Make your mark at one of the biggest names in payments. We are seeking a candidate for a Fortune 500 payments technology company, Global Payment’s management recognizes the importance of managing and responding to risk. Internal Audit is an integral and valued component of Global Payments’ risk management environment. It works closely with management to deliver value-added and challenging audit projects in the areas of information technology, information security, business operations, finance & accounting, and compliance using progressive audit procedures. Our philosophy is to evaluate complex business processes utilizing a risk-based approach and to provide the greatest value to our internal clients. We strive to apply tailored and progressive audit procedures and to avoid standard check-the-box auditing. The department is consistently recognized for its contributions to organizational improvements due to its diverse, energetic, and collaborative approach when working with management.
This role will deliver a diverse array of information technology and information security audits that include in-depth analysis and understanding of supporting business processes. This position will have the opportunity to evaluate numerous technology platforms and apply process, technology, and security risk considerations. Specifically, the role will have the opportunity to evaluate technology risks and controls within major cloud technology provider environments (e.g., Amazon AWS, Google GCP, and Microsoft Azure) as the company continues cloud technology strategic initiatives. The candidate should have experience with a wide array of technology processes, such as infrastructure design and management, information security operations, service management, software development lifecycle, disaster recovery planning, etc. This position provides the opportunity for future career advancement as well as exposure to senior leadership and organizational divisions across the globe.
The Internal Audit team focuses heavily on risk-based audits that help management identify and reduce organizational risk. These projects vary each year and provide a high degree of challenge and diversity. The team also performs internal advisory projects and supports compliance audit responsibilities.
Familiarity with the payment processing industry and common technology control frameworks, including COBIT, NIST Cybersecurity, ISO 27000 series, PCI-DSS, and FFIEC IT Handbook is also preferred.
What you’ll own
Support controls testing for risk-based audits and supports the project team with all aspects of the audit lifecycle, including risk assessment, planning, client coordination, fieldwork, data analysis, work paper documentation, reporting, and remediation validation, with direction from senior team members.
Willingness to learn and grow technical knowledge through team collaboration. Projects will include a strong focus on information technology and information security controls in executing integrated, risk-based audits to evaluate the design and effectiveness of internal controls. The auditor will also focus on the integration of IT and business process risk considerations within the audit process.
Familiarity and understanding of technology control application in on-premise environments vs. increased automation of controls within cloud service provider (CSP) environments.
Understanding of IT-managed processes, including technology architecture, system build, and provisioning, configuration management, performance monitoring, incident management, change management, user access management, disaster recovery, etc.
Evaluate key information security risks including confidentiality, integrity, and availability of technology components through a review of security operational processes, such as vulnerability management, penetration testing, security logging and monitoring, security incident response, and defense-in-depth strategies.
Evaluate root cause factors for audit testing exceptions and recommend practical solutions that reduce risk and strengthen business processes and controls.
Ensure audit testing work papers are documented in a consistent and high-quality manner while executing project tasks in adherence to established timelines.
Build and develop Internal Audit’s brand within the company through meaningful relationship building.
Enable continuous improvement of the Internal Audit department by identifying and communicating enhancement opportunities to department leadership.
Support the development of other team members within the Internal Audit department.
What you’ll bring
1+ years of relevant audit and/or risk management experience.
Knowledge of auditing principles and practices, and the analysis and reporting of audit information.
Bachelor’s degree in Auditing, Business Management, or Information Technology.
Merchant Acquiring / Payment Processing, Card Issuance, and Private-label Consumer Solutions industry experience preferred.
Familiarity with internal control frameworks, including COBIT, FFIEC, PCI DSS, Sarbanes-Oxley, ISO27001, and ITIL
Open to 10-15% travel requirement, including some potential international travel
Merchant Acquiring / Payment Processing, Card Issuance, and Private-label Consumer Solutions industry experience preferred.
CIA, CISA, CISM, CISSP, or other relevant certifications are preferred
Professional services audit or risk advisory experience preferred
It’s a bonus if you have
Audit and/or consulting experience in the following:
Information and data security for payment card data and publicly-identifiable information
Technology control applications within cloud environments and usage of automated, processes and cloud architectures such as CI/CD deployment pipelines, infrastructure-as-code, containerization, etc
Application security, including segregation of duties and least privileged access
Technology infrastructure security, including cloud computing, mainframe, UNIX/LINUX, Windows, SQL Server and Oracle database
Systems development, project management, and change management
On-prem and/or cloud IT infrastructure design, management, and operations, Business continuity and technology resiliency including high availability and disaster recovery architecture
Integration of business process controls with supporting technologies. Business process workflow documentation, including identification of key risks and the corresponding business and technology controls
Ability to work in a complex and evolving environment.
Demonstrate strong project management and execution skills, including: prioritizing tasks, balancing workload, anticipating next steps, and adapting to change.
Tailor project approaches based on areas of key risks. Critically evaluate audit procedures to maximize the value of each audit project.
Strong communication and presentation skills with an ability to tailor communications to different audiences.
Pursue work with enthusiasm, energy, drive, and team collaboration.
Establish and build effective relationships.
Collaborate with management and senior leadership to improve internal controls and processes.
Demonstrates ability to consider all team member’s input before decision-making.
Proactively communicate issues with colleagues and obtain agreement on audit findings and practical recommendations with control owners before presentation to management.
About the team
Our inclusive and global teams win together every day. We’re proud to have the best minds in the industry, who you can learn from as you grow your career. The people, the energy, the connections – it’s unmatched. Come and be part of an ever-evolving company and get dynamic opportunities that go beyond borders.
What makes a Globalpayer?
Globalpayers think like a client, act like an owner and win as one team. We’re curious and innovative – always finding better ways to deliver impact. We empower each other to make decisions, and it’s our passion that drives excellence in everything we set out to do.
Does this sound like you? Then you sound like a Globalpayer. Apply now to take your career global.
Applicant must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future; We will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa).
Diversity and EEO Statements
Global Payments is an organization that stands against racism, intolerance and injustice in all its forms — one that respects, honors and celebrates the diversity of our team members and the differences among us. Our commitment to fostering a company culture that values and respects Inclusion and Diversity is steadfast. Standing together as one company, we will continue to work to drive positive change for the communities in which we live and work and stamp out injustice.