IT Audit Principal
Core
Lead evaluation and monitoring of IT General Controls (ITGC) and cybersecurity controls to ensure compliance with SOX and regulatory requirements for an ERP software company.
Role type
Principal IT Audit and Cybersecurity Risk Manager
Builds
Independent assurance on IT controls, risk assessments, and control rationalization for the ERP software business.
Domain
Software industry, Enterprise Resource Planning (ERP), IT Audit, Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
ITGC auditing, SOX compliance, cybersecurity risk management, SDLC controls, root cause analysis, control documentation, regulatory monitoring, automation/AI integration
Preferred skills
Software industry experience, cloud environment auditing (IaaS/PaaS/SaaS), NIST/ISO 27001 frameworks, GRC platforms, AI tool utilization
Technologies
Kinetic, Salesforce, Workday, Microsoft Azure, Active Directory, Workiva Wdesk, GRC platforms, ChatGPT, Copilot, Claude
Responsibilities
Lead evaluation and ongoing monitoring of ITGCs; Assess cybersecurity controls intersecting with ITGC domains; Drive evaluation of broader cybersecurity programs; Provide thought leadership in IT SOX testing activities; Evaluate SDLC controls for secure system implementation; Partner with cybersecurity teams to assess cloud and infrastructure risks; Act as liaison to external auditors; Lead root cause analysis for control deficiencies; Provide independent advisory on control design and risk mitigation; Develop and maintain IT control documentation; Oversee quarterly SOX certification process; Monitor emerging cybersecurity threats and regulatory changes; Enable continuous improvement via automation and AI solutions; Support executive leadership with special project advisory.
Seniority
Principal, strategic advisory and hands-on execution