Job Summary
The Staff, IT Internal Audit conducts entry-level professional IT audit, risk assessment, and compliance reviews under the direct guidance of Internal Audit leadership. This role is responsible for executing foundational audit procedures and evaluating the design, implementation, and operational effectiveness of information technology infrastructure, application controls, and cybersecurity frameworks. The Staff Auditor actively participates in IT audit engagements and regulatory compliance assessments—including Sarbanes-Oxley (SOX), HIPAA Security, and Promoting Interoperability (PI)—and provides objective advisory observations to management. The individual bridges technology and business by learning to map control environments while maintaining strict professional, organizational, and ethical standards.
Essential Functions
Audit Execution & Testing: Performs specific audit testing procedures, analyzes population data sets, and thoroughly documents audit evidence in workpapers in accordance with Internal Audit standards.
Risk Evaluation & Scoping: Develops a foundational understanding of business and IT processes, infrastructure, and security policies to assist in identifying generic technology risks.
Documentation & Quality Assurance: Prepares clear and high-quality process narratives, system flowcharts, and walkthrough documentation to assess control design effectiveness.
Reporting & Communication: Identifies control deficiencies and security gaps, communicates them clearly to audit leadership, and assists in drafting observations for formal audit reports.
Advisory & Project Support: Supports basic technology assessments, system implementation reviews, and ad-hoc advisory projects to ensure risk management is integrated into new organizational initiatives.
Stakeholder & External Collaboration: Provides direct, coordinated testing support and data gathering assistance to external auditors to optimize overall audit efficiency.
Team Leadership & Development: Proactively seeks opportunities to increase individual knowledge in information systems controls, adhering to a collaborative, team-oriented corporate environment.
Strategic Planning & Innovation: Leverages basic data analysis tools (e.g., Excel, Power BI) to evaluate simple data populations and improve individual testing speeds
Qualifications
- Bachelor's Degree in accounting or related field required from an accredited college or university in Information Security, Information Systems, Business Administration (with a Cybersecurity/Data Analytics emphasis), or a related academic discipline.
- Less than 2 years of experience in IT compliance, IT external/internal audit, or technology risk management (relevant internships will be considered).
Knowledge, Skills and Abilities
- Technical Competency & IT Architecture: Foundational knowledge of operating systems, databases, networks, and basic cybersecurity concepts. Ability to understand how data flows through simple IT infrastructures.
- Regulatory Frameworks & Compliance: Basic awareness of IT control frameworks (COBIT, NIST) and regulatory compliance requirements (SOX, HIPAA, Promoting Interoperability).
- Audit Methodology & Data Analytics: Foundational understanding of internal audit concepts, risk assessment, and control testing. Proficiency in basic data manipulation tools (e.g., Excel) to perform data sorting and analysis.
- Project Management & Leadership: Strong time management skills with the ability to execute assigned audit steps within budget. Demonstrates a proactive, coachable mindset and a willingness to learn from peers.
- Communication & Stakeholder Relations: Clear written and verbal communication skills. Ability to document audit testing accurately in narratives and explain basic technical findings to immediate audit team members.
- Strong computer skills including ACL, MS Excel, Access, PowerPoint, and Word
Licenses and Certifications
- Certified Information Systems Auditor (CISA) preferred
- CISSP Certified Information Systems Security Professional
Skills Required
- Bachelor's degree in Accounting, Information Security, Information Systems, Business Administration (Cybersecurity/Data Analytics emphasis), or related field
- Less than 2 years of experience in IT compliance, IT internal/external audit, or technology risk management (internships considered)
- Foundational knowledge of operating systems, databases, networks, and basic cybersecurity concepts
- Basic awareness of IT control frameworks and regulatory requirements (COBIT, NIST, SOX, HIPAA, Promoting Interoperability)
- Proficiency with data manipulation and analysis using Excel and basic data tools
- Strong computer skills including ACL, Microsoft Excel, Access, PowerPoint, and Word
- Clear written and verbal communication skills and ability to document audit testing
- Time management and ability to execute assigned audit steps within budget
- CISA (Certified Information Systems Auditor)
- CISSP (Certified Information Systems Security Professional)
What We Do
Community Health Systems, Inc. is one of the nation’s leading operators of general acute care hospitals. The organization’s affiliates own, operate or lease more than 80 hospitals in 16 states with approximately 15,000 licensed beds. Affiliated hospitals are dedicated to providing quality healthcare for local residents and contribute to the economic development of their communities. Based on the unique needs of each community served, these hospitals offer a wide range of diagnostic, medical and surgical services in inpatient and outpatient settings.







