Please note: State agencies that contact job applicants do not usually request personal or financial information via text message or over the phone in connection with your response to a job posting. If you are contacted for such information by these methods, or any other method, please verify the identity of the individual before transmitting such information to that person.

Review Vacancy

Date Posted 02/01/24

Applications Due04/01/24

Vacancy ID149907


AgencyState Comptroller, Office of the

TitleInformation Systems Auditor 1, Item #02921

Occupational CategoryFinancial, Accounting, Auditing

Salary Grade23

Bargaining UnitPS&T - Professional, Scientific, and Technical (PEF)

Salary RangeFrom $81705 to $103350 Annually

Employment Type Full-Time

Appointment Type Contingent Permanent

Jurisdictional Class Non-competitive Class

Travel Percentage 10%

Workweek Mon-Fri

Hours Per Week 37.5


From 8 AM

To 4 PM

Flextime allowed? No

Mandatory overtime? No

Compressed workweek allowed? Yes

Telecommuting allowed? Yes

County To Be Determined

Street Address Office of the New York State Comptroller

TBD (see additional comments)

City TBD (see additional comments)


Zip Code00000

Minimum Qualifications Non-Competitive: Seven years of IT audit experience*.
Seven years of Information Technology audit experience, which must have been gained in any one of combination of the following (experience may be concurrent) See education and experience substitutions below.
• Responsibility for performing IT-related audits and examinations to determine the compliance of agencies, authorities, municipalities, and schools, including reviews of physical and logical access controls, general IT controls, and application controls, and the writing and presentation of findings reports of technical issues to a non-technical audience.
• Responsibility for the analysis and evaluation of information systems, such as platforms, applications, network infrastructure, and/or IT-related operational practices and the writing and presentation of reports of findings suitable for non-technical audience.
• Responsibility for supporting an audit group, such as designing, developing/programming, maintaining technological solutions in support of audit activity, and evaluating and developing artificial intelligence programs in support of audit activity.

Education/Experience Substitution: an Associate’s degree may be substituted for up to two years of IT audit experience; a bachelor’s degree may be substituted for up to four years of IT audit experience; a master’s degree may be substituted for an additional one year of IT audit experience (i.e., up to five years of experience). There is a maximum of 5 years of educational substitution. Additionally, one year of generalized audit experience** may be substituted for one year of IT audit experience.
**Generalized audit experience - Performed performance audits in accordance with Generally Accepted Government Auditing Standards; analyzed areas for audit, addressed areas of risk; evaluated systems and procedures relating to audit areas for compliance with applicable laws, rules and regulations and contract terms, as appropriate; ensured funds are utilized in accordance with laws and regulations, and proper and effective controls are in place for areas under audit; used computer assisted auditing tools and techniques across various platforms to meet audit objectives; determined the accuracy and completeness of computer-processed data, prepared audit work papers to document work done and conclusions; prepared preliminary audit findings or portions thereof, discussed findings with auditee representatives, and participated in exit and entrance conferences.

• An Associate’s degree may be substituted for up to two years of IT audit experience; a Bachelor’s degree may be substituted for up to four years of IT audit experience; a Master’s degree may be substituted for an additional one year of IT audit experience (i.e., up to five years of experience). There is a maximum of 5 years of educational substitution.
• Additionally, one year of generalized audit experience* may be substituted for one year of IT audit experience.

Duties Description Performs IT Audits and IT Specialized Projects
Under the supervision of an Information Systems Auditor 2, performs IT audits in accordance with applicable auditing standards and IT security requirements; analyzes areas for audit; helps establish scope and areas of risk; suggests approaches for addressing risk; analyzes and evaluates the adequacy of agency IT policies and procedures; conducts interviews with auditees and performs walk-throughs to assist in the evaluation of controls; examines internal controls to evaluate the extent to which proper and effective controls are in place; reviews general and application controls of agencies information security programs, performs various IT testing methodologies during audits; examines transactions and supporting documentation to determine legitimacy, fraud, waste and abuse.
• Consults with other audit teams as necessary on IT areas during financial or performance audits and provides expertise on highly technical IT matters, including developing IT audit programs, inspecting data, systems, and controls to assess risk and determine areas of audit and other projects.
• Works on specialized IT audits, projects, and studies that incorporate, for instance, advanced computer programming, complex IT matters, and emerging technologies.
• Prepares audit work papers to document work done and conclusions; prepares preliminary audit findings, discussion documents, draft reports and/or special project reports or portions thereof; discusses findings with auditee representatives and participates in entrance and exit conferences.

• May assist in the supervision of program examiners, trainees or students providing guidance and support by evaluating working papers for completeness, accuracy, and adequacy of supporting documentation.

• May perform tasks assessing program risks to plan potential audits, work on special projects or audit research efforts and may also assist in a variety of other areas supporting the IT audit work.

Additional Comments Additional Comments:
Location: State Government Accountability
Albany or New York City
110 State Street OR 59 Maiden Lane
Albany, NY 12236 New York, NY 10038

Desired Competencies:
• Strong verbal and written communication skills.
• Strong capacity in auditing skills such as professional skepticism, persistence, creative thinking, and risk taking.
• Strong analytical and problem-solving abilities.
• Excellent interpersonal and team skills.
• Proficient in use of technology such as Microsoft Office Suite and familiar with audit software used by SGA.
• Knowledge of the NYS Comptroller’s Office and the Division of State Government Accountability.
• Experience in use of various IT audit software tools and techniques to identify system weaknesses.
• Experience with network operating systems, security software system, and key application systems

Telecommuting: The Office of the New York State Comptroller (OSC) supports telecommuting where it is reasonable to do so based upon the agency’s mission and operational needs. Generally, employees new to OSC will be restricted from telecommuting for at least 8 calendar weeks. After the initial 8 calendar week restriction, if an employee’s duties and work performance are aligned with telecommuting they may be allowed to do so. Upon approval to telecommute, OSC employees may telecommute up to 5 days per pay period.

Some positions may require additional credentials or a background check to verify your identity.

Name Sara Burt

Telephone (518) 474-1924

Fax (518) 486-6723

Email Address


Street Office of Human Resources

110 State Street, 12th Floor

City Albany

State NY

Zip Code 12236


Notes on ApplyingSubmit a clear, concise cover letter, resume, and a completed copy of this template: 02921-information-systems-auditor-1-mq-template-1-2024.doc ( via e-mail to , no later than April 1, 2024. Documents must be sent as unlocked and accessible attachments.
Reference Item #02921-SAB in the subject line of your email and on the cover letter for proper routing.
Important Notes: To access the required template, copy the link above and paste it into your web browser, then download, complete, and save to submit with your email response. You MUST complete the linked template in full to demonstrate you meet the minimum qualifications for this position. Interview selection is based SOLELY on the information you provide in this document, incomplete or vague information will not be viewed in your favor.
If you have questions about this vacancy, please contact this Division representative:
Division contact: Kimberly Bott,

When responding, please include the reference number and letters listed in this section only. The OER ID # should not be included.
Be sure to submit an unofficial copy of any transcripts you may have with your cover letter, resume, and completed template, as there are educational requirements for this position.

Printable Version