What are the responsibilities and job description for the IT Compliance Specialist position at ASK Consulting?
Description
Job Title
IT Compliance Specialist
Position Description
The IT Compliance Specialist, Assurance independently performs control testing and documentation across ISO 27001, PCI DSS, SOC 2, and SOX ITGC. Manages issues and policy exceptions in ServiceNow Integrated Risk Management (IRM), designs and executes UAT, and contributes to IRM data/reporting (Data Analyst/Business Analyst/QA/Test Engineer responsibilities as needed).
Roles Responsibilities
• Plans and executes control tests; validates evidence sufficiency and traceability.
• Owns IRM records for issues and policy exceptions; ensures timely updates and closure.
• Designs UAT scripts for IRM changes; coordinates testers; tracks defects to resolution.
• Performs data quality routines; reconciles control catalogs, ownership, and status fields.
• Creates or enhances standard reports/dashboards for assurance KPIs and trends.
• Partners with system/control owners to remediate findings; documents remediation.
• Contributes to method improvements (test templates, sampling guidance, quality checklists).
• Performs other duties as assigned.
• Travel as required.
Skills
• Solid understanding of control testing methods, including sampling, walkthroughs, and reperformance.
• Working proficiency with Service Now, IRM, including records management, workflows, UAT and reporting.
• Strong analytical and problem-solving skills: intermediate proficiency in Excel, Power BI, or equivalent tools.
• Clear and effective communication with control owners, ensuring consistent and high-quality documentation.
• Ability to apply conceptual thinking and work independently while managing multiple priorities.
• Strong time management and organizational skills to handle competing tasks effectively.
• Ability to comply with company policies and applicable laws and regulations.
• Comfortable with occasional travel and participation in meetings (virtual or in-person).
• 5 years in IT compliance/audit/control testing or IRM/QA/data analysis.
Education
• Bachelor's Degree in information systems, computer science or related field from an accredited college or university preferred.
• Certification preferred: ISO 27001 internal Auditor, PCI Professional (PCIP), CISA (in progress).
Job Title
IT Compliance Specialist
Position Description
The IT Compliance Specialist, Assurance independently performs control testing and documentation across ISO 27001, PCI DSS, SOC 2, and SOX ITGC. Manages issues and policy exceptions in ServiceNow Integrated Risk Management (IRM), designs and executes UAT, and contributes to IRM data/reporting (Data Analyst/Business Analyst/QA/Test Engineer responsibilities as needed).
Roles Responsibilities
• Plans and executes control tests; validates evidence sufficiency and traceability.
• Owns IRM records for issues and policy exceptions; ensures timely updates and closure.
• Designs UAT scripts for IRM changes; coordinates testers; tracks defects to resolution.
• Performs data quality routines; reconciles control catalogs, ownership, and status fields.
• Creates or enhances standard reports/dashboards for assurance KPIs and trends.
• Partners with system/control owners to remediate findings; documents remediation.
• Contributes to method improvements (test templates, sampling guidance, quality checklists).
• Performs other duties as assigned.
• Travel as required.
Skills
• Solid understanding of control testing methods, including sampling, walkthroughs, and reperformance.
• Working proficiency with Service Now, IRM, including records management, workflows, UAT and reporting.
• Strong analytical and problem-solving skills: intermediate proficiency in Excel, Power BI, or equivalent tools.
• Clear and effective communication with control owners, ensuring consistent and high-quality documentation.
• Ability to apply conceptual thinking and work independently while managing multiple priorities.
• Strong time management and organizational skills to handle competing tasks effectively.
• Ability to comply with company policies and applicable laws and regulations.
• Comfortable with occasional travel and participation in meetings (virtual or in-person).
• 5 years in IT compliance/audit/control testing or IRM/QA/data analysis.
Education
• Bachelor's Degree in information systems, computer science or related field from an accredited college or university preferred.
• Certification preferred: ISO 27001 internal Auditor, PCI Professional (PCIP), CISA (in progress).