> Markdown version of [/jobs/ext/2580969-senior-it-sox-operational-auditor](https://www.wearedevelopers.com/jobs/ext/2580969-senior-it-sox-operational-auditor). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior IT SOX/Operational Auditor - **Company:** NW Natural - **Location:** Austin, TX, United States - **Experience:** Expert - **Salary:** $98,450.0 - $140,300.0 - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Data Analysis, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Systems, Document Management Systems, Information Technology Audit, Microsoft Office, Microsoft PowerPoint, SAP (Applications), IT General Controls (ITGC), Information Technology - **Published:** August 2, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/15863482?backUrl=%2Fcareer%2F15863482%2FSenior-It-Sox-Operational-Auditor-Texas-Austin ## About the Role * Bachelor's degree in Information Systems, Computer Science, Accounting, or a related field * Certification as Certified Information System Auditor (CISA) is required * Public accounting and publicly traded company experience preferred * Minimum of five (5) years of experience performing IT SOX audits * Experience developing test work programs for new SOX controls, including both manual and automated controls * Experience performing baseline and benchmark testing of key reports supporting internal controls over financial reporting * Demonstrated ability to work independently, showing self-motivation and effective self-management with limited oversight * Problem-solving skills and the ability to manage effectively through ambiguity * Excellent organizational, project management, and time management skills, including the ability to multitask and meet deadlines * Proven ability to document work in accordance with external auditor expectations, with strong attention to detail * Experience scoping and executing IT operational audits, from planning, risk assessment, and scoping through reporting * Experience assessing and implementing controls aligned with the NIST Cybersecurity Framework (CSF) * Experience performing risk and control assessments using NIST framework guidance * Experience implementing and evaluating controls aligned with the NIST framework * Experience conducting IT risk assessments using COBIT risk guidance and mapping risks to COBIT control objectives * Collaborative and flexible team-oriented mindset * Exceptional written and verbal communication skills, including the ability to synthesize and clearly communicate technical information * Experience with SAP, data analytics tools, and AuditBoard preferred * Proficiency with Microsoft Office applications, including Excel, PowerPoint, and Word ## Description This position requires a candidate who is experienced at defining, leading and executing on the annual IT SOX Audit Plan, specifically the annual assessment of the design and effectiveness of the company's key IT SOX controls and testing of key reports which support internal controls over financial reporting. With regard to the annual IT SOX testing, this position will be responsible for independently and pro-actively managing relationships with key business partners consisting of the Company's business controls office, the Company's IT compliance office, and the Company's external auditors relative to the execution of IT SOX testing, while ensuring alignment with both management's and the external auditor's expectations. In addition, this position will be responsible for flexibly supporting IT operational audits and other related deliverables as a key member of the internal audit team. Day to Day: * Lead the development and execution of the annual IT SOX Audit Plan * Execute and report on IT SOX testing, including testing of IT general controls, automated application controls, and key reports * Plan, lead, perform, and document control walkthroughs to evaluate the design of IT general controls * Evaluate the operating effectiveness of key IT SOX general controls and automated application controls through testing * Perform baseline and benchmark testing of key SOX-relevant reports * Develop detailed test steps and audit procedures for testing new IT general controls, automated application controls, and key reports * Apply appropriate test procedures to existing IT SOX controls and reports to ensure key control attributes are adequately addressed * Document SOX testing work thoroughly and accurately, providing high-quality audit evidence to support conclusions and facilitate efficient review * Execute test work in compliance with external audit expectations to maximize reliance on internal SOX testing * Drive cross-functional stakeholder engagement to ensure successful execution of, and alignment with, the annual IT SOX testing plan * Identify, discuss, and validate potential control exceptions (e.g., SOX deficiencies and process improvement opportunities) in real time with key stakeholders in a professional and constructive manner * Project manage IT SOX audit activities, ensuring timely execution, achievement of testing deadlines, and regular status reporting to stakeholders Additional responsibilities include: * Support the IT Audit Program Manager and audit team by leading and performing IT operational audits, including: + Developing risk-based IT audit scopes + Leading, conducting, and documenting walkthroughs + Developing, executing, and documenting audit testing procedures + Drafting audit findings, developing practical recommendations, and proposing remediation actions * Support internal and external audit activities related to the year-end financial statement audit by delivering required audit documentation and analyses * Contribute to overall team effectiveness by performing additional responsibilities as assigned in support of departmental objectives and the annual audit plan ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Developing the Rich Text Editor for DeepL.com](https://www.wearedevelopers.com/videos/1172-developing-the-rich-text-editor-for-deepl-com) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)