.
- Keeps current on banking regulations, auditing standards, information technology trends, cybersecurity risks, emerging technologies, and industry best practices.
- Maintains continuing professional education and relevant certifications.
- Maintains appropriate levels of confidentiality and professionalism in handling sensitive Bank information.
- Performs other duties and special projects as assigned
Education and Experience:
- Bachelor’s degree in accounting, Finance, Information Systems, Computer Science, Cybersecurity, Business Administration, or a related field.
- Minimum 3-5 years of experience in internal audit, external audit, public accounting, IT audit, information security audit, risk management, regulatory compliance, or financial services auditing, preferably within the banking industry.
- Experience conducting operational, compliance, financial, IT, information systems, cybersecurity, or integrated audits.
- Experience evaluating IT General Controls (ITGCs), application controls, automated controls, interfaces, system implementations, third-party/vendor risks, and information security controls.
Knowledge & Skills.
- Strong knowledge of internal auditing principles, practices, standards, and methodologies.
- Working knowledge of banking operations, products, services, and regulatory requirements.
- Strong understanding of risk assessment methodologies and internal control frameworks.
- Knowledge of IIA Global Internal Audit Standards.
- Knowledge of the Sarbanes-Oxley Act (SOX) and related control requirements.
- Good understanding of COSO 2013 Internal Control Framework requirements.
- Understanding of IT governance, information security, cybersecurity, data governance, cloud computing, and technology risk management concepts.
- Knowledge of industry control frameworks and standards such as NIST Cybersecurity Framework, COBIT, FFIEC guidance, ISO 27001, and related regulatory expectations is preferred.
- Strong analytical, problem-solving, critical-thinking, and investigative skills.
- Strong written and verbal communication skills with the ability to communicate effectively with senior management and technical personnel.
- Strong project management, organization, and time management skills. Ability to manage multiple assignments, prioritize competing deadlines, and work independently.
- Ability to positively interface and work well with all levels of staff and management (auditees and own department)
- Working knowledge of relevant computer programs, i.e. Microsoft Access, Word, Excel, core banking system and query
- Ability to handle bank and client information and sensitive matters professionally and confidentially
Preferred Certifications
One or more of the following certifications, or progress toward obtaining them, is preferred:
- Certified Internal Auditor (CIA)
- Certified Public Accountant (CPA)
- Certified Information Systems Auditor (CISA)
- Certified Information Security Manager (CISM)
- Certified in Risk and Information Systems Control (CRISC)
- Certified Regulatory Compliance Manager (CRCM)
- Certified Financial Services Auditor (CFSA)
- Certified Bank Auditor (CBA)
- Certified Community Bank Internal Auditor (CCBIA)
- Certified Trust & Financial Advisor (CTFA)
- Certified Fiduciary & Investment Risk Specialist (CFIRS)
Our job titles may span more than one career level. The starting base salary for this role is between $100,000.00 – $120,000.00. The actual base pay is dependent upon many factors, such as: training, transferrable skills, work experience, business needs and market demands. The base pay range is subject to change and may be modified in the future.
Amalgamated Bank is an Equal Opportunity and Affirmative Action Employer, Minorities / Females / Individuals with Disability / Veterans. AmeriCorps, Peace Corps and other national service alumni are encouraged to apply. View our Pay Transparency Statement. Submission of a resume or any information regarding your qualifications does not constitute a promise or offer of employment. At Amalgamated Bank, we consider an applicant to be someone who has interviewed at least once, in person, with the hiring manager. Amalgamated Bank does not sponsor applicants for work visas.
Effective February 18, 2025, employees in office-based positions will be working a Hybrid work schedule consisting of three days or more, on-site per week, Monday - Thursday, although the specific days may vary by site or organization, with Friday designated as a remote-working day, unless business critical tasks require an on-site presence. This Hybrid work model does not apply to, and daily in-person attendance is required for, the contact center, branch service roles, and general services where the work to be performed is located at a Company site; positions covered by a collective-bargaining agreement (unless the agreement provides for hybrid work); or any other position for which the Company has determined the job requirements cannot be reasonably met working remotely. Please note, this Hybrid work model guidance does not apply to roles that have been designated as “remote”.
 Amalgamated Bank does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for the position will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails.
Learn more about this Employer on their Career Site
