> Markdown version of [/jobs/ext/3054842-it-senior-internal-auditor](https://www.wearedevelopers.com/jobs/ext/3054842-it-senior-internal-auditor). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Senior Internal Auditor - **Company:** National Vision, Inc. - **Location:** Alpharetta, GA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Word, Microsoft Excel, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, Databases, Data Integrity, Data Visualization, Identity and Access Management, Information Technology Audit, IT Management, Information Technology Operations, Information Systems Security Architecture Professional, Python (Programming Language), Microsoft PowerPoint, Systems Development Life Cycle, Power BI, SQL Databases, Software Vulnerability Management, Google Cloud, Cloud Platform System, Uipath, Information Technology, Data Analytics, Operational Systems, User Administration, Alteryx - **Published:** September 24, 2026 - **Apply:** https://jobs.smartrecruiters.com/NationalVision1/744000151463829-it-senior-internal-auditor ## About the Role Work Experience * 4-6 years in an audit capacity in either a publicly traded company and/or with a public accounting firm (Required) * 2-4 years experience leading and executing IT audits, including ITGCs, ITACs, key reports/calculations, SOX, SOC, and ISO-related controls (Required) Education * Four year college degree or equivalent experience. in Information Systems, Cybersecurity, Computer Science, or a related field (Required) Licenses, Certifications, Professional Affiliations * Certified Information Systems Auditor (CISA) (Preferred) * Certified Internal Auditor (CIA) (Preferred) * Certified Information Systems Security Professional (CISSP) (Preferred) * Certified in Risk and Information Systems Control (CRISC) (Preferred) * Certified Information Security Manager (CISM) (Preferred) * Cloud security certifications (e.g., AWS, Azure, or Google Cloud) (Preferred) * Additional certifications related to IT governance, cybersecurity, privacy, risk management, or data analytics (Preferred) Additional Skills * Advance skills in Microsoft tool suite (Excel, Power Point, Word). (Required) * Working knowledge of IT environments, including applications, databases, operating systems, cloud platforms, infrastructure, and networks (Required) * Understanding of IT control frameworks and risk management concepts, including ITGCs, ITACs, cybersecurity, IT operations, and technology governance (Required) * Strong verbal and written communication skills, including the ability to communicate technical concepts to non-technical audiences and strong analytical, critical-thinking, and problem-solving skills with the ability to identify risks and develop practical recommendations. (Required) * Knowledge of cybersecurity domains, including identity and access management, vulnerability management, data protection, incident response, and third-party risk management. (Preferred) * Experience auditing cloud environments, operational technology (OT), cybersecurity programs, or digital transformation initiatives. (Preferred) * Experience using data analytics, reporting, automation, or visualization tools (e.g., Power BI, SQL, UiPath,Alteryx, Python). (Preferred) * ## Description The Senior IT Internal Auditor is responsible for independently planning and executing IT audits to evaluate the effectiveness of technology controls, risk management practices, and regulatory compliance across National Vision's retail, laboratory, corporate, and technology operations. As a member of the Global Internal Audit team, this role partners with business leaders, IT management, and risk and compliance stakeholders to assess and improve controls supporting enterprise systems, cybersecurity, data integrity, and technology-enabled business processes. The position conducts audits and advisory reviews related to SOX, SOC, ISO, cybersecurity, privacy, third-party risk management, system development life cycle (SDLC), user access management, IT automated controls (ITACs), key reports and calculations, and supporting infrastructure to enhance operational efficiency, compliance, and risk mitigation across the organization. What Would You Do? The Specifics. * Execute risk-based IT audits across applications, infrastructure, cybersecurity, SOX, and technology operations. * Perform IT risk assessments and evaluate the design and effectiveness of key controls. * Assess controls over user access, system development, automated controls, key reports, data integrity, and third-party risk. * Identify control gaps, root causes, and opportunities to strengthen risk management and compliance. * Communicate audit observations, recommendations, and project results to management. * Lead multiple audit engagements and provide guidance and feedback to junior team members. * Partner with business, IT, compliance, and external stakeholders throughout the audit lifecycle. * Support control remediation efforts and monitor corrective action plan implementation. * Drive continuous improvement through audit automation, continuous monitoring, and process enhancements. * Maintain current knowledge of emerging technologies, cybersecurity risks, regulatory requirements, and industry best practices. * Maintain confidentiality and uphold the highest standards of integrity and objectivity. * Support continuous improvement initiatives within the Internal Audit function. * Develop and maintain effective working relationships across the organization. ## Related Videos - [How to achieve web automation with UiPath](https://www.wearedevelopers.com/videos/310-how-to-achieve-web-automation-with-uipath) - [Beyond Dashboards: Fixing Text-to-SQL with Semantic RAG](https://www.wearedevelopers.com/videos/2036-beyond-dashboards-fixing-text-to-sql-with-semantic-rag) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [RPA crash course for .Net developers – intro into the world of RPA from the perspective of a .Net developer](https://www.wearedevelopers.com/videos/271-rpa-crash-course-for-net-developers-intro-into-the-world-of-rpa-from-the-perspective-of-a-net-developer) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [REST, GraphQL, gRPC, and more: A comparison of modern API styles](https://www.wearedevelopers.com/videos/100247-rest-graphql-grpc-and-more-a-comparison-of-modern-api-styles) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)