About the Client
Our client is a global Earth observation company that operates one of the world's largest fleets of satellites, providing daily imagery and data that help organizations make informed decisions about our planet. Working across industries such as agriculture, government, environmental sustainability, mapping, and disaster response, the client combines advanced space technology with data and analytics to solve real-world challenges.
Joining our client means being part of a mission-driven technology company where innovation, continuous learning, and global collaboration are at the core of how teams work.
About the Role
Our client is seeking an experienced IT Internal Audit Senior to join its growing Internal Audit team. Reporting to the Head of IT Internal Audit, this role will support the enhancement of the company's IT SOX compliance program and the transition of audit testing activities in-house.
This is a great opportunity for an audit professional who enjoys working in a dynamic technology environment and collaborating with engineering, cloud, DevOps, and business teams. The role offers exposure to cloud platforms, enterprise applications, IT controls, and compliance initiatives while partnering with leadership and external auditors to identify risks, strengthen controls, and drive continuous improvement.
As part of the company's commitment to innovation, the Internal Audit team is also incorporating AI-enabled audit testing tools to improve the effectiveness and efficiency of SOX testing. While prior AI experience is not required, candidates should be curious, adaptable, and eager to leverage emerging technologies in the audit space.
The ideal candidate brings strong IT audit expertise and can confidently engage with technical stakeholders on topics such as SDLC, CI/CD pipelines, cloud controls, and change management, applying a risk-based approach to auditing modern technology environments.
Responsibilities
IT SOX & Controls Testing
- Execute IT SOX compliance testing across:
- IT General Controls (ITGCs)
- Automated Controls (ITACs)
- Key Report Testing
- Segregation of Duties (SoD)
- Information Produced by the Entity (IPE) testing
- Perform walkthroughs, testing, documentation, and quality reviews of IT controls.
- Assess control design and operating effectiveness.
- Support remediation activities and validate corrective actions.
- Utilize AI-enabled audit testing tools to support the execution of SOX control testing and compliance activities.
- Collaborate with audit leadership to identify opportunities to enhance audit quality and efficiency through technology and automation.
Audit Execution & Risk Management
- Conduct risk assessments and participate in SOX scoping activities.
- Evaluate new systems, technology implementations, infrastructure changes, and business process updates for compliance impact.
- Support internal audits covering IT operations, cybersecurity, data governance, and technology risks.
- Identify opportunities to improve control efficiency and audit effectiveness.
Stakeholder & Auditor Partnership
- Partner with business leaders, technical teams, and external auditors.
- Coordinate audit requests, evidence gathering, and testing activities.
- Help resolve audit findings and support external audit requirements.
- Communicate technical audit concepts clearly to both technical and non-technical audiences.
Process Improvement
- Strengthen process documentation, control ownership, and audit readiness.
- Support continuous improvement initiatives and scalable compliance programs.
- Contribute to the development of risk-based audit plans and internal audit methodologies.
Engineering & Cloud Technology Audits
- Assess design and effectiveness of controls across software development, CI/CD pipelines, source code management, and technology change management processes.
- Evaluate risks related to cloud infrastructure, platform services, and application deployments within AWS and GCP environments.
- Partner with engineering leaders to understand technical architecture, deployment processes, and system integrations.
- Review controls surrounding automated deployments, infrastructure changes, and release management activities.
- Identify opportunities to strengthen governance within cloud-native and DevOps operating models.
Qualifications
- 4+ years of experience in IT Audit, SOX Compliance, IT Risk, Internal Controls, or Technology Assurance.
- Demonstrated experience performing SOX IT audits and testing across ITGCs, automated controls, change management, user access management, and system development lifecycle (SDLC) processes.
- Strong understanding of technology environments including cloud platforms, software development practices, and modern engineering workflows.
- Experience auditing technology change management processes within DevOps or Agile environments.
- Working knowledge of CI/CD concepts and tools such as GitHub, GitLab, Jenkins, Azure DevOps, or similar platforms.
- Experience evaluating controls related to code deployments, source code management, automated releases, and production change controls.
- Familiarity with cloud computing environments such as AWS, Google Cloud Platform (GCP), or Azure, including identity/access management, logging, monitoring, and security controls.
- Experience partnering with engineering, infrastructure, and product teams during audits and compliance assessments.
- Strong understanding of SOX requirements and COSO/IT control frameworks.
- Excellent communication skills with the ability to translate technical concepts into business risk discussions.
Preferred Qualifications
- Big 4 Technology Risk or IT Audit experience.
- CISA, CPA, CISSP, AWS Cloud Practitioner, AWS Solutions Architect, or equivalent certifications.
- Experience auditing SaaS companies, cloud-native organizations, or publicly traded technology companies.
- Experience reviewing controls within:
- GitHub or GitLab environments
- CI/CD pipelines
- Infrastructure-as-Code (Terraform, CloudFormation)
- Kubernetes and containerized environments
- AWS and GCP cloud platforms
- Exposure to cybersecurity, cloud governance, DevSecOps, or engineering compliance programs.
- Experience transitioning SOX testing activities from external providers to an in-house audit function.