About Andesa Services, Inc.
Andesa Services, Inc is a service and technology company. We are proud to serve the Life Insurance and Annuity industry through custom Software as a Service (SaaS) technology solutions and dedicated business support to end-users such as clients, brokers or policy holders. More information on these services can be found on our website at www.AndesaServices.com.
Andesa was established in 1983 and is located in Allentown, PA. We are a 100% employee-owned company via an Employee Stock Ownership Plan (ESOP), which means when you join our team, you will not only become an employee-owner, you will be contributing to and taking part in the success and longevity of the company!
Position Summary:
Responsible for the designing, testing, reporting, and maintaining IT General Controls and Application level controls for Andesa Services in support of SOC-1/SOC-2/SOC-3 audits and client service level agreements.
Primary Job Responsibilities:
- Coordinate SOC-1, SOC-2, and SOC-3 reviews with external auditors.
- Design and execute tests of key IT controls assigned to the Risk Management Office.
- Assign control activities to "owners" and ensure that they carry out these activities.
- Educate control owners as appropriate to ensure understanding of controls assigned.
- Provide a sound basis for the "Management Assertion" in the SOC reports.
- Respond to client inquiries on the SOC2 reports - i.e. testing exceptions, control remediation, etc.
- Assist external auditors in walk-thru visits of Andesa facilities and in collection of their requested test samples
- Update SOC report narrative sections each year to ensure it accurately reflects Andesa's product service offerings.
- Provide a written bridge letter and associated diligence for clients.
- Watermark and distribute the SOC reports to all clients and appropriate third parties.
- Drive the quarterly Internal Control Questionnaire (ICQ) process designed to assess the design and operating effectiveness of existing SOC controls.
- Provide quarterly report to Senior Staff on the state of IT controls including control deficiencies in need of remediation.
- Perform annual security training
- Ensures IT compliance incidents are promptly addressed, documented and resolved; considers implications, makes recommendations and takes appropriate follow-up
- Identify IT controls, assess their design and operational effectiveness, determine risk exposures and develop remediation plans.
Knowledge, Skills, and Abilities
- Strong communication skills
- Perform security reviews of Andesa’s systems and identify gaps in security architecture
- Business Continuity
- Review or conduct audits of information technology (IT) programs and projects
- Risk Management
Education, Training, and Experience
- Bachelor's degree in Auditing, Information Systems or equivalent experience.
- At least two (2) years relevant work experience (Auditing, IT Controls, etc.)
- Appropriate professional certification preferred – e.g., CISA.
Work Environment:
Work Schedule:
This is a full-time (40 Hours/Week) exempt position. Hours are flexible within core business hours. This position is fully remote reporting out of our office in Allentown, PA.