> Markdown version of [/jobs/ext/1447228-it-internal-audit-lead](https://www.wearedevelopers.com/jobs/ext/1447228-it-internal-audit-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Internal Audit Lead - **Company:** BrightSpring Health Services - **Location:** Louisville, KY, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Access, Business Software, Control Objectives for Information and Related Technology (COBIT), Software Documentation, Information Systems, Data Auditing, Data Integrity, Information Technology Audit, IT Management, Information Technology Operations, Oracle (Applications), SAP (Applications), IT General Controls (ITGC), Information Technology, Data Analytics - **Published:** July 26, 2026 - **Apply:** https://www.juju.com/job/00000000gjgkyg ## About the Role + Bachelor's degree in Information Systems, Computer Science, Accounting, Finance, or a related field. + 5-7+ years of experience in Internal Audit, IT Audit, or external audit (Big 4 or national firm strongly preferred), with substantial: + SOX ITGC ownership, and + hands on IT audit or technology risk assessment experience. + Experience auditing ERP environments (e.g., SAP, Oracle), key business applications, and supporting infrastructure preferred. + Industry experience in healthcare, provider services, pharmacy services, or other regulated environments preferred. + CISA strongly preferred; CIA or CPA a plus + Strong knowledge of ITGCs, SOX/PCAOB expectations, COSO, COBIT, and IIA/ISACA standards. + Experience evaluating IT dependent manual controls, automated controls, system interfaces, and reports used as IPE. + Proficiency with audit management platforms (e.g., Workiva, AuditBoard, TeamMate). + Strong analytical and data evaluation skills; familiarity with data analytics or continuous auditing concepts is a plus. + Excellent written and verbal communication skills, with the ability to explain technical concepts to non technical stakeholders. + Percentage of Travel: 0-25% To perform this role will require frequently sitting and typing on a keyboard with fingers, and occasionally standing, walking, and climbing (stairs/ladders). The physical requirements will be the ability to push/pull and lift/carry 1-10 lbs ## Description The IT Internal Audit Lead supports the execution of the SOX 404 program with a focus on IT risks and controls and independently performs risk-based IT and technology-enabled audits. This role partners with IT and business stakeholders, co-sourced providers, and other assurance functions to deliver timely, high-quality assurance and actionable insights related to systems, applications, and data. As the Internal Audit function continues to mature and expand, this role is expected to grow in breadth and scope, taking on increasing responsibility across IT audit coverage, emerging technology risks, and assurance coordination. Responsibilities + The IT Internal Audit Lead works with the Vice President of Internal Audit, IT leadership, and business stakeholders to execute the Company's internal audit plan, with emphasis on IT risk and controls + Fosters relationships with IT and business personnel at appropriate levels and serve as a subject matter expert for IT control design, system access, change management, data integrity, and documentation standards + Consistently deliver high-quality IT internal audit services in accordance with applicable professional standards (IIA, ISACA) + Contributes to the annual audit plan and periodic risk updates, partnering with other assurance providers to coordinate activities and enhance overall assurance coverage across IT risks + Independently plan and execute risk-based IT and technology-enabled audits, including defining objectives and scope, developing test procedures, performing fieldwork, synthesizing findings, assessing impact, and recommending practical, actionable remediation + Drives high-quality work products within expected time frames and budget + Coordinates multiple concurrent projects and proactively manage stakeholder expectations related to service delivery and timelines + Stays abreast of current technology, cybersecurity, and industry risk trends + Performs other duties as assigned + Supports execution of the SOX 404 program related to IT General Controls (ITGCs), automated application controls, and system-dependent controls, coordinating closely with third-party service providers + Facilitates and lead IT SOX walkthroughs and design effectiveness assessments, including evaluation of: + logical access controls, + change management, + IT operations, + system interfaces, and + IT-dependent manual controls and IPE completeness and accuracy + Oversee and review co-sourced operating effectiveness testing of IT controls, ensuring testing approaches, evidence, and conclusions meet Internal Audit standards and support external auditor reliance + Perform operating effectiveness testing as needed, validate system-generated evidence, and ensure conclusions are supportable, clearly documented, and audit-ready + Provide day-to-day oversight and project management of co-sourced resources supporting SOX IT and IT audit engagements, including coordinating scope, timelines, deliverables, and reviewing workpapers for quality and consistency + Serve as one of the primary points of contact for assigned co-source engagements, facilitating communication, resolving issues, and escalating risks or delivery concerns as appropriate + Independently manage and execute assigned IT audit engagements end-to-end, while balancing oversight responsibilities and ensuring alignment with Internal Audit standards and expectations ## Related Videos - [Exploring 5 Key Applications of AI Abundance with Blockchain Assurance](https://www.wearedevelopers.com/videos/971-exploring-5-key-applications-of-ai-abundance-with-blockchain-assurance) - [A walkthrough on Responsible AI Frameworks and Case Studies](https://www.wearedevelopers.com/videos/509-a-walkthrough-on-responsible-ai-frameworks-and-case-studies) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Navigating the Corporate Jungle: Life as a Developer in a large Company](https://www.wearedevelopers.com/videos/621-navigating-the-corporate-jungle-life-as-a-developer-in-a-large-company) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Give Your LLMs a Left Brain](https://www.wearedevelopers.com/videos/1160-give-your-llms-a-left-brain) ## Related Articles - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)