Logo for The Hershey Company

Analyst IT Auditor

Role overview

Qualifications

  • Bachelor's Degree in Accounting, Information Technology, Information Systems, Computer Science, Cybersecurity, or a related field
  • Minimum of 2 years of experience in IT Audit, Cybersecurity Audit, IT Compliance, SOX 404 testing, Internal Audit, or related areas
  • Strong understanding of IT General Controls (ITGCs), Application Controls, SOX 404 compliance and testing
  • Strong preference for CISA (Certified Information Systems Auditor) and CPA (Certified Public Accountant) highly preferred

Responsibilities

  • Execute SOX 404 testing for IT General Controls (ITGCs) and application controls across assigned business processes
  • Evaluate the readiness and effectiveness of key IT General Controls and application controls
  • Participate in global IT audit engagements, including infrastructure security and cybersecurity reviews
  • Assess the design and operating effectiveness of controls related to user access management and data integrity

Key facts

Other skills

  • Communication
  • Analytical Thinking
  • Problem Solving
  • Decision Making
  • Collaboration

About the company

The Hershey Company logo

The Hershey Company

Food & Beverage Manufacturing

The Hershey Company is headquartered in Hershey, Pa., and is an industry-leading snacks company known for bringing goodness to the world through its iconic brands, remarkable people and enduring commitment to help children succeed. Hershey has approximately 17,000 employees around the world who work every day to deliver delicious, quality products. The company has more than 90 brands around the world that drive more than $8 billion in annual revenues, including such iconic brand names as Hershey's, Reese's, Kit Kat®, Jolly Rancher, Ice Breakers, SkinnyPop, and Pirate's Booty. For more than 125 years, Hershey has been committed to operating fairly, ethically and sustainably. Hershey founder, Milton Hershey, created the Milton Hershey School in 1909 and since then the company has focused on helping children succeed. To learn more visit www.thehersheycompany.com

Company details

Company typeLarge
IndustryFood & Beverage Manufacturing
Company size10001

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

 
 

About the Role

The IT Audit & SOX Compliance Analyst will be a key member of Hershey's Global Internal Audit team, supporting the organization's efforts to maintain a strong control environment, ensure SOX 404 compliance, and strengthen IT and cybersecurity risk management practices across global operations.

In this role, you will partner with business, finance, and IT stakeholders worldwide to assess the effectiveness of IT General Controls (ITGCs), application controls, cybersecurity controls, and financial reporting processes. You will participate in global audit engagements, control readiness assessments, SOX activities, and special projects related to technology risk, cybersecurity, and operational assurance.

This is a fully remote position based in the Philippines. Occasional office presence may be required when senior leadership or executive management visit the local office. The role follows a mid-shift schedule (2:00 PM to 11:00 PM) and may require up to 5% international travel.


Your Responsibilities

Support SOX 404 Compliance

  • Execute SOX 404 testing for IT General Controls (ITGCs) and application controls across assigned business processes and functions.
  • Partner with Internal Controls teams and business stakeholders to provide guidance on control execution, documentation quality, evidence requirements, and remediation plans.
  • Support quarterly and annual SOX compliance activities, including walkthroughs, readiness reviews, management assistance requests, and coordination with external auditors.
  • Serve as a resource for SOX enablement tools such as Workiva and ServiceNow, providing support and guidance to business users.

Perform Control Readiness Assessments

  • Evaluate the readiness and effectiveness of key IT General Controls and application controls.
  • Identify risks impacting financial reporting, governance, business continuity, cybersecurity, and regulatory compliance.
  • Collaborate with IT and business stakeholders to understand processes, assess controls, communicate findings, and recommend practical remediation actions.
  • Maintain audit project plans and provide timely updates on project progress, risks, and dependencies.
  • Prepare concise, executive-level reporting to communicate key risks and recommended improvements.

Execute IT and Cybersecurity Audits

  • Participate in global IT audit engagements, including infrastructure security, application security, vulnerability management, and cybersecurity reviews.
  • Support Internal Audit's annual IT risk assessment process by identifying emerging technology and cybersecurity risks.
  • Execute audit procedures using recognized frameworks such as COBIT, COSO, and NIST.
  • Document audit work in accordance with IIA standards and internal audit methodology.
  • Develop recommendations that strengthen controls and mitigate identified risks.

