Skip to content
GitLabGitLabUnited States

Senior Internal Auditor

Senior Internal Auditor assessing technology risks and strengthening controls for SOX compliance, cloud infrastructure, AI/ML systems, and DevSecOps practices. Requires experience with IT audits, control frameworks, cybersecurity, and relevant certifications.

86k – 146k/yr
Remote5+ YOEOther

About the role

What You’ll Do

  • Execute technology audits covering SOX compliance, cloud infrastructure across Amazon Web Services, and Google Cloud Platform, application controls, cybersecurity, artificial intelligence and machine learning systems, and DevSecOps practices.
  • Design and test IT general controls, application controls, and entity-level controls with minimal supervision.
  • Support the IT SOX program from planning through reporting, including risk-based audit planning, process walkthroughs, testing, and coordination with external co-source providers.
  • Maintain clear, high-quality audit documentation, including risk and control matrices, process flows, test procedures, findings, and business impact assessments.
  • Own remediation efforts by partnering with process owners on practical corrective action plans, validating effectiveness before closure, and preparing status updates for leadership.
  • Collaborate with Engineering, IT Operations, Security, and business process owners to assess emerging risks and evaluate new system implementations for control adequacy and SOX relevance.
  • Review controls across financial statement cycles, including record to report, order to cash, hire to retire, and procure to pay, as well as third-party System and Organization Controls 1 and 2 reports.
  • Use data analytics, automation, and generative artificial intelligence tools to improve audit efficiency, coverage, and quality.

What You’ll Bring

  • Experience executing technology audits and risk management work in complex technology environments, including audit planning, testing, reporting, and remediation.
  • Experience supporting IT SOX programs and designing and testing IT general controls and application controls.
  • Knowledge of IT control frameworks such as COBIT, the National Institute of Standards and Technology framework, Information Technology Infrastructure Library, ISO 27001, and the Committee of Sponsoring Organizations of the Treadway Commission Internal Control Framework.
  • Knowledge of cloud security principles and cybersecurity fundamentals, including network security, encryption, identity and access management, vulnerability management, and Zero Trust principles.
  • Experience with modern development practices, including Agile and DevOps, and with data analytics and audit automation tools.
  • Clear written and verbal communication skills, with the ability to explain technical findings, business impact, and practical recommendations to technical and business audiences.
  • A self-directed, collaborative approach to managing multiple priorities, adapting to change, and helping teams improve their risk and control environments.
  • A bachelor’s degree in Accounting, Information Technology, Computer Science, Finance, or a related field, and an active relevant professional certification such as Certified Public Accountant, Certified Internal Auditor, Certified Information Systems Auditor, Certified Information Systems Security Professional, Certified Information Security Manager, Certified in Risk and Information Systems Control, or an equivalent certification.

How GitLab will support you

  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental leave
  • Home office support

Skills

SOX Complianceit general controlsapplication controlsAWSGCPCybersecurityDevSecOpscobitnistISO 27001cosoData Analyticsaudit automationAgileDevOps

Similar roles

Lithic

Senior Compliance Analyst

LithicNew York, NY

Own end-to-end CIP/KYB/CDD compliance execution and QA for a fintech card-issuing platform, including AI-assisted workflow oversight and sponsor bank deliverables. Requires 3-5 years fintech/payments compliance experience with direct CIP background.

86k – 140k/yr
Remote3+ YOEOther
Current

Consumer Compliance Senior Analyst, Complaints

CurrentNew York, NY

Individual contributor role focused on analyzing and responding to regulatory customer complaints, drafting formal responses to customers/regulators, identifying risks, and supporting special compliance projects at a consumer fintech company. Requires 4+ years experience, strong writing/research skills, and familiarity with Reg E/Z.

85k – 110k/yr
On-site4+ YOEOther
Shield AI

Compliance Analyst - Policy, Process, and Procedure

Shield AIWashington, DC +1

Develop and maintain compliant policies and processes for government contracting operations, ensuring alignment with FAR/DFARS and supporting DCAA/DCMA audits. Requires 6+ years in compliance or business systems and a bachelor's degree.

88k – 130k/yr
Remote6+ YOEOther
Kraken

SOX Auditor - IT Controls Manager

KrakenUnited States

Lead IT SOX controls testing program for a crypto exchange, testing ITGCs across access management, change management, and system operations for blockchain and digital asset systems.

83k – 167k/yr
Remote8+ YOEOther
Idme

Senior Fraud Investigations Analyst

IdmeMcLean, VA

Leads complex account takeover investigations, analyzes large datasets with SQL/Python to uncover fraud patterns, and improves detection systems. Requires 4+ years in fraud/cybersecurity and bachelor's in quantitative field.

90k – 120k/yr
On-site4+ YOEOther