Overview
This hands-on lead role in IT Risk & Assurance focuses on owning IT audit coverage for a defined portfolio of financial applications, cloud platforms, and security tooling. Responsibilities include running engagements end to end, defining testing approaches, and raising the bar on how assurance is delivered using data analytics, automation, and AI.
Responsibilities
- Lead IT audit engagements end to end with limited supervision, including:
- Scoping and risk assessment
- Walkthroughs
- Design and operating effectiveness testing
- Issue development
- Remediation validation
- Own the Sarbanes-Oxley Section 404 (SOX 404) IT general controls (ITGC) program for an assigned portfolio of in-scope financial applications and supporting infrastructure, including:
- Access to programs and data
- Change management
- Program development
- IT operations
- Test IT application controls, key reports, interfaces, and system-generated data supporting financial reporting across ERP and other in-scope financial applications.
- Perform annual and ad-hoc segregation of duties (SoD) analysis:
- Extract role and entitlement data from source systems
- Normalize and deduplicate data
- Apply and maintain a conflict ruleset
- Identify conflicting access combinations and privileged access exceptions
- Partner with process owners to validate, justify, or remediate results
- Automate extraction, normalization, and comparison steps to enable repeatable, monitorable analysis
- Audit identity and access management across the enterprise, covering:
- Directory services
- Enterprise single sign-on
- Identity governance and access certification platforms
- Privileged access and secrets management tooling (password vaults and safes)
- Joiner/mover/leaver provisioning, privileged access, and periodic user access reviews
- Evaluate change and release management controls across modern DevOps toolchains, including:
- Git-based source control
- CI/CD pipelines
- IT service management platforms such as Jira and ServiceNow
- Automated approvals and separation of duties between development and production
- Assess controls over cloud infrastructure and enterprise data platforms, including:
- Configuration
- Encryption
- Logging and monitoring
- Data pipeline integrity
- Perform cybersecurity and cloud security assessments across SaaS product environments holding sensitive client data.
- Support third-party risk and service organization report reviews, including:
- Evaluating SOC 1 and SOC 2 reports
- Transcribing and mapping complementary user entity controls (CUECs) to internal controls
- Assessing subservice organization coverage and bridge letters
- Contribute to emerging-risk coverage as AI use expands, including AI and model governance controls evaluated against frameworks such as the NIST AI Risk Management Framework and ISO/IEC 42001.
- Use data analytics and AI-assisted tooling to audit work, such as:
- Scripted population extraction
- Full-population testing where practical
- Automated continuous monitoring
- Prepare clear, well-supported work papers and summarize findings for review with the Chief Audit Executive and/or the Senior Manager, IT Risk & Assurance.
- Serve as a liaison between external auditors and internal stakeholders:
- Coordinate IT scoping and walkthroughs
- Own evidence and PBC requests end to end
- Support reliance discussions on internal audit work
- Translate external auditor expectations into practical requests for system and process owners
- Track open items through to closure
- Partner with IT, Engineering, Security, Finance, and business process owners to efficiently identify, communicate, and retrieve population and sample requests.
- Drive improvements to the internal control structure through practical control design and process enhancement recommendations.
- Coach and review junior auditors and co-sourced resources; help maintain testing standards, templates, and documentation quality.
- Provide proactive updates to leadership on progress, control weaknesses, and audit findings; meet deadlines while maintaining confidentiality.
Requirements
- Bachelor’s degree in information technology, information systems, computer science, accounting, or a related field; equivalent practical experience will be considered.
- Approximately 3–5 years of progressive IT audit experience, including exposure to public accounting, a national firm, or corporate internal audit in a technology, SaaS, or financial services environment.
- At least 3 years is recommended, including meaningful exposure to owning or leading ITGC and SOX 404 testing (not just executing others’ test steps).
- Hands-on experience testing IT general and application controls over a major ERP—Oracle strongly preferred; SAP, NetSuite, or comparable also valued.
- Hands-on experience testing cloud-hosted business applications such as HCM, CRM, revenue, and data warehouse platforms.
- Strong interest in using AI and automation to change how audit work is performed, including replacing recurring manual procedures with scripts and continuous monitoring.
- Working knowledge of identity governance and privileged access concepts, including the ability to evaluate access evidence critically.
- Cloud audit experience in AWS (Azure or GCP also relevant), including:
- IAM
- Logging
- Network segmentation
- Key management
- Configuration baselines
- Familiarity with control frameworks and regulatory standards, including:
- COSO 2013
- COBIT
- NIST CSF and SP 800-53
- ISO/IEC 27001
- SOC 1 and SOC 2
- PCI DSS
- GDPR
- HIPAA
- US state privacy law, including the CCPA/CPRA
- Data and scripting capability:
- Advanced Excel, including Power Query, expected
- SQL and Python are immediately useful
- PowerShell, VBA, Power BI or Tableau, shell scripting, regular expressions, and working with REST APIs are valuable
- Depth in two or three of these areas is preferred over broad but shallow familiarity
- CISA achieved or actively being pursued.
- CISSP, CIA, CRISC, CPA, ISO/IEC 27001 Lead Auditor, or an AWS certification are a plus.
- Experience with GRC and audit management platforms (AuditBoard, ServiceNow IRM, Workiva, or similar) preferred.
- Proactive and independent thinking in analyzing and developing solutions to complex problems.
- Strong written and verbal communication skills, including the ability to explain technical control failures to non-technical finance or business audiences while supporting a sound finding.
- Comfortable working across global teams and time zones in a fast-moving public company environment.
Preferred Qualifications
- Experience with GRC and audit management platforms (AuditBoard, ServiceNow IRM, Workiva, or similar).
- Certifications such as CISSP, CIA, CRISC, CPA, ISO/IEC 27001 Lead Auditor, or an AWS certification.
Compensation & Benefits
- Targeted base pay range: $80,500 to $126,500 (range reflects differences in candidate knowledge, skills, and experience).
- Competitive compensation, benefits, and rewards programs.
- Work/life balance support and an inclusive, people-first work environment.
- Employee resource groups and social events.
Location
Not specified in the provided job description.