GitLab7 дней назад
Senior Internal Auditor, Technology
Зарплата не указана
Remote
Обязанности
- 01Execute technology audits covering SOX compliance, cloud infrastructure across Amazon Web Services, and Google Cloud Platform, application controls, cybersecurity, artificial intelligence and machine learning systems, and DevSecOps practices
- 02Design and test IT general controls, application controls, and entity-level controls with minimal supervision
- 03Support the IT SOX program from planning through reporting, including risk-based audit planning, process walkthroughs, testing, and coordination with external co-source providers
- 04Maintain clear, high-quality audit documentation, including risk and control matrices, process flows, test procedures, findings, and business impact assessments
- 05Own remediation efforts by partnering with process owners on practical corrective action plans, validating effectiveness before closure, and preparing status updates for leadership
- 06Collaborate with Engineering, IT Operations, Security, and business process owners to assess emerging risks and evaluate new system implementations for control adequacy and SOX relevance
- 07Review controls across financial statement cycles, including record to report, order to cash, hire to retire, and procure to pay, as well as third-party System and Organization Controls 1 and 2 reports
- 08Use data analytics, automation, and generative artificial intelligence tools to improve audit efficiency, coverage, and quality
Требования
- 01Experience executing technology audits and risk management work in complex technology environments, including audit planning, testing, reporting, and remediation
- 02Experience supporting IT SOX programs and designing and testing IT general controls and application controls
- 03Knowledge of IT control frameworks such as COBIT, the National Institute of Standards and Technology framework, Information Technology Infrastructure Library, ISO 27001, and the Committee of Sponsoring Organizations of the Treadway Commission Internal Control Framework
- 04Knowledge of cloud security principles and cybersecurity fundamentals, including network security, encryption, identity and access management, vulnerability management, and Zero Trust principles
- 05Experience with modern development practices, including Agile and DevOps, and with data analytics and audit automation tools
- 06Clear written and verbal communication skills, with the ability to explain technical findings, business impact, and practical recommendations to technical and business audiences
- 07A self-directed, collaborative approach to managing multiple priorities, adapting to change, and helping teams improve their risk and control environments
- 08A bachelor’s degree in Accounting, Information Technology, Computer Science, Finance, or a related field, and an active relevant professional certification such as Certified Public Accountant, Certified Internal Auditor, Certified Information Systems Auditor, Certified Information Systems Security Professional, Certified Information Security Manager, Certified in Risk and Information Systems Control, or an equivalent certification
Условия
- 01Benefits to support your health, finances, and well-being
- 02Flexible Paid Time Off