Compliance Analyst, Audit Assurance
Listed on 2026-09-13
-
IT/Tech
Information Security & Data Protection, Cybersecurity
Position Summary
The Audit & Assurance Analyst supports the Enterprise Compliance and Risk team in executing risk-based assurance activities across the organization's control environment. The role executes the external audit program for the certified business units, covering System and Organization Controls and HITRUST engagements and agreed-upon procedures, and supports internal assurance over the risk framework without assuming direct management responsibility for the processes reviewed.
PositionSummary
The Audit & Assurance Analyst supports the Enterprise Compliance and Risk team in executing risk-based assurance activities across the organization's control environment. The role executes the external audit program for the certified business units, covering System and Organization Controls and HITRUST engagements and agreed-upon procedures, and supports internal assurance over the risk framework without assuming direct management responsibility for the processes reviewed.
The function is consolidating a fragmented external audit estate onto a single firm and a single platform, so this role participates in a genuine transformation rather than maintaining a steady state. The ideal candidate brings a foundational understanding of insurance operations, risk management principles, and audit methodology, with strong analytical and communication skills. It suits someone detail-oriented, comfortable working across functions, and looking to grow within a maturing and high-visibility program.
Key Responsibilities- Execute System and Organization Controls and HITRUST readiness activities, including evidence collection, control walkthroughs, and gap identification
- Support external audit fieldwork and manage auditor requests through to closure within agreed time frames
- Maintain audit-ready control evidence within the enterprise GRC platform to support ongoing assurance activity
- Conduct independent assessments to determine whether major business risks are accurately identified, evaluated, and reported by management
- Support consistent application of risk appetite and tolerance policies across the organization as those standards are established
- Track and validate closure of issues and corrective actions taken by management to address identified risk or control gaps
- Support the findings process, including tracking, validation, and reporting of finding status and remediation progress
- Identify trends and systemic issues emerging from findings data to inform risk prioritization
- Support information technology general control testing in coordination with Finance and Internal Audit
- Assist in preparing documentation for audits, regulatory reviews, and internal assessments
- Support the consolidation of external audit engagements onto a single firm, including transition of evidence and working papers
- Partner with compliance, risk, legal, technology, and business unit teams to drive process standardization
- Support communication of assurance findings to stakeholders with varying levels of risk expertise
- Bachelor's degree in Accounting, Finance, Information Systems, Business, or a related field
- 1 to 3 years of experience in information technology audit, internal audit, assurance, or control testing; internship experience will be considered
- Working knowledge of control frameworks such as System and Organization Controls 2, HITRUST, NIST, or COSO
- Demonstrated experience with evidence collection, control documentation, or walkthrough procedures
- Familiarity with risk and control concepts sufficient to evaluate whether a control operates as described
- Skills
- High attention to detail and strong documentation discipline
- Strong written and verbal communication, including the ability to write a clear finding
- Analytical mindset with the ability to interpret information and identify key themes
- Ability to manage multiple concurrent requests and meet deadlines
- Collaborative approach with a willingness to learn in a dynamic, high-growth environment
- Proficiency in Microsoft Office Suite (Excel, PowerPoint, Word)
- CISA or CIA certification, or demonstrable progress toward either
- Experience in insurance, financial services, or other regulated industries
- Hands-on experience with an enterprise GRC platform
- Exposure to HITRUST Common Security Framework or System and Organization Controls 2 Type II engagements
- Familiarity with data visualization tools such as Power BI or Tableau
- Understanding of life, annuity, or health insurance operations
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).