← Back to job listings
NO
IT Audit and Technology Risk Lead
Notion · United States
About The Role
Join our Finance team as the IT Audit and Technology Risk Lead. In this high-impact role, you will own the IT SOX lifecycle, design and improve technology controls, execute operational IT and cybersecurity audits, and serve as a strategic advisor on cross-functional initiatives. You will need strong stakeholder management and communication skills, as well as experience in the software or SaaS industry, IT SOX/ITGC programs, and operational IT audits. A bachelor's degree in a related field and 12+ years of relevant experience are required.
- Establish and elevate the technology controls program end to end, owning the IT SOX lifecycle and designing the IT general and application controls framework.
- Partner with leaders across Engineering, Security, IT, Finance, and the business to ensure sound technology controls are built into how the company operates as it scales.
- Design and execute value-added operational IT and cybersecurity audits, driving enterprise-level technology risk assessment that anticipates emerging risks before they materialize.
- This role is ideal for someone who thinks like a builder, not just an auditor — someone who can translate complex control and security requirements into practical, scalable processes in a fast-moving SaaS environment with modern cloud architecture and complex data flows
- Strong stakeholder management and communication skills, with the ability to translate complex technical and audit topics into clear language and influence partners across all levels of the organization
- Software or SaaS industry experience is a must — particularly modern cloud-based technology stacks (AWS, GCP, Azure), software development lifecycles, and complex data flows — paired with strong technical knowledge across cloud security configurations, identity and access management, change management, DevOps and CI/CD pipelines, and enterprise IT operations risks and controls
- Deep, hands-on ownership of IT SOX/ITGC programs, with a strong understanding of PCAOB standards, SEC requirements, and frameworks such as COSO, COBIT, NIST, and ITIL
- Demonstrated experience designing and leading operational IT audits end to end — including annual planning, risk-based scoping, fieldwork, and reporting — across areas such as IT operations, infrastructure resilience, disaster recovery and business continuity, capacity and availability management, and IT vendor and third-party risk
- Bachelor's degree in Information Systems, Computer Science, Accounting, or a related field; CISA, CISSP, CISM, CIA, CPA, or equivalent certification required
- 12+ years of progressive IT audit, IT SOX, or technology risk experience, with a combination of Big 4 and high-growth technology company experience
- Strong cybersecurity audit experience with working fluency in frameworks and regulations such as NIST CSF, ISO 27001, SOC 2, GDPR, and CCPA, and the ability to translate them into practical, testable controls
- Process leadership — a track record of building functions, designing new processes and policies, and driving continuous improvement
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring