IT Auditor
IT Auditor Job Description
Position Summary
We are seeking an experienced IT Auditor with at least three years of audit experience to perform risk-based IT audits with limited oversight. This role evaluates IT controls, identifies governance and risk management improvements, and recommends practical actions to strengthen the control environment. Experience with OT, AI, and cloud environments is preferred.
Responsibilities
- Plan, execute, and document risk-based IT audits with limited oversight.
- Assess IT general controls, cybersecurity controls, application controls, and technology-enabled business processes.
- Identify control weaknesses, assess risk exposure, and develop practical recommendations.
- Conduct interviews, test controls, analyze evidence, and prepare workpapers that comply with professional standards.
- Prepare clear audit reports and communicate findings to management and stakeholders.
- Monitor remediation activities and validate corrective actions.
- Evaluate cloud governance, security, and compliance controls.
- Review AI-related processes, models, governance practices, and associated risks.
- Assess Operational Technology environments, industrial control systems, and related cybersecurity controls.
- Support enterprise risk management, compliance, and continuous improvement initiatives.
Qualifications
- Bachelor's degree in Accounting, Information Technology, Information Systems, Computer Science, Business Administration, or a related field.
- At least 3 years of experience in IT auditing, internal auditing, IT risk, cybersecurity, or a related field.
- Ability to perform audits independently while managing multiple engagements.
- Strong understanding of risk assessment methodologies and internal control frameworks.
- Excellent analytical, documentation, communication, and report-writing skills.
Preferred Qualifications
- Professional certification such as CIA, CISA, CISSP, or other relevant credentials.
- Experience auditing cloud platforms such as Microsoft Azure, AWS, or Google Cloud.
- Knowledge of Operational Technology (OT) environments and industrial cybersecurity concepts.
- Experience assessing AI governance, security, privacy, and model risk controls.
- Familiarity with NIST, COBIT, ISO 27001, SOC, or similar frameworks.
Key Competencies
- Audit planning and execution
- Critical thinking and problem solving
- Stakeholder communication and relationship management
- Attention to detail
- Engagement management and organization
- Professional judgment and integrity



