Lead, IT Audit and Technology RiskActive$185K–$220K

The opportunity

We are seeking a strategic and technically fluent Lead, IT Audit to join our Finance team reporting to the Head of Internal Audit. This is a broad, high-impact role spanning both IT SOX compliance and operational IT audits.

What you'll do

  • Own the full IT SOX lifecycle: scoping, risk assessment, documentation, walkthroughs, testing, deficiency evaluation, remediation, and reporting — driving automation and efficiency across IT general controls (ITGCs) and IT application controls (ITACs)

  • Design, operate, and continuously improve technology controls spanning user: access and segregation of duties, change management, SDLC and CI/CD pipelines, interfaces, data flows, and system-generated reports

  • Design and execute value-added operational IT and cybersecurity audits: across cloud infrastructure, security operations, identity and access management, data protection and privacy, disaster recovery and resilience, and vendor and third-party risk — while driving enterprise-level technology risk assessment that anticipates emerging risks before they materialize

  • Serve as a strategic advisor on cross-functional initiatives (product: launches, new systems, architecture changes, M&A) and as the primary point of contact for external auditors, ensuring sound controls are built in from day one and audit evidence is complete, clear, and timely

  • Own IT control deficiencies from identification through sustained remediation: while partnering with and educating system owners to build a culture of ownership and accountability

  • Champion the adoption of AI and modern tooling: from automated control testing and anomaly detection to continuous monitoring and AI-assisted documentation — to make the IT audit function smarter, faster, and more forward-looking

What they're looking for

  • + years of progressive IT audit, IT SOX, or technology risk experience, with: a combination of Big 4 and high-growth technology company experience
  • Deep, hands-on ownership of IT SOX/ITGC programs, with a strong understanding: of PCAOB standards, SEC requirements, and frameworks such as COSO, COBIT, NIST, and ITIL
  • Demonstrated experience designing and leading operational IT audits end to: end — including annual planning, risk-based scoping, fieldwork, and reporting — across areas such as IT operations, infrastructure resilience, disaster recovery and business continuity, capacity and availability management, and IT vendor and third-party risk
  • Strong cybersecurity audit experience with working fluency in frameworks and: regulations such as NIST CSF, ISO 27001, SOC 2, GDPR, and CCPA, and the ability to translate them into practical, testable controls