Senior Internal Auditor, Technology
Job description
Senior Internal Auditor, Technology at GitLab.
About the role
This role involves evaluating risk and strengthening controls across GitLab's technology environment, which includes multi-cloud infrastructure, AI/ML systems, and modern development practices. You will support the Sarbanes-Oxley Act (SOX) program and collaborate with various teams to implement effective controls. The position focuses on conducting technology audits, translating findings into actionable improvements, and leveraging data analytics, automation, and generative AI to enhance audit processes.
Key facts
What you'll do
- Perform technology audits covering SOX compliance, cloud infrastructure (AWS, GCP), application controls, cybersecurity, AI/ML systems, and DevSecOps.
- Design and test IT general controls, application controls, and entity-level controls with limited oversight.
- Manage the IT SOX program from initial planning through reporting, including risk-based planning, process walkthroughs, testing, and coordinating with external co-source providers.
- Create and maintain clear audit documentation, such as risk and control matrices, process flows, test procedures, findings, and business impact assessments.
- Oversee remediation efforts by collaborating with process owners on corrective action plans, verifying effectiveness before closure, and providing leadership with status updates.
- Work with Engineering, IT Operations, Security, and business process owners to identify emerging risks and evaluate new system implementations for control adequacy and SOX relevance.
- Review controls across financial statement cycles like record to report, order to cash, hire to retire, and procure to pay, as well as third-party SOC 1 and 2 reports.
- Utilize data analytics, automation, and generative AI tools to improve audit efficiency, coverage, and quality.
Requirements
- Experience conducting technology audits and risk management in complex technology environments, including planning, testing, reporting, and remediation.
- Experience supporting IT SOX programs and designing and testing IT general controls and application controls.
- Knowledge of IT control frameworks such as COBIT, NIST, ITIL, ISO 27001, and COSO.
- Understanding of cloud security principles and cybersecurity fundamentals, including network security, encryption, identity and access management, vulnerability management, and Zero Trust.
- Familiarity with modern development practices like Agile and DevOps, and with data analytics and audit automation tools.
- Strong written and verbal communication skills, capable of explaining technical findings, business impact, and practical recommendations to diverse audiences.
- A self-motivated, collaborative approach to managing multiple priorities, adapting to change, and improving risk and control environments.
- A bachelor's degree in Accounting, Information Technology, Computer Science, Finance, or a related field.
- An active professional certification such as CPA, CIA, CISA, CISSP, CISM, CRISC, or an equivalent.
Practical notes
Benefits include health, financial, and well-being support, flexible paid time off, team member resource groups, equity compensation, an employee stock purchase plan, a growth and development fund, parental leave, and home office support. GitLab welcomes applications from candidates with varying experience levels, and encourages individuals from underrepresented groups to apply even if they do not meet every single qualification.