HomeSearch › Job

IT Internal Auditor II

Davenport, IA, USA

Description TITLE: IT Internal Auditor II DEPARTMENT: 996 – GO Internal Audit/Loan Review/Compliance Audit JOB SUMMARY: The IT Internal Auditor II is responsible for performing information technology audits, IT-related Sarbanes-Oxley (SOX) internal control testing, and technology risk assessments for QCR Holdings, Inc. and its subsidiaries. This position evaluates the design and operating effectiveness of IT general controls, application controls, cybersecurity controls, and technology processes to determine whether risks are appropriately managed and controls comply with regulatory, policy, and industry expectations.

The IT Auditor collaborates with audit management, business partners, and IT personnel to execute the annual audit plan. This role builds strong relationships, engages stakeholders with professionalism and respect, contributes to a positive, high-performing audit culture, and demonstrates behaviors that foster trust, teamwork, and organizational success. ESSENTIAL FUNCTIONS: Perform IT audits, SOX IT-related control testing and procedural reviews in accordance with the approved audit plan.

Evaluate IT general controls including logical access, privileged access, change management, system development, backup and recovery, information security, cloud, and IT operations controls. Assess automated and application controls supporting critical financial and operational processes. Conduct interviews and walkthroughs to obtain an understanding of systems, risks, and control activities. Assist in maintaining audit analytics methodologies, scripts, dashboards, and documentation to support consistency and quality across engagements.

Prepare audit workpapers that support conclusions and recommendations. Document audit findings and develop practical recommendations to strengthen controls and mitigate risk. Prepare written draft audit reports to management detailing audit results for audit management’s review. Track and validate remediation of identified audit issues. Expand technical and compliance knowledge of all subsidiaries’ departments through training programs, seminars, employee interaction, and publications.

Continuously develop and expand internal audit skills as well as develop best practices. As directed by Audit Management, assist with reviewing other internal auditors’ work/completion of audit steps along with providing constructive feedback/review comments. Verify the auditor cleared comments accordingly and ensure draft report is ready for Senior Auditor/Manager’s review. Maintain confidentiality and safeguard sensitive information.

Maintain professional competence through continuing education and certifications. Comply with all company or regulatory policies, procedures and requirements that are applicable to this position. Foster and preserve a culture of diversity, equity, and inclusion. Additional duties and responsibilities may be required to support the company’s mission, vision and values. QUALIFICATIONS: Bachelor’s degree in Management Information Systems, Computer Information Systems, Cybersecurity, Computer Science, Accounting, Business, or related field.

A minimum of 2 years of years of experience in IT internal audit, information security, risk management, public accounting, technology compliance, or related disciplines preferred. Working knowledge of data analytics tools and techniques, including SQL, Power BI, Alteryx, or similar technologies. Ability to extract, transform, analyze, and interpret data from multiple systems and databases. Knowledge of IT general controls, application controls, information security principles, SOX compliance, and technology risk management.

Familiarity with FFIEC guidance, COBIT, NIST Cybersecurity Framework, and banking regulatory expectations preferred. Hold a certification such as CISA, CIA, CISSP, CRISC, or CPA. Strong analytical, interpersonal, organization, and problem-solving skills. Minimal travel to all QCRH company locations, as needed. Salary & Benefits:

Search all live jobs — free, no account →