10390- Auditor, Integrated Risk Management
$83,940–$120,032 year
On-siteIrvine, California, United States
Job Summary
Develop and maintain a control testing and validation plan aligned to the organization's technology risk landscape, covering cloud, infrastructure, networks, identity, and security tooling. Execute design and operating effectiveness testing across these domains, creating repeatable, audit-ready workpapers and validating control implementation through technical inspection of configurations, logs, and pipeline artifacts. Partner with control owners and engineers to perform walkthroughs, identify gaps, assess risk impact, and provide clear remediation guidance. Track remediation activities, re-test controls for closure, and produce concise reporting for leadership. Support internal and external audits by providing documentation and control narratives. Continuously improve the testing program through standardization and automation opportunities.
Required Qualifications
- Bachelor's degree in Information Systems, Cybersecurity, Information Technology, Computer science or a related field or equivalent work experience
- 5+ years of experience in technology audit, technology risk, or control testing/assurance
- Proven experience performing control testing and validation (design and operating effectiveness), including sampling and evidence standards, across a broad spectrum of technology domains
- Demonstrated strong documentation skills with the ability to produce audit-ready workpapers, test scripts, and results
- Strong stakeholder management with the ability to work effectively with engineers, control owners, leadership and customers
- Knowledge of GRC tooling and workflows
- Excellent stakeholder management and communication skills
- Ability to translate technical details into clear risk statements, issues, and practical remediation recommendations
Desired Qualifications
- Master's degree in Cybersecurity, Information Technology, Computer Science or a related discipline or equivalent work experience AND 5+ years of experience as a Technology Auditor at a large professional services firm (e.g., Big 4 or similar) or comparable complex enterprise environment
- Familiarity with control frameworks and standards such as COSO, COBIT, NIST, ISO 27001, and/or SSAE 16 requirements
- Industry-recognized credentials such as CISSP, CISM, CISA
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.