Provide Financial & Operational IT Assurance

  • Assess the design and operating effectiveness of controls related to:
    • User access management
    • Segregation of duties
    • Change management
    • Operating system and database security
    • Interface controls
    • Data integrity and transmission controls
    • Third-party service provider risk management
  • Prepare audit findings and reports for management and senior leadership.
  • Support special projects including cybersecurity assessments, system implementation reviews, third-party risk reviews, data analytics initiatives, and other management requests.

Your Background

Education

  • Bachelor's Degree in Accounting, Information Technology, Information Systems, Computer Science, Cybersecurity, or a related field.

Experience

  • Minimum of 2 years of experience in IT Audit, Cybersecurity Audit, IT Compliance, SOX 404 testing, Internal Audit, or related areas.
  • Experience performing IT controls testing, risk assessments, audit procedures, and control evaluations.
  • Exposure to system implementation reviews and enterprise technology environments is preferred.

Technical Skills

  • Strong understanding of:
    • IT General Controls (ITGCs)
    • Application Controls
    • SOX 404 compliance and testing
    • Risk and control frameworks
  • Working knowledge of COBIT, COSO, NIST, or similar frameworks.
  • Experience with ERP systems such as SAP, Microsoft Dynamics, NetSuite, or similar platforms is an advantage.
  • Ability to prepare audit documentation and communicate findings effectively.

Certifications

  • Strong preference for CISA (Certified Information Systems Auditor).
  • CPA (Certified Public Accountant) highly preferred.
  • Additional certifications such as CIA, CRISC, or other relevant audit and risk credentials are advantageous.

Personal Attributes

  • High integrity and strong professional ethics.
  • Excellent communication and stakeholder management skills.
  • Strong analytical thinking, problem-solving, and decision-making abilities.
  • Ability to independently manage multiple priorities in a global environment.
  • Strong collaboration and influencing skills with stakeholders across all organizational levels.
  • Commitment to continuous learning and professional development.
  • Flexibility to work in a mid-shift environment and support a global business.

Job Overview

This role performs assigned audit tasks and recurring processes that support the evaluation of financial, operational, and basic IT controls. The position follows established procedures to complete testing, gather evidence, and document results under general supervision. It identifies routine issues within defined audit areas and prepares clear, structured workpapers. The role contributes to audit planning and risk assessment by compiling information and supporting analysis.

Accountabilities

1. Execute Assigned Audit Testing Across Financial, Operational, and IT Controls
The role performs defined audit and SOX 404 testing steps by strictly following established procedures. It gathers evidence through walkthroughs and validation activities without modifying test design. It documents outcomes clearly to support senior reviewer evaluation.
2. Prepare Workpapers and Organize Documentation for Reviewer Evaluation
The role prepares accurate workpapers that detail testing performed, evidence obtained, and initial results. It identifies routine issues such as process deviations or missing documentation. It organizes materials to support the development of audit observations by senior team members. 
3. Compile Data to Support Risk Assessments and Planning
The role collects data and performs preliminary reconciliation activities to support risk assessment of financial, operational, and IT processes. It identifies recurring issues or exceptions that may inform later stages of testing. It compiles information into structured formats for use by senior auditors in audit planning. 
4. Assist With Fraud Detection and Compliance Testing Under Guidance
The role performs assigned steps to identify anomalies, exceptions, or deviations from compliance requirements. It flags potential indicators of fraud and escalates them to senior auditors for further evaluation. It documents findings to support additional testing or review. 
5. Support Follow-Up and Remediation Validation Activities
The role assists with follow-up testing to determine whether corrective actions were implemented as designed. It follows established procedures to validate updated controls or processes within assigned areas. It summarizes results for senior team members to incorporate into broader remediation analyses.

Minimum Education & Requirements

1+ years

 

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

IT Auditor Related jobs

Other jobs at The Hershey Company

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.