Note: This position requires presence in our San Jose or San Francisco office location 4 days per week; Lambda's designated work from home day is currently Tuesday.
What You'll DoWe are seeking an experienced Senior Auditor - IT Systems and Controls to join our Internal Audit function, reporting to the Internal Audit Lead - IT Systems and Controls. You will independently execute IT SOX testing for your assigned systems, review testing performed by co-sourced or junior team members, and be a credible, experienced voice with engineering, IT, and security teams across Lambda's homegrown platform and third-party SaaS applications.
- SOX IT Controls & Assurance
- Plan, execute, and document SOX testing for IT General Controls (ITGCs), IT Automated Controls, and Key Reports across assigned in-scope systems, exercising independent judgment on complex or ambiguous control questions.
- Contribute to the annual IT SOX scoping and risk assessment process for assigned systems, in alignment with the overall ICFR and SOX program.
- Conduct walkthroughs and design/effectiveness testing of IT controls across homegrown and third-party systems, engaging directly with control owners and engineering leads.
- Review the testing work of co-sourced resources or junior team members for quality, completeness, and adherence to methodology.
- Coordinate evidence collection and remediation efforts, holding process and system owners accountable to agreed timelines.
- Identify control deficiencies, evaluate severity and root cause, and partner with engineering and IT management to design and validate effective remediation.
- Maintain ICFR/SOX 404 documentation for assigned areas, including COSO framework mapping, process and control narratives/flowcharts, risk and controls matrices, and testing approach.
- Apply professional skepticism to independently evaluate and conclude on control design and operating effectiveness.
- IT & Data Assurance Projects
- Execute internal audit and advisory projects focused on IT, data governance, and emerging technology risk, with a primary focus on internal controls over financial reporting.
- Advise technology and business stakeholders on IT risk management and control optimization for their assigned area.
- Evaluate data integrity, system development practices, access management, and change management processes across homegrown and third-party systems.
- Partner directly with engineering and IT teams to design practical, scalable controls that fit a fast-moving codebase and infrastructure.
- Control Evaluation & Remediation
- Assess the severity and impact of control deficiencies, including evaluation of aggregation and compensating controls.
- Work with engineering and IT process owners to develop, track, and validate remediation plans on time.
- Recommend process improvements and efficiency opportunities while maintaining control effectiveness.
- Stakeholder Collaboration
- Serve as the day-to-day point of contact for IT, Engineering, and Security teams on IT SOX and assurance activities for assigned systems.
- Support external auditors during IT SOX testing for assigned systems, providing evidence, walkthroughs, and context as needed.
- Provide guidance to IT and business stakeholders, and informal coaching to co-sourced or junior team members, on IT control requirements and leading practices.
- Reporting & Communication
- Prepare clear, well-organized workpapers and status updates on testing results and remediation progress for the Internal Audit Lead and Head of Internal Audit, including materials to support their Audit Committee reporting.
- Translate technical IT control issues into business-relevant language for non-technical stakeholders.
- Monitor industry and regulatory developments relevant to assigned systems, flagging emerging risks to the Internal Audit Lead.
You- Education & Certification
- Bachelor's degree in Information Systems, Computer Science, Accounting, or related field.
- CISA strongly preferred; CISSP, CPA, or CIA a plus.
- Experience
- 8+ years of progressive experience in IT audit, IT risk, or IT SOX compliance, at a level equivalent to Manager at a Big Four accounting firm, or an internal audit professional with comparable scope and seniority in industry.
- Big Four accounting firm or equivalent experience in Internal or External Audit or IT consulting practice, including experience reviewing and directing the work of junior staff.
- Deep expertise in ITGCs, IT Automated Controls, key report testing, and their relevance to ICFR, internal audit methodology, and IIA standards.
- Experience independently leading audits of both homegrown business systems and third-party SaaS applications.
- Demonstrated experience in data governance, system implementation reviews, and cybersecurity risk assessments.
- Experience working with audit management tools (e.g., AuditBoard, Archer, Workiva) to manage SOX and IT compliance programs.
- Skills & Competencies
- Strong analytical and technical skills with the ability to independently evaluate IT and data risks across complex environments.
- Excellent communication and interpersonal skills to effectively engage with, and influence, both technical and non-technical senior stakeholders.
- Proven ability to review and quality-check the work of junior team members or co-sourced resources, even without formal direct reports.
- Organized, detail-oriented, and able to manage multiple concurrent engagements in a dynamic, fast-growth environment with minimal oversight.
Nice to Have- Experience with data analytics and automated testing tools (e.g., SQL, Python, ACL, Power BI) to enhance SOX testing efficiency and insights.
- Exposure to emerging technologies such as cloud computing, cybersecurity, and RPA, and their control implications.
- Prior experience working in a fast-growth or pre-IPO organization, building or scaling a SOX program ahead of public-company readiness.
- Familiarity with cybersecurity frameworks (e.g., NIST, ISO 27001, COBIT) and their application to IT risk management.
- Experience auditing engineering practices such as GitHub-based change management, CI/CD pipelines, or internally managed databases.
- Prior involvement in system implementation or upgrade reviews for ERP, financial systems, or homegrown applications.
- Experience presenting findings to senior leadership or an Audit Committee.
Salary Range InformationThe annual salary range for this position has been set based on market data and other factors. However, a salary higher or lower than this range may be appropriate for a candidate whose qualifications differ meaningfully from those listed in the job description.