| Title | IT Auditor |
|---|---|
| Department | Internal Audit / IT Audit / Assurance |
| Reports to | [IT Audit Manager / Director of Internal Audit / Chief Audit Executive] |
| Location | [Remote / Hybrid / On-site] |
| Employment type | Full-time |
| Salary | [Salary range. Postings with a range perform significantly better, and several states require one.] |
Position overview
The IT Auditor plans and executes audits of [Company]'s technology environment, assessing whether IT controls are well designed and operating effectively. This includes IT general controls, application controls, cybersecurity controls, and controls that support financial reporting.
Working within the internal audit function, the IT Auditor scopes engagements, tests controls, documents findings, and recommends improvements. The role provides independent assurance to management and the audit committee that technology risk is being managed.
This is a hands-on assurance role for a professional who is comfortable with both technology and structured audit methodology.
Key responsibilities
Audit planning and scoping
- Support risk-based audit planning across the technology environment.
- Define audit scope, objectives, and test procedures.
- Identify key controls and risks for each engagement.
- Prepare audit programs and workpaper templates.
IT general controls testing
Test IT general controls across access management, change management, and operations. Evaluate:
- Logical access, provisioning, and segregation of duties
- Change management and release controls
- Backup, job scheduling, and operations
- Configuration and security baseline controls
Application and SOX controls
Test application controls and IT dependencies that support financial reporting under SOX. Assess automated controls, interfaces, and key reports, and coordinate with financial audit teams on control reliance.
Cybersecurity and infrastructure
- Assess controls across networks, servers, databases, and cloud services.
- Evaluate vulnerability management and security monitoring.
- Test controls against recognized security frameworks.
Findings and reporting
Document exceptions clearly, quantify risk, and write actionable findings. Review results with control owners, agree remediation, and prepare reporting for audit leadership.
Follow-up and continuous improvement
Track remediation of prior findings to closure and support the adoption of data analytics and continuous auditing techniques.
Required qualifications
- Bachelor's degree in Information Systems, Accounting, Computer Science, or a related discipline.
- 3 to 6 years of experience in IT audit, internal audit, or a related controls or assurance role.
- Working knowledge of IT general controls, application controls, and SOX.
- Familiarity with audit methodology and workpaper documentation standards.
- Understanding of common technology environments, including cloud and enterprise applications.
- Strong analytical and written communication skills.
Preferred certifications
One or more of: CISA, CIA, CISSP, CPA, or equivalent audit or security certification.
Technical knowledge
IT general controls, application controls, SOX IT testing, access management, change management, cybersecurity control assessment, cloud and infrastructure controls, audit methodology, workpaper documentation, and data analytics for audit.
About [Company]
[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]
Post this role on GRC Careers
Reach professionals who specialize in IT audit and controls testing rather than hoping they find you in a general feed. Hand reviewed, live within one business day.
See how others are hiring
Review live GRC jobs postings to benchmark scope, level, and posted salary before you publish yours.
Stay close to the market
Job alerts
Get new GRC jobs roles sent to you as they post.
Newsletter
Hiring trends, salary signals, and new templates from GRC Careers.
Frequently asked questions
What does an IT Auditor do?
An IT Auditor evaluates whether technology controls are well designed and operating effectively. They test IT general controls, application controls, and cybersecurity controls, document findings, and give independent assurance that technology risk is being managed.
What qualifications and certifications does an IT Auditor need?
Most bring 3 to 6 years in IT audit or a related controls role, plus a bachelor's degree in information systems or accounting. The most common certification is CISA, and many also hold CIA, CISSP, or CPA.
What frameworks does an IT Auditor use?
Common references include COBIT for IT governance and controls, the NIST Cybersecurity Framework, ISO 27001, SOX requirements for IT general controls, and the IIA International Standards for the Professional Practice of Internal Auditing.
What are IT general controls?
IT general controls, or ITGCs, are the foundational controls over access management, change management, and operations that support the reliability of applications and data. They are a core focus of IT and SOX audits.