Ensure successful delivery of IT change audit requirements for ICOFR Internal Controls over Financial Reporting
Limit the risk of unauthorised IT changes across the BT IT estate
Assist security programmes affecting change management and compliance
Assist internal and external audit teams by providing required information, evidence, and assist for IT Change detection processes
Analyse all detected changes on BT’s critical applications and systems to meet ICOFR requirements
Run monthly change detection populations and produce evidence for significant events affecting system configuration, application data, or financial data; upload evidence to MCP for external auditor use
Perform quarterly validation of ICOFR critical hosts actively scanned by the detection team through collaboration with application assist teams
Conduct quarterly validation of areas scanned on ICOFR applications through coordination with application assist teams
Investigate uncontrolled IT changes using forensic methods to identify the source where possible
Execute remediation and violation processes for UIC (Unauthorised IT Change) investigations, maintaining a complete audit trail
Assist analysis and trend reporting of UIC processes to enhance information quality, tools, and systems used
Provide technical knowledge in computer security and forensics to assist peer reviews of change detection events and assist the wider team
Use subject matter expertise to assist knowledge sharing, skills development, and capability building within change management teams
Requirements
Experience with Windows or nix administration to assist UIC investigations
Strong logical capability to interpret large data sets and identify key information
Ability to work independently while collaborating effectively within a small team
Clear written and verbal communication skills to engage both technical teams and non technical stakeholders, including external auditors
Analyzing of databases and/or web services to assist UIC management
Ability to interpret Perl scripting or other programming languages to analyse UIC application operations
Knowledge of IT Change Management tools (such as ServiceNow) and ITIL procedures
Ability to use SQL Developer to create and interpret queries
General Microsoft Office proficiency, including experience with Microsoft Access