Fair Isaac Corporation

Internal Audit - Manager (Remote)

Fair Isaac Corporation$80K — $126K *
US-AnywhereRemote in San Diego, CA
Finance & Insurance
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in IT, computer science, accounting, or equivalent experience.
  • 3-5 years of IT audit experience, preferably in public accounting or corporate audit.
  • Hands-on experience with ERP systems (Oracle preferred) and cloud applications.
  • Strong enthusiasm for AI and automation in auditing processes.
  • Knowledge of identity governance and privileged access management concepts.
  • Cloud auditing experience, particularly with AWS, Azure, or GCP.
  • Familiarity with control frameworks such as COSO, NIST, and ISO standards.

Responsibilities

  • Lead IT audit engagements from scoping to remediation validation.
  • Own the SOX 404 IT general controls program for financial applications.
  • Conduct IT application control testing across ERP systems.
  • Perform data-driven segregation of duties analysis and automate processes.
  • Audit identity and access management across enterprise services.
  • Evaluate change and release management controls in DevOps environments.
  • Assess controls over cloud infrastructure and data integrity.

Benefits

  • Inclusive work culture reflecting core values.
  • Opportunity for professional development and impact.
  • Competitive compensation and benefits programs.
  • People-first work environment promoting work/life balance.
  • Opportunities for social interactions and team-building events.
Full Job Description
The Opportunity

Join our top-notch risk and assurance team within a global, fast-growing and progressive data analytics and cutting-edge AI oriented software company. If you're eager to feel empowered and apply your creativity and experience in a way that adds value and serves to mitigate business risks across the enterprise, this is the opportunity for you. This is a hands-on lead role. You will own the IT audit coverage for a defined portfolio of FICO's financial applications, cloud platforms and security tooling - running engagements end to end, setting the testing approach, and raising the bar on how we use data, automation and AI to get assurance.

What You'll Contribute
  • Lead IT audit engagements end to end with limited supervision - scoping and risk assessment, walkthroughs, design and operating effectiveness testing, issue development, and remediation validation.
  • Own the Sarbanes-Oxley Section 404 (SOX 404) IT general controls program for an assigned portfolio of in-scope financial applications and supporting infrastructure, spanning access to programs and data, change management, program development, and IT operations.
  • Test IT application controls, key reports, interfaces and system-generated data supporting financial reporting across our ERP and other in-scope financial applications.
  • Perform annual and ad-hoc segregation of duties (SoD) analysis. This is data-driven work: extracting role and entitlement data from source systems, normalizing and deduplicating it, applying and maintaining a conflict ruleset, identifying conflicting access combinations and privileged access exceptions, and working with process owners to validate, justify or remediate what surfaces. A standing goal for this role is to automate the extraction, normalization and comparison steps so the analysis becomes a repeatable, monitorable process rather than a once-a-year manual exercise.
  • Audit identity and access management across the enterprise - directory services, enterprise single sign-on, identity governance and access certification platforms, and privileged access and secrets management tooling (password vaults and safes) - covering joiner/mover/leaver provisioning, privileged access, and periodic user access reviews.
  • Evaluate change and release management controls across modern DevOps toolchains - Git-based source control, CI/CD pipelines, and IT service management platforms such as Jira and ServiceNow - including automated approvals and separation of duties between development and production.
  • Assess controls over cloud infrastructure and enterprise data platforms, covering configuration, encryption, logging and monitoring, and data pipeline integrity.
  • Perform cybersecurity and cloud security assessments across FICO's SaaS product environments that hold sensitive client data.
  • Support third-party risk and service organization report reviews - evaluating SOC 1 and SOC 2 reports, transcribing and mapping complementary user entity controls (CUECs) to FICO controls, and assessing subservice organization coverage and bridge letters.
  • Contribute to emerging-risk coverage as FICO's use of AI expands, including AI and model governance controls evaluated against frameworks such as the NIST AI Risk Management Framework and ISO/IEC 42001.
  • Apply data analytics and AI-assisted tooling to audit work - scripted population extraction, full-population testing where practical, and automated continuous monitoring - rather than defaulting to manual sampling.
  • Prepare clear, well-supported work papers; summarize findings and review them with the Chief Audit Executive and/or the Senior Manager, IT Risk & Assurance.
  • Act as the liaison between our external auditors and internal stakeholders across a wide variety of topics and projects. This means coordinating IT scoping and walkthroughs, owning evidence and PBC requests end to end, supporting reliance discussions on internal audit work, translating external auditor expectations into practical asks for system and process owners, and tracking open items through to closure so neither side is left waiting.
  • Partner with IT, Engineering, Security, Finance and business process owners so that population and sample requests are identified, communicated and retrieved efficiently.
  • Drive improvement of FICO's internal control structure through practical control design and process enhancement recommendations.
  • Coach and review the work of junior auditors and co-sourced resources, and help maintain testing standards, templates and documentation quality across the team.
  • Proactively keep leadership informed of progress, control weaknesses and audit findings; meet established deadlines while maintaining confidentiality when dealing with sensitive information and situations.


