> Markdown version of [/jobs/ext/1206104-senior-it-internal-auditor](https://www.wearedevelopers.com/jobs/ext/1206104-senior-it-internal-auditor). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior IT Internal Auditor - **Company:** STERIS Corporation - **Location:** United States - **Experience:** Expert - **Salary:** $75,000.0 - $90,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Data Analysis, Cloud Computing Security, Cyber Security, Information Systems, Identity and Access Management, Information Technology Audit, Information Technology Operations, Network Security, Oracle (Applications), SAP (Applications), Software Vulnerability Management, IT General Controls (ITGC), Information Technology - **Published:** July 8, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17507651?backUrl=%2Fcareer%2F17507651%2FSenior-It-Internal-Auditor-Ohio-Mentor ## About the Role * Bachelor's degree in Accounting, Finance, Information Systems, or related field. * Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA), Certified Public Accountant (CPA), or comparable certification required. * Minimum of 5 years of relevant internal or external audit experience, including at least 3 years in IT audit. * Experience with SOX compliance, including ITGC and application control testing and reviews. * Understanding of cybersecurity frameworks and concepts. * Knowledge of ERP systems (e.g., Oracle, SAP) and related business processes. * Strong analytical, organizational, and problem-solving skills. * Effective written and verbal communication skills. * Ability to manage multiple priorities and meet deadlines. * Willingness to travel approximately 10-20%, including participation in inventory observations and related audits. * Experience working with external auditors. Preferred: * Experience auditing cybersecurity domains (e.g., identity and access management, network security, cloud security, incident response). * Experience with automated controls, system implementations, and data analytics tools. * Exposure to manufacturing and/or distribution environments. Other: * Strong interpersonal skills - ability to work closely with people at all levels of the organization and facilitate the implementation of corrective action. * Self-starter with demonstrated organizational, project management, time management and problem-solving skills. * Able to balance multiple high priority responsibilities on-time and effectively. * Able to confront difficult issues with the appropriate response and to do so in a timely manner with any/all stakeholders. ## Description As a Senior IT Internal Auditor you are responsible for owning and executing risk-based IT and cybersecurity audits in accordance with Internal Audit methodology, including planning, scoping, testing, and reporting. You will lead audit activities end-to-end, including evaluating risks, developing audit approaches, and delivering clear, actionable recommendations to management., You will also support broader Internal Audit activities, including participation in inventory observations and financial or operational audits, as needed. As a Senior IT Internal Auditor you will work closely with IT, Information Security, Finance, Compliance, and external auditors to strengthen the overall control environment and drive continuous improvement. What You'll do as a Senior IT Internal Auditor * Lead and support SOX IT compliance activities, including walkthroughs, control testing and reviews, and documentation reviews of IT general controls (ITGCs) and automated/application controls, ensuring alignment with Company standards and external auditor reliance expectations. Assess the design and operating effectiveness of ITGCs (user access, change management, and IT operations) across key systems and processes. * Perform risk assessments and support audit planning, including identifying key risks, developing audit scope and objectives, and assisting in the creation of risk-based audit programs. * Execute IT and cybersecurity audits, including evaluation of controls over identity and access management, change management, IT operations, vulnerability management, incident response, and data protection. * Evaluate risks and controls related to system implementations, enhancements, and emerging technologies, including cloud and cybersecurity-related initiatives. * Identify, assess, and communicate control deficiencies, including root cause analysis and development of actionable recommendations; support and monitor remediation efforts. * Perform audit fieldwork and maintain high-quality documentation, including preparation and review of audit workpapers to ensure completeness, accuracy, and compliance with Internal Audit standards. * Serve as a key liaison with IT, Information Security, business stakeholders, and external auditors, facilitating alignment on audit scope, testing, and timelines. * Provide day-to-day guidance, oversight, and project management support for audit engagements, including reviewing work, coordinating timelines and deliverables, coaching on audit methodology, and supporting development to ensure consistent, high-quality execution. * Support execution of financial and operational audits, providing IT expertise and assisting with planning, testing, reviews, and reporting, as needed. * Lead and participate in inventory observations at manufacturing and distribution locations, including required domestic and limited international travel. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Blazing Accessibility Basics](https://www.wearedevelopers.com/videos/568-blazing-accessibility-basics) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) ## Related Articles - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Companies to Work For in Berlin: Top 14 Companies in 2023 ](https://www.wearedevelopers.com/magazine/188-best-companies-to-work-for-in-berlin-top-14-companies-in-2023)