IT Audit Principal

Epicor Incorporated
United States
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours

Tech stack

Active Directory Artificial Intelligence Microsoft Azure Backup Devices Software as a Service Cloud Computing Control Objectives for Information and Related Technology (COBIT) Cyber Security Information Systems Data Recovery Data Security Document Management Systems
+20 more
Disaster Recovery Infrastructure as a Service (IaaS) Identity and Access Management Information Technology Audit Internet Security Information Systems Security Architecture Professional Platform as a Service (PAAS) Systems Development Life Cycle Salesforce.Com Secure Coding Software Engineering Software Vulnerability Management Data Logging Cloud Platform System IT General Controls (ITGC) Information Technology RSA Archer Platform Data Management GPT Workday

Job description

Help strengthen trust, accountability, and resilience across our technology environment. As an IT Audit Principal, you will lead complex audits across IT SOX, IT general controls, application controls, and cybersecurity frameworks. You will evaluate control design and operating effectiveness, identify meaningful risks and gaps, and provide practical recommendations that help the business improve.

You will serve as an independent and objective partner to leaders across Internal Audit, IT, Security, Finance, and external audit teams. Drawing on your deep subject matter expertise, you will take a hands-on approach to control evaluations, support major transformation initiatives, and advise leadership on effective ways to manage risk. We are seeking applicants with strong technical knowledge, sound judgment, and the ability to turn complex findings into clear actions that support a strong and sustainable control environment.

What you’ll be doing

  • Lead the evaluation and ongoing monitoring of ITGCs to ensure adequate design, operating effectiveness, efficiency, and compliance with SOX requirements and regulatory expectations.
  • Assess cybersecurity controls that intersect with ITGC domains, including identity and access management, privileged access, logging/monitoring, vulnerability management, and incident response.
  • Drive evaluation of broader cybersecurity programs (e.g., NIST, ISO 27001) as dictated by our audit plan and underlying business objectives.
  • Provide thought leadership and partnered advisory in the planning, scoping, and execution of IT SOX testing activities, including risk assessments and control rationalization.
  • Evaluate System Development Life Cycle (SDLC) controls to ensure secure system implementation practices, including secure coding, change management, and vulnerability remediation.
  • Partner with cybersecurity teams to assess risks related to cloud environments, infrastructure, and applications, ensuring appropriate controls are designed and operating effectively.
  • Act as a liaison to external auditors for ITGC and cybersecurity-related audits, ensuring alignment and timely communication of findings.
  • Lead root cause analysis and provide recommendations for control deficiencies, including those related to cybersecurity incidents and/or control gaps.
  • Provide independent and objective advisory to IT and business stakeholders on control design, risk mitigation, and cybersecurity best practices.
  • Develop, review, and maintain IT control documentation, including process flows, narratives, and control matrices, ensuring alignment with both SOX and cybersecurity requirements.
  • Oversee and enhance the quarterly SOX certification process, incorporating cybersecurity risk considerations where applicable.
  • Monitor emerging cybersecurity threats, regulatory changes, and industry trends, and assess their impact on the organization’s control environment.
  • Enable continuous improvement initiatives across IT Audit and cybersecurity programs, including automation and deployment of new technologies.
  • Support executive leadership with special project advisory that inform strategic initiatives, risk assessments, and special transformational projects as needed.
  • Build and leverage AI solutions and workflows to enable capacity or unlock capability for an Internal Audit function.

Requirements

  • 8+ years of progressive experience in IT audit, IT compliance, SOX, and/or cybersecurity risk management (public accounting and/or industry). Big 4 is a plus.
  • Specialized experience in the Software industry.
  • Bachelor’s degree in Information Systems, Cybersecurity, Accounting, Finance, or related field.
  • Relevant certifications such as CISA, CISSP, CISM, CRISC, CIA, or CPA (or equivalent).

