Audit, Technology
Job description
About the role
Column is seeking a highly experienced audit professional to oversee the entire audit lifecycle, with a specific focus on information technology and security. This role requires close collaboration with various internal teams, including engineering, security, compliance, and executive leadership, to ensure that the company's operations adhere to regulatory standards and internal controls. The successful candidate will play a critical role in maintaining governance and risk management as the company scales a nationally chartered bank built on proprietary infrastructure. You will be responsible for designing, executing, and reporting on audits that span banking operations, technology systems, and compliance frameworks, ensuring the organization remains secure, compliant, and efficient in its processes.
Key facts
What you'll do
- Design, plan, and execute comprehensive audits across multiple domains, including banking, technology, compliance, and operational controls, from initial scoping through to final reporting and issue resolution.
- Develop and continuously refine a risk-based audit plan tailored specifically for a software company operating a regulated bank, ensuring coverage of key risk areas and regulatory requirements.
- Collaborate closely with engineering, information security, and product teams to audit software development lifecycle processes, data protection measures, identity and access management controls, cybersecurity protocols, and cloud infrastructure, including AI and machine learning applications.
- Assess third-party risk management frameworks and oversight processes for fintech partners, ensuring compliance with applicable regulatory standards and internal policies.
- Leverage data analytics and artificial intelligence tools to identify emerging risks, automate testing procedures, and improve overall audit efficiency and effectiveness.
- Evaluate the effectiveness of controls related to IT and information security, BSA/AML compliance, sanctions screening (KYC, CDD, SAR, OFAC), fair lending practices, consumer protection, privacy, and asset/liability management (ALM) and interest rate risk, following NIST standards and regulatory expectations from agencies such as OCC, FRB, and FDIC.
- Oversee third-party audit staff and external auditors to ensure that audits are completed on time, with high quality, and in accordance with regulatory and internal standards.
- Work collaboratively with the Head of Internal Audit to enhance the overall audit function, including preparing materials for the Audit Committee, implementing quality assurance processes, conducting risk assessments, and developing meaningful metrics to track audit performance and risk mitigation progress.
- Stay informed of evolving regulatory requirements and industry best practices related to banking, fintech, and cybersecurity to ensure the audit program remains current and comprehensive.
- Provide guidance and training to internal teams on audit findings, control improvements, and compliance requirements to foster a culture of continuous improvement and risk awareness within the organization.
- Assist in the development and refinement of internal policies, procedures, and controls to mitigate identified risks and enhance operational resilience.
- Participate in special projects or investigations related to internal controls, fraud detection, or regulatory inquiries as needed.
Requirements
- 5-10 years of experience in audit, risk management, or compliance within banking, fintech, consulting, or technology sectors.
- Strong background in technology audit, including IT risk management, cybersecurity, modern software development practices, and the impact of AI on development and security.
- Practical experience conducting audits in cloud-native environments, with proficiency in AWS IAM, CI/CD pipelines, infrastructure as code (Terraform), and secrets management.
- Ability to extract, analyze, and interpret data directly from cloud platforms and security tools such as CloudTrail, Datadog, and Okta, using APIs or queries, rather than relying solely on dashboards.
- Deep understanding of BSA/AML regulations, sanctions compliance (KYC, CDD, SAR, OFAC), and core banking regulations from agencies such as OCC, FRB, and FDIC.
- Proven ability to build trust and communicate effectively with engineers, senior leadership, and regulators, translating technical findings into clear, actionable insights.
- Experience managing audit teams or external auditors, ensuring timely delivery of high-quality audit work.
- Strong analytical skills, with the ability to identify risks, evaluate controls, and recommend improvements.
- Knowledge of regulatory standards and frameworks, including NIST, OCC, FRB, and FDIC guidelines.
- Excellent written and verbal communication skills, with the ability to prepare detailed audit reports and present findings to executive management and the Board.
- Demonstrated commitment to ethical standards, confidentiality, and professional integrity.
Nice to have
- Certifications such as Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), Certified Internal Auditor (CIA), Certified Information Security Manager (CISM), or Certified in Risk and Information Systems Control (CRISC).
- Experience working in a regulated banking environment, particularly within a nationally chartered bank.
- Familiarity with emerging technologies such as AI, machine learning, and their implications for security and compliance.
- Knowledge of additional regulatory frameworks or standards relevant to banking and fintech industries.
Skills & tools
- AWS Identity and Access Management (IAM)
- Continuous Integration/Continuous Deployment (CI/CD) pipelines
- Infrastructure as Code (Terraform)
- CloudTrail for AWS activity logging
- Datadog for monitoring and analytics
- Okta for identity management
- NIST cybersecurity standards and frameworks
- Regulatory compliance standards from OCC, FRB, FDIC
Practical notes
- Column offers comprehensive health, dental, and vision insurance plans, with options fully covered for employees and their dependents.
- Family planning and fertility benefits are provided through Carrot, with reimbursements up to $20,000.
- Employees living within 2 miles of the San Francisco office are eligible for a monthly rent subsidy of up to $2,000 (post-tax).
- Flexible Spending Accounts (FSA) and Health Savings Accounts (HSA) options are available for pre-tax medical and dependent care expenses.
- The company provides a 401(k) plan with self-directed brokerage options, supporting long-term financial planning.
- Employees enjoy a flexible time-off policy to promote work-life balance.
- Paid parental leave includes 16 weeks for birth mothers, 12 weeks for primary caregivers, and 8 weeks for secondary caregivers.
- Up to $4,500 annually is reimbursed for backup childcare services, supporting working parents.
- In-office perks include catered lunches and dinners for employees based in San Francisco.
- Commuter benefits, including paid transportation to and from the office, are provided to support sustainable commuting options.
- The company hosts regular team-building events and an annual offsite to foster a collaborative and engaging work environment.
- Column is an E-Verify participant where legally required, ensuring compliance with employment verification laws.
About the company
A Column or pillar in architecture and structural engineering is a structural element that transmits, through compression, the weight of the structure above to other structural elements below. In other words, a Column is a compression member.