Okta logo
OktaPosted 1 month ago

Senior IT Internal Auditor

$117,000–$160,600 year

HybridSan Francisco, California, United States

Full TimeSenior LevelLargeCybersecurity Software

Job Summary

Independently lead technology, cybersecurity, and AI-related risk assessments to define audit scope and prioritize testing strategies across Technology Data & Insights, Security, and Engineering. Execute fieldwork by conducting process walkthroughs, evaluating control design and operational effectiveness, and leveraging data analytics to automate workpapers. Pinpoint systemic root causes of control weaknesses and draft clear, concise audit reports requiring minimal revision. Partner with cross-functional teams to track remediation activities and provide advisory support during business process improvements. Mentor junior auditors on methodology standards and champion internal audit methodology improvements.

Required Qualifications

  • Bachelor's degree in Computer Science, Information Systems, STEM (Science, Technology, Engineering, and Math), Accounting, or a related field
  • 3-6 years of audit experience with a focus on technology, cybersecurity, or related field
  • 2+ years of audit experience in diverse technology environments (e.g. operating systems, networks, public/private cloud, third-party cloud-based applications and platforms)
  • 2+ years of audit experience with technology operational processes (e.g. software development lifecycle, system integration and monitoring, data protection, identity and access management)
  • Experience assessing emerging AI risks (e.g. generative AI, ML models, automated decisioning, AI-enabled third-party services)
  • Demonstrated ability to execute complex audit engagements independently, with minimal supervisory oversight
  • Proven ability to identify and articulate systemic root causes of control deficiencies, linking causes to the business processes that generated them
  • Strong understanding of IT general controls (ITGCs) and IT application controls (ITACs), including cybersecurity, Software Development Life Cycle (SDLC), access and change management, logging and monitoring, disaster recovery, and cloud computing
  • Technical expertise in IT systems including infrastructure, cybersecurity, and familiarity with IT governance frameworks (e.g. NIST CSF, COBIT, ISO 27001)
  • Strong analytical and critical thinking skills, with proficiency in analyzing complex data and extracting meaningful insights
  • Strong written and verbal communication skills, including interviewing skills and the ability to effectively present audit findings with business partners, and minimal revisions on audit reports and workpapers
  • Proficiency in data analytics tools (e.g., SQL, Python, Tableau, Power BI, or equivalent) and familiarity with AI-assisted audit tools (e.g., Claude, NotebookLM, Gemini)
  • Excellent interpersonal skills, with demonstrated ability to independently manage client relationships and gain stakeholder agreement on sensitive findings
  • Big 4 public accounting or IT audit advisory experience at a comparable firm
  • Active Certified Information Systems Auditor (CISA) (strongly preferred); or Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Internal Auditor (CIA), or Certified Ethical Hacker (CEH)
  • Experience auditing within cloud-based or Software-as-a-Service (SaaS) environments - IAM, identity governance, or zero-trust architectures a significant plus
  • Awareness of AI governance, ethics, and emerging risks such as model bias, data privacy, and hallucination
  • Experience contributing to internal audit methodology improvements, templates, or training programs
  • This role operates in Okta's hybrid work environment
  • You are expected to go to the San Francisco office two days per week

Desired Qualifications

  • Experience auditing within cloud-based or Software-as-a-Service (SaaS) environments - IAM, identity governance, or zero-trust architectures a significant plus
  • Active Certified Information Systems Auditor (CISA) (strongly preferred); or Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Internal Auditor (CIA), or Certified Ethical Hacker (CEH)
  • Awareness of AI governance, ethics, and emerging risks such as model bias, data privacy, and hallucination
  • Experience contributing to internal audit methodology improvements, templates, or training programs

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce