IT Internal Auditor
Core
Execute IT audit testing for SOX compliance, evaluate cybersecurity controls, and develop data analytics/automation routines to assess internal controls over financial reporting.
Role type
Mid-level IT Internal Auditor (SOX & Cybersecurity)
Builds
Independent assurance on SOX compliance, cybersecurity control reviews, and automated audit evidence collection.
Domain
Logistics / Financial Services / IT Audit / Cybersecurity
Deliverable
production ML models | dashboards & analysis | client delivery
Required skills
SOX 404 testing, ITGC/ITAC evaluation, cybersecurity control assessment, Python scripting, SQL, data analytics, Power BI/Tableau, ERP systems knowledge, NIST CSF/CIS Controls/ISO 27001 familiarity
Preferred skills
CISA/CIA/CISSP/CISM/CPA certifications, experience with AI/ML in audit, RPA, cloud security (Azure/AWS/GCP), complex IT systems auditing
Technologies
Python, pandas, SQL, Power BI, Tableau, Azure, AWS, GCP
Responsibilities
Execute IT audit testing for SOX controls (ITGC, ITAC, automated business process controls); Assess design and operating effectiveness of controls for financial systems, data integrity, access management, and change management; Evaluate cybersecurity controls (IAM, privileged access, vulnerability management, logging, data protection, third-party/cloud security) against frameworks like NIST CSF, CIS Controls, and ISO 27001; Develop and maintain SOX testing documentation (risk/control matrices, test plans, workpapers); Identify control deficiencies and work with management on remediation plans; Perform completeness and accuracy testing of Information Provided by Entity (IPE); Design and perform data analytics over full populations using Python and SQL to extract, cleanse, join, and reconcile data; Build and maintain Python-based scripts and repeatable audit routines for evidence collection and workpaper preparation; Develop continuous auditing dashboards and visualizations using Power BI; Support automation efforts including workflow automation and AI/ML application for document review and risk assessment; Maintain version control and quality review over analytics and automation code; Stay current on SOX regulations and emerging IT/cybersecurity/AI risks.
Seniority
Junior to Mid-level, hands-on IC