> Markdown version of [/jobs/ext/2463059-it-audit-controls-analyst](https://www.wearedevelopers.com/jobs/ext/2463059-it-audit-controls-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Audit & Controls Analyst - **Company:** The Smart - **Location:** United States (Remote available) - **Experience:** Starter - **Contract:** Permanent contract - **Skills:** Software Documentation, Cyber Security, Information Technology Audit, Smartsuite, User Provisioning Software, IT General Controls (ITGC) - **Published:** August 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=41c3d04323305dc2 ## About the Role * 1 or more years of professional experience in IT General Controls (ITGC), IT Audit, Technology Risk, Cybersecurity Risk, or IT SOX. * Hands-on experience testing technology controls and evaluating control design and operating effectiveness. * Demonstrated ability to collect, evaluate, and validate supporting control evidence. * Proven capability to prepare clear, defensible testing documentation and workpapers. * Knowledge of common IT control domains, including logical access, user provisioning, privileged access, change management, computer operations, and security controls. * Ability to work independently in a fully remote environment, taking ownership of deliverables with minimal supervision. Preferred Qualifications * Prior IT SOX testing experience and exposure to cybersecurity maturity assessments. * Familiarity with established cybersecurity, IT control frameworks, and GRC tools. * Experience working alongside Internal Audit, external auditors, Information Security, or Technology Risk teams. * Experience documenting control deficiencies and tracking remediation plans. * Relevant professional certifications or progress toward certifications (e.g., CISA, Security+, CRISC)., * Strong analytical, problem-solving, and risk-assessment skills with exceptional attention to detail. * Excellent written and verbal communication skills to interact with control owners and program leadership. * High accountability, self-sufficiency, and time-management capabilities to manage multiple assignments and meet deadlines. * Professional demeanor with a strong commitment to producing high-quality workpapers. ## Description The ITGC Consultant supports the IT Risk and Control Program within the Information Security organization. This role focuses on executing IT General Controls (ITGC) testing, including evidence review, testing documentation, status reporting, and risk analysis. Additionally, the consultant supports cybersecurity maturity assessments, technology risk activities, and SOX-related testing requests as project needs arise., ITGC Testing & Controls Assessment * Execute testing of IT General Controls (ITGCs) across assigned applications, systems, and technology processes. * Perform testing of control design and operating effectiveness, reviewing control descriptions and underlying technology risks. * Request, collect, review, and validate supporting evidence from control owners to ensure controls operated as designed. * Prepare complete, accurate, and audit-ready workpapers, documenting testing procedures, evidence reviewed, results, and conclusions. * Identify control gaps, exceptions, and deficiencies, escalating issues appropriately and conducting remediation validation testing. IT Risk & Control Program Support * Support the ongoing execution of the IT Risk and Control Program, assisting with technology risk assessments and control evaluations. * Analyze control results, identify potential security risks, and maintain testing trackers, status reports, and supporting records. * Report on control effectiveness, testing status, exceptions, and remediation progress to meet established timelines. Cybersecurity Maturity & SOX Support * Support cybersecurity maturity assessments by gathering documentation, evaluating current-state controls, and documenting risks and recommendations. * Assist with IT SOX control testing, walkthroughs, evidence collection, and remediation follow-up for SOX-relevant applications and infrastructure. * Respond to SOX-related audit requests and coordinate with technology control owners. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Humanizing Your Documentation](https://www.wearedevelopers.com/videos/476-humanizing-your-documentation) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Why Is Software Documentation Still Static – And Why Modern Browsers Deserve Better](https://www.wearedevelopers.com/videos/2054-why-is-software-documentation-still-static-and-why-modern-browsers-deserve-better) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Excellent Software Testing](https://www.wearedevelopers.com/videos/87-excellent-software-testing) ## Related Articles - [Why SmartGit Is More Than a Git Client](https://www.wearedevelopers.com/magazine/689-why-smartgit-is-more-than-a-git-client) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)