Lead, IT Audit and Technology Risk
$185,000–$220,000 year
RemoteUnited States
Job Summary
Own the full IT SOX lifecycle, from scoping and risk assessment to testing, deficiency evaluation, and reporting, while driving automation across IT general and application controls. Design and operate technology controls spanning user access, change management, SDLC, CI/CD pipelines, and data flows. Execute value-added operational IT and cybersecurity audits covering cloud infrastructure, identity management, data protection, and vendor risk, anticipating emerging threats before they materialize. Serve as a strategic advisor on cross-functional initiatives and the primary point of contact for external auditors, ensuring controls are built in from day one. Lead IT control deficiencies through sustained remediation and partner with system owners to build a culture of accountability. Champion the adoption of AI and modern tooling for automated control testing and continuous monitoring. This role is based in San Francisco or New York City with a hybrid schedule on Mondays, Tuesdays, and Thursdays.
Required Qualifications
- 12+ years of progressive IT audit, IT SOX, or technology risk experience
- combination of Big 4 and high-growth technology company experience
- Deep, hands-on ownership of IT SOX/ITGC programs
- strong understanding of PCAOB standards
- SEC requirements
- frameworks such as COSO, COBIT, NIST, and ITIL
- Demonstrated experience designing and leading operational IT audits end to end
- annual planning
- risk-based scoping
- fieldwork
- reporting
- areas such as IT operations
- infrastructure resilience
- disaster recovery and business continuity
- capacity and availability management
- IT vendor and third-party risk
- Strong cybersecurity audit experience
- working fluency in frameworks and regulations such as NIST CSF, ISO 27001, SOC 2, GDPR, and CCPA
- ability to translate them into practical, testable controls
- Software or SaaS industry experience is a must
- modern cloud-based technology stacks (AWS, GCP, Azure)
- software development lifecycles
- complex data flows
- strong technical knowledge across cloud security configurations
- identity and access management
- change management
- DevOps and CI/CD pipelines
- enterprise IT operations risks and controls
- Bachelor's degree in Information Systems, Computer Science, Accounting, or a related field
- CISA, CISSP, CISM, CIA, CPA, or equivalent certification required
- Strong stakeholder management and communication skills
- ability to translate complex technical and audit topics into clear language
- influence partners across all levels of the organization
- This role can be based in either San Francisco or New York City
- We work from our offices on Mondays, Tuesdays and Thursdays
- We're looking for someone who's excited to work alongside the team during those days
- intellectually curious
- drawn to tinkering and discovery
- excited to use AI as a real collaborator in their work
- People who thrive here don't treat AI as a novelty
- They use it to think better
- make their work easier for others to build on
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.