Summary
MSI is a managing general agency that provides specialized insurance solutions through underwriting expertise, risk capacity, and advanced technology. The Internal Controls Associate supports the organization’s internal control environment by evaluating control design and effectiveness, conducting risk assessments and testing, maintaining documentation and evidence, and assisting with audits, compliance, remediation, and governance initiatives.
Responsibilities
- Support the design, execution, and documentation of IT General Controls (ITGCs), including user access reviews, segregation of duties, and system change management controls
- Document and maintain policies, procedures, process flows, risk and control matrices (RCMs), and control narratives in alignment with COSO principles
- Ensure controls are appropriately designed to mitigate identified business, operational, financial, compliance, and technology risks
- Perform periodic risk assessments across business and technology functions
- Identify control gaps, emerging risks, and process inefficiencies
- Develop and recommend risk mitigation strategies and control enhancements
- Support enterprise risk management and compliance initiatives
- Develop and execute control testing procedures to evaluate control design and operating effectiveness
- Analyze testing results, identify deficiencies, and track remediation activities
- Maintain evidence supporting control execution and effectiveness
- Monitor key controls through continuous auditing and data analytics techniques where applicable
- Support compliance with applicable regulations, standards, and contractual obligations, including: Sarbanes-Oxley (SOX)State insurance regulationsPrivacy regulations (CCPA, CPRA, GDPR, etc.)Cybersecurity and information security requirementsSOC reporting, PCI DSS, and other industry-specific frameworks as applicable
- Assist in preparing regulatory examinations, audits, and compliance assessments
- Serve as a primary liaison for Internal Audit and external auditors
- Coordinate audit requests and facilitate walkthroughs, interviews, and evidence collection
- Respond to audit inquiries and support remediation efforts
- Track audit findings and ensure corrective actions are implemented timely
- Evaluate operational processes to identify risks, inefficiencies, and control weaknesses
- Conduct special reviews and investigations relating to control failures, incidents, or identified concerns
- Participate in assessments related to fraud prevention, business continuity, vendor management, and cybersecurity
- Perform periodic user access reviews across key business applications and platforms, including **Microsoft Entra ID**, to ensure appropriate access and compliance with internal policies
- Prepare clear, concise, and audit-ready reports summarizing risks, control effectiveness, and recommendations
- Communicate findings and corrective action plans to business and technology leadership
- Escalate significant issues and emerging risks appropriately
- Present control-related information to management committees and stakeholders
- Identify opportunities to enhance operational efficiency, governance, and compliance processes
- Assist in developing metrics, dashboards, and reporting to monitor control effectiveness
- Promote a culture of accountability, risk awareness, and strong internal controls throughout the organization
- Stay informed on regulatory changes, emerging risks, and industry best practices affecting the insurance sector
- Support control, audit, risk management, governance, compliance, and operational initiatives as assigned by Internal Controls leadership
- Perform additional control-related activities necessary to maintain an effective enterprise-wide control environment
- Support the implementation and governance of controls within **Microsoft Azure** environments, including access management, security configurations, and compliance requirements
Skills
- 1-2 years of experience in internal controls, external or internal audit positions
- Demonstrated ability to consistently deliver on commitments and manage competing priorities
- Strong organizational, planning, and project management skills
- Sound professional judgment and risk-based decision-making capabilities
- Exceptional attention to detail and analytical thinking
- Strong written and verbal communication skills
- Ability to work independently with minimal supervision
- Demonstrated accountability, ownership, and follow-through
- Strong listening skills and openness to coaching and feedback
- Ability to quickly learn new systems, regulations, and business processes
- Proven ability to build effective working relationships and influence stakeholders
- Bachelor's degree in accounting, Finance or Tech preferred
- Big four or banking experience is a plus
Qualifications
Must Haves
- 1-2 years of experience in internal controls, external or internal audit positions
- Demonstrated ability to consistently deliver on commitments and manage competing priorities
- Strong organizational, planning, and project management skills
- Sound professional judgment and risk-based decision-making capabilities
- Exceptional attention to detail and analytical thinking
- Strong written and verbal communication skills
- Ability to work independently with minimal supervision
- Demonstrated accountability, ownership, and follow-through
- Strong listening skills and openness to coaching and feedback
- Ability to quickly learn new systems, regulations, and business processes
- Proven ability to build effective working relationships and influence stakeholders
Nice to Haves
- Bachelor's degree in accounting, Finance or Tech preferred
- Big four or banking experience is a plus
Benefits
- Remote work arrangement (Remote US, United States of America)