Job purpose
The Senior IT Auditor is responsible for executing and supporting a range of internal audit activities under the direction of the Internal Audit Manager and Senior Manager Internal Audit, including SOX 404 testing (ITGCs, automated, etc.), data analysis, query code/logic review and testing, identifies deficiencies, and develops clear, well-supported audit conclusions. This role evaluates the efficiency and effectiveness of internal controls, ensures compliance with company policies and regulatory requirements, and provides value-added recommendations to improve process and strengthen controls. This position also supports program activities including SOX scoping, risk assessment, planning, external auditor coordination, and continuous improvement. All audit work must be performed in a timely and high-quality manner while maintaining strong client relationships and demonstrating professional conduct at all times.
Duties and ResponsibilitiesSOX & Risk Assessment
- Support the IT SOX Manager in annual SOX planning, including scoping significant systems, applications, interfaces, reports, queries, and technology processes supporting financial reporting.
- Execute testing of ITGCs, automated controls, IT-dependent manual controls, system-generated reports, key queries, and related technology controls, including walkthroughs, evidence requests, testing procedures, sampling, evaluation of results, and conclusions.
- Identify control gaps, deficiencies, and process improvement opportunities, and clearly document issues, root causes, and potential impact.
- Evaluate control design and operating effectiveness and maintain high-quality RACMs, narratives, flowcharts, walkthroughs, testing workpapers, sampling documentation, and conclusions in accordance with Internal Audit methodology and SOX requirements.
- Manage assigned activities to established timelines and quality expectations and escalate significant matters to the IT SOX Manager.
- Key technology areas include, but are not limited to:
- IT infrastructure and operations,
- ERP and enterprise applications,
- Cloud and SaaS environments,
- Identity and access management,
- SDLC/change management,
- Interfaces and system integrations,
- Cybersecurity and information security controls,
- Data governance and privacy,
- System implementations and conversions.
Data Analytics & Automation
- Perform advanced data analysis to support audit testing and risk identification using tools such as SQL, Python, Power BI, Excel, and visualization tools where applicable.
- Extract, transform, and analyze large datasets to identify anomalies, control failures, trends, and operational inefficiencies.
- Develop and enhance automated audit testing procedures to improve efficiency, coverage, and accuracy of audit work.
- Support continuous auditing and monitoring initiatives through data-driven insights and repeatable analytic routines.
Technology Risk & Technical Expertise
- Apply strong technical knowledge when evaluating IT risks, control design, operating effectiveness, system dependencies, and financial reporting reliance across enterprise applications, ERP systems, cloud/SaaS, databases, infrastructure, interfaces, and integrations.
- Evaluate application security, identity and access management, change management, system operations, data integrity, cybersecurity, and other ITGC areas supporting financial reporting.
- Evaluate automated controls and system-generated information by considering underlying system logic, data sources, configurations, interfaces, and IT dependencies.
- Assess SOC 1/SOC 2 reports and complementary user entity controls, as applicable, and participate in assessments involving cybersecurity, cloud adoption, system implementations, AI, automation, and other emerging technologies.
- Use data analytics, automation, and technology-enabled audit techniques to improve testing efficiency, coverage, and effectiveness while escalating significant technology risks to the IT SOX Manager.
- Perform the annual key reports and queries testing project, including reading, interpreting, analyzing, and, where appropriate, writing or modifying code and reporting logic (including SQL, Python, stored procedures, scripts, formulas, and system/report configurations) to assess the completeness, accuracy, integrity, and reliability of system-generated information relied upon for SOX controls.
Stakeholder Engagement & Communication
- Build effective working relationships with IT, Finance, business and control owners, Internal Audit, co-sourced resources, and external auditors to support timely execution of assigned SOX activities.
- Serve as a knowledgeable point of contact for assigned controls and audit areas, providing practical guidance on control requirements, testing expectations, evidence, and documentation.
Minimum Qualifications- Education: Bachelor’s degree in Accounting, Finance, Information Systems, or Computer Science.
- Experience: 4-7 years of experience in IT audit, SOX compliance, external audit, internal audit, risk advisory, or related functions.
- Experience testing ITGCs, automated controls, IT-depdendent manual controls, and IPE in publicly traded companies subject to SOX requirements.
- Experience evaluating system-generated reports, report/query logic, data integrity, and related technical dependencies.
- Experience documenting and evaluating control deficiencies and remediation, leading audit engagements, and reviewing work performed by others.
Preferred Qualifications- Professional certifications such as CISA strongly preferred; CPA or CIA are a plus
- Big 4 or Top 10 public accounting experience and/or experience supporting integrated audits under PCAOB standards.
- Advanced experience with IT audit tools, data analytics, and visualization platforms (e.g., SQL, Python, ACL, IDEA, Power BI, Tableau)
- Experience with GRC platforms such as AuditBoard, Workiva, Archer, or MetricStream.
- Experience supporting digital transformation, system implementations, emerging technologies, or technology risk initiatives.
Critical Competencies- Strong expertise in IT audit, SOX compliance, ITGCs, cybersecurity risk, and technology governance.
- Professional skepticism, sound judgment, integrity, and ability to challenge evidence and conclusions appropriately.
- Strong written and verbal communication skills, including the ability to explain complex technical and control matters to technical and non-technical stakeholders.
- Strong organization and project management skills with the ability to manage multiple priorities and deadlines.
- Collaborative, independent, accountable, and continuous-improvement mindset with openness to automation and emerging technologies.
Working ConditionsThis is a hybrid position that requires 3 days of onsite work, with remote work capability for 2 days, depending upon work performance.