Own IT General Controls and technology risk as a Senior IT Auditor at Legora, applying AI and automation to enhance testing efficiency.
Posted by employer 4 days ago
First seen on Joblaze 2 days ago
Last verified on the company career page 18 hours ago
Skills & Technologies
What you'll build
Must have
Nice to have
AI in the day-to-day
Implementing AI-driven and automated solutions to reduce manual testing effort and improve testing coverage.
Requirements
Not disclosed in this posting: compensation, work arrangement, visa sponsorship.
Benefits
Joblaze summary
The Senior IT Auditor at Legora is responsible for developing and managing the IT General Controls (ITGC) program, focusing on assessing technology risks and implementing testing processes. This role requires expertise in IT audit and compliance, particularly in access management and change management, along with proficiency in tools like Auditboard and Vanta. Ideal candidates have a strong background in IT audit, preferably with Big 4 experience, and are comfortable building processes from the ground up in a fast-paced environment.
Joblaze insights
Quick facts
From the original posting
We lean in: ownership over titles, outcomes over intentions.
We're hiring a Senior IT Auditor to own IT General Controls (ITGC) and technology risk across our audit program. You'll assess risk across our core systems and vendors, design and execute testing where formal processes don't yet exist, and be a key point of coordination with external audit and our co-source partner on all IT-related matters.
This is a hands-on, build-from-scratch role for someone who wants real ownership over how technology risk is assessed and controlled as the company scales — and who's excited to apply AI and automation to make testing faster and more effective, not just more of the same
You'll work closely with the CIO org, Engineering, Security, Finance, external audit, and our co-source partner to build a rigorous, efficient ITGC program from the ground up.
More than that, we believe you will thrive by taking ownership of:
Contributing the IT risk assessment and translating it into a prioritized testing plan across access, change management, and operations
Designing new ITGC testing processes, workpaper templates, and documentation frameworks from scratch
Coordinating with external audit and the co-source partner on timelines, deliverables, and open items for IT controls
Leading walkthroughs with system owners and IT stakeholders across key applications and infrastructure
Testing access provisioning/deprovisioning, change management, and system operations controls across in-scope systems
Assessing SOC 1/SOC 2 reports for key vendors and subservice organizations, and evaluating complementary user entity controls (CUECs)
Assessing control deficiencies for severity and root cause, and driving remediation plans to completion with system and process owners
Implementing AI-driven and automated solutions to reduce manual testing effort and improve testing coverage
You're a controls-minded IT audit professional who pairs technical fluency with strong judgment. You're comfortable operating in ambiguity, enjoy owning a program end-to-end, and know how to translate technology risk into a practical testing plan.
3+ years of experience in IT audit, ITGC testing, or a related IT risk/compliance function
Big 4 or co-source firm experience in IT audit
Demonstrated experience building or significantly enhancing an ITGC testing program or methodology from scratch
Strong understanding of access management, change management, and system operations control concepts
Experience reviewing SOC 1/SOC 2 reports and assessing vendor/subservice organization risk
Strong track record managing external audit and/or co-source relationships
Proficiency with Auditboard, Vanta, NetSuite, Google Docs/Workspace, major LLM providers (e.g., ChatGPT, Claude, Gemini), Salesforce, and Workday
Strong written and verbal communication skills, with the ability to explain technical control concepts to non-technical stakeholders
A high degree of ownership and comfort building process where none exists
While not required, we think this role could be an especially strong fit if you've helped build or scale an ITGC program through a period of rapid growth.
We'd be excited if you bring:
CISA, CISSP, CIA, or similar certification
Prior experience applying AI or automation tools directly within an IT audit or testing workflow
Experience auditing cloud infrastructure and SaaS environments (e.g., Github, Azure, AWS, GCP, Okta, Google Workspace)
Experience with data analytics or continuous monitoring tools (e.g., SQL, Power BI, Tableau, ACL)
Background in a SOX-compliant or public-company-readiness environment
Global collaboration: Partner with teams and clients across Europe, APAC, and North America.
In-person environment: Union Square office designed for ambitious builders and company provided lunch daily.
Benefits & Perks: We invest in our people with a comprehensive, thoughtfully designed benefits package:
Medical, Dental & Vision
Multiple medical plan options through Aetna and Kaiser Permanente
Dental plans via MetLife
Vision plans via Vision Care
Family Support
Generous parental leave
Free access to Maven Clinic
Dependent Care FSA
Additional Perks
Pre-tax commuter benefits
Life Insurance + STD/LTD
401(K) with generous company match
Unlimited PTO
Standard company text repeated across Legora's postings is omitted here.