Description
Primary Purpose
This position owns complex audit workstreams, integrate analytics and technology insights into testing, and influence scope to address significant risks. Mentor team members and contribute to methodology and tooling improvements.
This position owns complex audit workstreams, integrate analytics and technology insights into testing, and influence scope to address significant risks. Mentor team members and contribute to methodology and tooling improvements.
Duties and Responsibilities
- Designs risk-based programs for multi-system processes, integrating coverage across governance, acquisition and development, operations, and protection of information assets.
- Applies data analysis or tool-assisted techniques to test large populations and identify outliers efficiently.
- Evaluates the design and operating effectiveness of automated and information technology dependent controls in enterprise applications.
- Assesses third-party or service provider control reports and determines appropriate additional procedures.
- Leads stakeholder walkthroughs to align on criteria and to confirm end-to-end control coverage across platforms.
- Produces clear, concise reporting packages that connect evidence to impact and prioritize remediation.
- Coaches associates and seniors on documentation quality, sampling logic, and evidence sufficiency.
- Recommends improvements to audit templates, analytics scripts, and knowledge assets to reduce cycle time.
- Performs other duties as assigned.
Qualifications
Education
- Typically requires a 4 year degree in a relevant field, or equivalent combination of relevant education and experience.
Experience
- Typically requires 8 years of related experience.
-
Must reside in Southern California or be willing to relocate upon hire.
Knowledge, Skills and Abilities
- Ability to design audit approaches for complex or emerging technology risks.
- Ability to evaluate interconnected technology controls across end-to-end processes.
- Ability to exercise significant autonomy while adhering to professional standards.
- Knowledge of complex IT environments, including integrated applications and infrastructure.
- Knowledge of enterprise risk management and IT governance frameworks.
- Skill in communicating complex technical risks to non-technical audiences.
- Skill in influencing stakeholders to remediate technology control gaps.
Contact
Sempra
101 Ash St
San Diego
California United States
www.sempra.com
From the same organization
9 Oct, 2026
18 Sep, 2026
8 Nov, 2026


