Application deadline: October 8th at 12:00PM ET
Position: Principal, IT Audit
Employment Type: Permanent
Compensation Details:- Audit 19: Salaries typically range from $112,006 to $149,341 annually, based on qualifications and experiences, plus a performance-based incentive.
Location:- Export Development Canada operates in a hybrid work environment, with a current requirement of three in-office days per week.
- This role can be performed from EDC's headquarters in Ottawa or from one of our Community Hubs located in Toronto and Montreal
- Relocation assistance is available for candidates who meet the eligibility criteria.
Internal Employees, please consult the ServiceNow article entitled Internal movements - what you need to know.
Team Overview:The Internal Audit function is comprised of two teams: Internal Audit and CS&R. Both teams provide critical services to our organization (including our subsidiary), customers and stakeholders by consistently applying a risk-based mindset, aligned with the organization's values and strategic objectives.
Internal Audit
- Provides independent and objective assurance and advisory services, designed to add value and help the organization achieve its business objectives pertaining to operations, reporting, and compliance with laws and regulations.
- Executes a Quality Assurance and Improvement Program (QAIP) to evaluate and ensure the internal audit function conforms with the Global internal Audit Standards, achieves performance objectives and pursues continuous improvements.
Role Overview:The Principal, IT Audit is a senior individual contributor role responsible for leading and executing complex, high-risk IT audit engagements. The role combines hands-on audit delivery with leadership through expertise, judgment, and influence, ensuring audits are risk-focused, high-quality, and impactful for senior management and the Audit Committee.
As the engagement lead, the Principal is accountable for audit outcomes and leads the most complex and judgment-intensive work, while guiding and reviewing work performed by Senior Individual Contributors (ICs).
This position does not include direct people management. Leadership impact is achieved through leading engagements, setting direction, exercising professional judgment, and raising the overall quality and effectiveness of IT audit work.
Success in this role is measured by audit impact, strength and clarity of conclusions, executive trust, and the ongoing advancement of IT audit practices.
What You Will Be Doing:- Lead and deliver complex IT audits from start to finish, serving as the engagement lead ensuring risk focus, quality, and value.
- Perform hands-on audit work in the most complex and higher-risk areas, including assessing risks, evaluating controls, testing key processes, and forming audit conclusions.
- Define audit scope and approach to focus on critical and emerging technology risks, such as cyber security, cloud services, data and privacy, identity and access management, AI, and third-party technology.
- Guide, review, and challenge audit work performed by Senior Individual Contributors (ICs) to ensure high-quality analysis, sufficient evidence, and sound judgment.
- Develop clear, concise, and impactful audit findings that articulate root causes, risk implications, and meaningful improvement opportunities for senior leadership.
- Prepare and present executive-level audit reports, summaries, and presentations, including material for senior management and the Audit Committee.
- Serve as audit contact for Director and VP-level stakeholders, communicating audit objectives, emerging issues, and conclusions with credibility and clarity.
- Bring a forward-looking perspective to audit work by considering emerging risks, regulatory expectations, and leading industry practices.
- Identify common themes and systemic issues across audits to help inform broader IT risk discussions.
- Support the continuous improvement of IT audit practices, including the use of data analytics and advanced audit techniques.
- Influence audit quality and capability through mentoring, knowledge sharing, and setting expectations.
What we are looking for:- Bachelor's degree in information systems, computer science, engineering, or equivalent relevant experience.
- Professional certifications (e.g., CISSP, CISM, CRISC, CGEIT, CISA) are strongly preferred.
- Minimum of 8-10 years of relevant experience in IT audit, IT risk, cybersecurity, technology governance, or technology assurance.
- Demonstrated experience leading audits and managing stakeholders at multiple levels.
- Strong knowledge of modern IT environments including cloud, identity, networks, endpoint security, data platforms, and agile delivery.
- Working familiarity with frameworks and standards (e.g., NIST, CIS Controls, COBIT, ISO 2700x) and alignment to IIA standards.
- Excellent communication skills-able to distill complex technical risks into clear, decision-ready insights.
- Strong organizational and project management skills, including the ability to manage multiple priorities and deliver to timelines.
What will make you stand out:- A leadership mindset grounded in curiosity, pragmatism, collaboration, and continuous improvement.
- Deep expertise in one or more areas: cybersecurity, cloud security, identity, data governance, third-party risk, or technology resilience.
- Hands-on experience using data analytics tools and techniques (Power BI, ACL/HighBond, IDEA, Python, SQL) to enhance audit testing.
- Practical experience with GenAI use cases for audit (e.g., planning, evidence summarization, control mapping, anomaly detection) with appropriate governance.
- Bilingual (French and English).
Eligibility:EDC is committed to Fair Employment Practices and preference will be given to a candidate who is able to work legally in Canada
at the time of application (Canadian Citizens or Permanent Residents). Candidates must meet the requisite government security screening requirements.
Internal applicants must also meet EDC's eligibility criteria for applying to internal opportunities. For more information, please refer to Section 2.1 in the Talent Acquisition Standard, available on LINK under the Resources tab in the Policies & Procedures section. The position is open to those who meet all of the essential requirements stated above and whose applications are received by the closing date. The position is open to those who meet all of the essential requirements stated above and whose applications are received by the closing date.