# Senior IT Internal Auditor

**Company:** [Okta](https://hotfix.jobs/companies/okta)
**Location:** San Francisco, CA
**Role:** IT Support
**Salary:** $104k – $161k/yr
**Experience:** 5+ years
**Skills:** it auditing, Cybersecurity, ai risk assessment, itgc, itac, SDLC, cloud computing, nist csf, cobit, ISO 27001, SQL, Python, Tableau, Power BI, cisa
**Posted:** 2026-07-21

> Senior IT Internal Auditor leading technology, cybersecurity, and AI-related audit engagements at Okta. Independently executes risk assessments, control testing, root cause analysis, and reporting while mentoring juniors and leveraging data analytics/AI tools. Requires 3-6 years tech audit experience, strong ITGC/ITAC knowledge, and data analytics proficiency.

## Job Description

## What You Will Own

### Audit Planning & Risk Assessment
- Independently lead technology, cybersecurity, and AI-related risk assessments to identify key enterprise risks, define audit scope, and prioritize testing strategies with limited management direction.
- Design comprehensive, risk-based audit programs and testing procedures tailored to the technology environment.
- Apply professional judgment in setting audit objectives, sequencing fieldwork, and managing competing priorities across simultaneous engagements.

### Audit Fieldwork & Testing
- Independently lead process walkthroughs and execute fieldwork in strict alignment with Internal Audit methodology, actively championing methodology standards with limited guidance.
- Evaluate the design and operational effectiveness of key technology, cybersecurity, and AI-related controls.
- Prepare high-quality, self reviewed detailed workpapers that clearly document scope, testing results, evidence, and conclusions; requiring minimal editorial revision.
- Leverage data analytics, AI tools, and emerging technologies to enhance audit efficiency, automate workpapers, and evaluate AI/ML controls and governance.
- Contribute to the identification and documentation of process improvements within the Internal Audit methodology, templates, and testing procedures.

### Reporting & Remediation
- Pinpoint systemic root causes of control weaknesses and associate those causes with the specific business processes that generated or permitted them — going beyond symptom identification.
- Contextualize audit findings and recommendations within Okta's wider risk, control, and governance environment, providing analysis that contributes to the annual audit opinion.
- Draft clear, concise audit reports that require minimal revision, presenting findings with appropriate business impact framing for management and senior stakeholders.
- Gain independent stakeholder agreement on root cause conclusions and right-sized corrective actions, while maintaining positive client relationships.
- Partner with TDI, Security, Engineering, and cross-functional teams to track and ensure the timely completion of agreed-upon remediation activities.

### Advisory & Collaboration
- Provide risk-based advisory support to management during business process improvements, new system implementations, or emerging technology assessments.
- Mentor and provide structured guidance to Associate and Staff Auditors on audit methodology, workpaper standards, and root cause analysis techniques.
- Champion Internal Audit methodology standards across the team, identifying and proposing improvements to templates, processes, and quality benchmarks.

## What You Bring
- Bachelor's degree in Computer Science, Information Systems, STEM, Accounting, or a related field.
- 3-6 years of audit experience with a focus on technology, cybersecurity, or related field.
- 2+ years of audit experience in diverse technology environments (e.g. operating systems, networks, public/private cloud, third-party cloud-based applications and platforms).
- 2+ years of audit experience with technology operational processes (e.g. software development lifecycle, system integration and monitoring, data protection, identity and access management).
- Experience assessing emerging AI risks (e.g. generative AI, ML models, automated decisioning, AI-enabled third-party services).
- Demonstrated ability to execute complex audit engagements independently, with minimal supervisory oversight.
- Proven ability to identify and articulate systemic root causes of control deficiencies, linking causes to the business processes that generated them.
- Strong understanding of IT general controls (ITGCs) and IT application controls (ITACs), including cybersecurity, Software Development Life Cycle (SDLC), access and change management, logging and monitoring, disaster recovery, and cloud computing.
- Technical expertise in IT systems including infrastructure, cybersecurity, and familiarity with IT governance frameworks (e.g. NIST CSF, COBIT, ISO 27001).
- Strong analytical and critical thinking skills, with proficiency in analyzing complex data and extracting meaningful insights.
- Strong written and verbal communication skills, including interviewing skills and the ability to effectively present audit findings with business partners, and minimal revisions on audit reports and workpapers.
- Proficiency in data analytics tools (e.g., SQL, Python, Tableau, Power BI, or equivalent) and familiarity with AI-assisted audit tools (e.g., Claude, NotebookLM, Gemini).
- Excellent interpersonal skills, with demonstrated ability to independently manage client relationships and gain stakeholder agreement on sensitive findings.

## What Sets You Apart
- Big 4 public accounting or IT audit advisory experience at a comparable firm.
- Active Certified Information Systems Auditor (CISA) (strongly preferred); or Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Internal Auditor (CIA), or Certified Ethical Hacker (CEH).
- Experience auditing within cloud-based or Software-as-a-Service (SaaS) environments - IAM, identity governance, or zero-trust architectures a significant plus.
- Awareness of AI governance, ethics, and emerging risks such as model bias, data privacy, and hallucination.
- Experience contributing to internal audit methodology improvements, templates, or training programs.

## Similar roles

- [Senior IT Specialist](https://hotfix.jobs/jobs/45409e35-2477-4ba4-acb3-b1a476587fe8) - Viz.ai - Remote - $104k – $150k/yr
- [Senior Financial Analyst](https://hotfix.jobs/jobs/72e144d7-2168-43b2-b468-70ab4841cd03) - Hinge Health - San Francisco, CA - $101k – $151k/yr
- [Technology Operations Lead](https://hotfix.jobs/jobs/b6a4309c-2a2e-46d6-9456-1a242e832b07) - Mercor - San Francisco, CA - $100k – $200k/yr
- [Senior Manager, IT Implementation](https://hotfix.jobs/jobs/8a6a8947-f176-47da-afb4-c345b6d24f00) - Rippling - Austin, TX - $100k – $196k/yr
- [Sr Information Systems Engineer](https://hotfix.jobs/jobs/8967dc20-3499-4478-974f-a4a2b4b6e4d7) - Cribl - Remote - $99k – $156k/yr

**Apply:** https://hotfix.jobs/jobs/822bc55f-03a9-42bf-a116-4d70530560c9
**Canonical:** https://hotfix.jobs/jobs/822bc55f-03a9-42bf-a116-4d70530560c9