What can set you apart

  • Deep experience auditing or supporting systems such as Kinetic, SalesForce, Workday, Microsoft Azure (Entra ID), Active Directory, and different types of cloud environments (IaaS, PaaS, and SaaS).
  • Strong knowledge of ITGC domains (Access Management, Change Management, Interfaces, Backups, Disaster Recovery), SDLC, and their intersection with cybersecurity controls.
  • Deep experience performing cybersecurity audits.
  • Strong understanding of SOX requirements (e.g. 302, 404), principles-based internal control-integrated framework (COSO), IT Frameworks (e.g., COBIT) and cybersecurity control frameworks (e.g., NIST CSF, ISO 27001, CIS Critical Security Controls).
  • Understanding of data protection, privacy regulations, and secure architecture principles.
  • Experience leveraging automation and tools such as Workiva Wdesk, GRC platforms, and AI tools (ChatGPT, Copilot, Claude, etc.).
  • Strong analytical, problem-solving, and risk assessment skills.
  • Excellent communication and stakeholder management skills, with the ability to influence at all levels of the organization.
  • Ability to manage multiple priorities, execute complex tasks, and operate both strategically and tactically., Accounting, Artificial Intelligence (AI), Auditing, Automation, Best Practices, Business Development, Business Plan, Career Development, Change Management, Cloud Computing, Committee of Sponsoring Organizations of the Treadway Commission (COSO), Communication Skills, Computer Security, Continuous Improvement, Control Objectives for Information and related Technology (COBIT), Data Recovery, Design Evaluation, Disaster Recovery, Document Management, ERP (Enterprise Resource Planning), Emerging Technology, External Audit, Finance, Financial Audit, ISO (International Organization for Standardization), Identity Data Management, Incident Response, Industry/Trade Analysis, Information Technology & Information Systems, Information Technology/Systems Audit, Information/Data Security (InfoSec), Infrastructure as a Service (IaaS), Internal Audit, Internet Security, Leadership, LinkedIn, Mentoring, Microsoft Active Directory, Microsoft Windows Azure, Multitasking, Platform as a Service (PaaS), Privacy Regulations, Process Flow, Process Improvement, Program Evaluation, Public Accounting, Regulations, Regulatory Requirements, Risk, Risk Analysis, Risk Management, Root Cause Analysis, Sales, Salesforce.com, Sarbanes-Oxley Act (SOX), Secure Coding, Software Development Lifecycle (SDLC), Software Engineering, Software as a Service (SaaS), Strategic Planning, Supply Chain, Sustainability, Testing, Thought Leadership, Time Management, Trend Analysis, U.S. National Institute of Standards and Technology (NIST)

Benefits & conditions

Competitive Pay & Benefits

  • Health and Wellness: Comprehensive health and wellness benefits designed to support your overall well-being.

  • Internal Mobility: Opportunities for mentorship, continuing education, and focused career goal setting, with 25% of positions filled internally.

  • Career Development: Free LinkedIn Learning licenses for everyone, along with our Mentoring Program to boost your personal development.

  • Education Support: Geographically specific programs to balance the cost of education with the benefits of continued learning and personal development.

  • Inclusive Workplace: Collaborate with a diverse team in an inclusive, global workplace that fosters innovation and celebrates partnership.

  • Work-Life Balance: Policies built on mutual trust and support, encouraging time off to rest, recharge, and reconnect.

  • Global Mobility:Comprehensive support for international relocations and permanent residency processes.

About the company

At Epicor, we’re truly a team. Join 5,000talented professionals in creating a world of better business through data, AI, and cognitive ERP. We help businesses stay future-ready by connecting people, processes, and technology. From software engineers who command the latest AI technology to business development reps who help us seize new opportunities, the work we do matters. Together, Epicor employees are creating a more resilient global supply chain.

We’re Proactive, Proud, Partners.

Whatever your career journey, we’ll help you find the right path. Through our training courses, mentorship, and continuous support, you’ll get everything you need to thrive. At Epicor, your success is our success. And that success really matters, because we’re the essential partners for the world’s most essential businesses-the hardworking companies who make, move, and sell the things the world needs.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:43 min

Auditing third-party technical quality and team skill profiles

Loïc Carbonne Loïc Carbonne · WWC 2024

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · WWC Europe 2026

6:22 min

Eliminating HR bureaucracy and trusting employees

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

40 sec

Generative pre-trained transformer models powering code completions

lgonta lgonta +1 · WWC 2024

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · WWC 2023

5:06 min

Primary reasons for capability gaps in modern recruitment systems

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

Videos

See all

Related articles

See all