What We're Seeking
  • Bachelor's degree in information technology, information systems, computer science, accounting or a related field; equivalent practical experience will be considered.
  • Approximately 3-5 years of progressive IT audit experience - public accounting, a national firm, or corporate internal audit at a technology, SaaS or financial services company. At least 3 years is recommended, including meaningful exposure to owning or leading ITGC and SOX 404 testing rather than executing someone else's test steps.
  • Hands-on experience testing IT general and application controls over a major ERP - Oracle strongly preferred, SAP, NetSuite or comparable also valued - and over cloud-hosted business applications such as HCM, CRM, revenue and data warehouse platforms.
  • Real enthusiasm for using AI and automation to change how audit work gets done. Our team uses Claude daily and is actively building AI-assisted workflows: drafting and rolling forward testing narratives, mapping SOC report CUECs to our control set, cleaning and normalizing large access extracts, sizing and documenting samples, summarizing evidence, and replacing recurring manual procedures with scripts and continuous monitoring. You do not need to arrive an expert - but you should be the kind of auditor whose first instinct is to ask whether a task can be automated or monitored rather than repeated by hand every year.
  • Working knowledge of identity governance and privileged access concepts - directory services, single sign-on, access certification, and privileged credential management - and the ability to evaluate access evidence critically rather than accept a system-generated report at face value.
  • Cloud audit experience in AWS (Azure or GCP also relevant), covering IAM, logging, network segmentation, key management and configuration baselines.
  • Familiarity with the control frameworks and regulatory standards we operate against: COSO 2013, COBIT, NIST CSF and SP 800-53, ISO/IEC 27001, SOC 1 and SOC 2, PCI DSS, GDPR, HIPAA and US state privacy law including the CCPA/CPRA.
  • Data and scripting ability. Advanced Excel, including Power Query, is expected. Beyond that we are deliberately looking to add technical depth to the team - SQL and Python are the most immediately useful, and PowerShell, VBA, Power BI or Tableau, shell scripting, regular expressions, and working with REST APIs are all genuinely valuable here. Real depth in two or three of these counts for far more than passing familiarity with all of them.
  • CISA achieved or actively being pursued. CISSP, CIA, CRISC, CPA, ISO/IEC 27001 Lead Auditor or an AWS certification are a plus.
  • Experience with GRC and audit management platforms (AuditBoard, ServiceNow IRM, Workiva or similar) preferred.
  • Pro-active and independent thinking in analyzing and developing solutions to complex problems.
  • Strong written and verbal communication - able to explain a technical control failure to a non-technical finance or business audience and hold the line on a finding constructively.
  • Comfortable working across global teams and time zones in a fast-moving public company environment.


Our Offer to You
  • An inclusive culture strongly reflecting our core values: Act Like an Owner, Delight Our Customers and Earn the Respect of Others.
  • The opportunity to make an impact and develop professionally by leveraging your unique strengths and participating in valuable learning experiences.
  • Highly competitive compensation, benefits and rewards programs that encourage you to bring your best every day and be recognized for doing so.
  • An engaging, people-first work environment offering work/life balance, employee resource groups, and social events to promote interaction and camaraderie.
  • The targeted base pay range for this role is: $80,500 to $126,500 with this range reflecting differences in candidate knowledge, skills and experience.


#LI-CG1

#LI-REMOTE

About Fair Isaac Corporation

Fair Isaac Corporation, also known as FICO, is a data analytics company that provides credit scoring services and decision management solutions to businesses in various industries. The company was founded in 1956 and is headquartered in San Jose, California. FICO's products and services are used by banks, credit card companies, insurance companies, retailers, and other businesses to make data-driven decisions about credit risk, fraud detection, customer acquisition, and more. The company is committed to using advanced analytics and artificial intelligence to help businesses make better decisions and improve their bottom line.
Learn more about Fair Isaac Corporation
Size
3,460 employees
Market Cap
$15.2 billion
Industry
Net Income
$267.9 million
Founded
1956
5 Year Trend
+8.1%
Revenue
$1.3 billion
NASDAQ

Similar Jobs

More Jobs at Fair Isaac Corporation

More Finance & Insurance Jobs

Find similar Internal Audit - Manager (Remote) jobs: