IT Audit Consultant Financial Crimes Technology & Regulatory Programs
Location: Remote U.S. based
Schedule: Primarily Eastern Time, with flexibility to support international stakeholders
Employment Type: Contract - high chance of extension or full-time conversion
Position Overview: We are seeking experienced IT Audit professionals to support technology-focused audit and regulatory initiatives within a large global financial institution.
This role will focus on evaluating technology controls supporting Financial Crimes/AML environments, assessing remediation of regulatory and audit issues, and performing independent testing across applications, data, technology processes, and control frameworks.
The ideal candidate will bring strong banking IT Audit experience, be comfortable working independently, and have the technical depth to understand complex applications, data flows, system configurations, and technology controls.
Key Responsibilities:
- Plan and execute risk-based technology audit procedures across complex banking applications and infrastructure.
- Evaluate technology supporting AML and Financial Crimes functions, including transaction monitoring, sanctions screening, KYC/CDD, and related platforms.
- Perform independent testing of corrective actions associated with regulatory, audit, and control issues to determine whether identified weaknesses have been appropriately addressed.
- Assess IT general controls and application controls, including logical access, change management, system development, security, and IT operations.
- Review system configurations, interfaces, data flows, and technology dependencies to identify control weaknesses and potential risk.
- Evaluate data completeness, accuracy, lineage, and controls supporting information exchanged between systems.
- Perform targeted and substantive testing based on identified technology and regulatory risks.
- Review controls supporting models and automated monitoring processes, where applicable, including underlying data, implementation, governance, and ongoing monitoring.
- Document testing procedures, evidence, conclusions, and identified issues in clear, audit-ready workpapers.
- Communicate findings and challenge remediation approaches with technology, risk, compliance, and audit stakeholders.
- Collaborate with teams across multiple international regions and time zones.
Required Qualifications:
- At least 8 years of IT Audit or Technology Audit experience, preferably within large banking or financial-services organizations.
- Strong hands-on experience performing technology control testing and independently executing audit procedures.
- Experience auditing AML/Financial Crimes technology or closely related regulatory technology environments.
- Experience with regulatory remediation, issue validation, corrective-action testing, or similar regulatory programs.
- Strong knowledge of ITGCs, application controls, logical access, change management, SDLC, security, and data controls.
- Experience evaluating system interfaces, data quality, data lineage, and application-to-application data flows.
- Ability to assess both control design and operating effectiveness.
- Strong audit documentation and workpaper-writing skills.
- Ability to work independently with limited oversight and communicate effectively with senior stakeholders.
Preferred Experience:
- Transaction Monitoring, Sanctions, KYC/CDD, or other Financial Crimes platforms.
- Regulatory findings, enforcement-related remediation, or formal issue-closure validation.
- Model risk, model validation, or technology controls supporting automated monitoring/models.
- Payments technology or other complex banking applications.
- Experience working within geographically distributed/global banking environments.
- CISA, CIA, CAMS, CISSP, or similar professional certification.
Schedule Expectations:
This is a remote engagement supporting a global initiative. Candidates should be able to work primarily Eastern Time hours while maintaining flexibility for occasional meetings with stakeholders in Europe, the Middle East, and Asia-Pacific. Some days may require adjusted or split working hours depending on project needs and stakeholder availability.
.