Summary
CVS Health is working to create a more connected, convenient, and compassionate health experience. The Senior Analyst will evaluate IT application controls and automated business controls for SOX compliance, supervise testing, assess control effectiveness, and recommend improvements to financial compliance processes. The role also collaborates with auditors, technology and business teams, and cross-functional project teams.
Responsibilities
- Assess application controls and security configurations across the Enterprise
- Perform data integrity and system interface reviews
- Review the process documentation obtained during the walkthroughs and determining the nature, timing and extent of audit procedures needed
- Work with the external auditors and regulatory bodies, as needed
- Execute testing and create work paper documentation
- Interacts with various levels of Internal Audit and technology and digital line management to resolve issues in a timely manner and to maintain effective communications
- Demonstrates a commitment to integrity and the company code of conduct, and a respect for diversity and inclusion
- Ensure high-quality workpapers: clear test objective, criteria, procedures, evidence, and conclusions
- Develop test plans for ITACs (e.g., configuration parameters, automated 3-way match, approval workflows, tolerance/thresholds, system-enforced segregation, data validations, exception handling)
- Test IPE (Information Produced by the Entity) for IT Automated Key Reports: validate report logic, parameters, source, completeness & accuracy (C&A) and retention
- Evaluate interfaces/integrations (e.g., file transfer completeness, error handling, reconciliation)
- Execute operating effectiveness testing, including sample selection, re-performance, inspection, and inquiry, in accordance with entity methodology
Skills
- 2+ years prior experience in IT Audit, Automated Controls Assessment, Risk Assessment, or Risk Consulting
- Bachelor's degree in a relevant field such as Information Technology, Data Analytics, Finance, Accounting, etc. OR equivalent experience
- Professional designations such as CISA, CPA, CIA, etc., or measured progress in achieving such designations
- Demonstrate a base-level understanding of IT related application controls, related technologies and deployment strategies and how automated business controls function within these technologies and in broader business processes
- Understanding of cloud environments and data classification and protection concepts
- Understanding of key IT concepts and processes - including applications and infrastructure, change control, access management, job scheduling, data privacy, and IT risk assessment, automated control environments, cybersecurity best practices, Cloud security controls etc
- Demonstrate an ability to understand and communicate with both members of the business and IT, bridging gaps in understanding between the groups
- Practical knowledge of processes, risks, and internal controls
- Prior audit experience including technical report writing desirable
- Strong analytical, deductive, problem solving, and critical thinking skills
- Good teamwork and collaboration skills
- Solid meeting management and oral/written communication skills
Qualifications
Must Haves
- 2+ years prior experience in IT Audit, Automated Controls Assessment, Risk Assessment, or Risk Consulting
- Bachelor's degree in a relevant field such as Information Technology, Data Analytics, Finance, Accounting, etc. OR equivalent experience
Nice to Haves
- Professional designations such as CISA, CPA, CIA, etc., or measured progress in achieving such designations
- Demonstrate a base-level understanding of IT related application controls, related technologies and deployment strategies and how automated business controls function within these technologies and in broader business processes
- Understanding of cloud environments and data classification and protection concepts
- Understanding of key IT concepts and processes - including applications and infrastructure, change control, access management, job scheduling, data privacy, and IT risk assessment, automated control environments, cybersecurity best practices, Cloud security controls etc
- Demonstrate an ability to understand and communicate with both members of the business and IT, bridging gaps in understanding between the groups
- Practical knowledge of processes, risks, and internal controls
- Prior audit experience including technical report writing desirable
- Strong analytical, deductive, problem solving, and critical thinking skills
- Good teamwork and collaboration skills
- Solid meeting management and oral/written communication skills
Benefits
- This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above.
- Medical, dental, and vision coverage
- Paid time off
- Retirement savings options
- Wellness programs
- Other resources, based on eligibility
- Remote work arrangement