Epicorsoftware

IT Audit Principal

US, United StatesFull timeStaffPosted 18 days ago
Apply on Epicorsoftware →

Sign into see who you know at Epicorsoftware.

Help strengthen trust, accountability, and resilience across our technology environment. As an IT Audit Principal, you will lead complex audits across IT SOX, IT general controls, application controls, and cybersecurity frameworks. You will evaluate control design and operating effectiveness, identify meaningful risks and gaps, and provide practical recommendations that help the business improve.You will serve as an independent and objective partner to leaders across Internal Audit, IT, Security, Finance, and external audit teams. Drawing on your deep subject matter expertise, you will take a hands-on approach to control evaluations, support major transformation initiatives, and advise leadership on effective ways to manage risk. We are seeking applicants with strong technical knowledge, sound judgment, and the ability to turn complex findings into clear actions that support a strong and sustainable control environment.What you'll be doingLead the evaluation and ongoing monitoring of ITGCs to ensure adequate design, operating effectiveness, efficiency, and compliance with SOX requirements and regulatory expectations.Assess cybersecurity controls that intersect with ITGC domains, including identity and access management, privileged access, logging/monitoring, vulnerability management, and incident response.Drive evaluation of broader cybersecurity programs (e.g., NIST, ISO 27001) as dictated by our audit plan and underlying business objectives.Provide thought leadership and partnered advisory in the planning, scoping, and execution of IT SOX testing activities, including risk assessments and control rationalization.Evaluate System Development Life Cycle (SDLC) controls to ensure secure system implementation practices, including secure coding, change management, and vulnerability remediation.Partner with cybersecurity teams to assess risks related to cloud environments, infrastructure, and applications, ensuring appropriate controls are designed and operating effectively.Act as a liaison to external auditors for ITGC and cybersecurity-related audits, ensuring alignment and timely communication of findings.Lead root cause analysis and provide recommendations for control deficiencies, including those related to cybersecurity incidents and/or control gaps.Provide independent and objective advisory to IT and business stakeholders on control design, risk mitigation, and cybersecurity best practices.Develop, review, and maintain IT control documentation, including process flows, narratives, and control matrices, ensuring alignment with both SOX and cybersecurity requirements.Oversee and enhance the quarterly SOX certification process, incorporating cybersecurity risk considerations where applicable.Monitor emerging cybersecurity threats, regulatory changes, and industry trends, and assess their impact on the organization’s control environment.Enable continuous improvement initiatives across IT Audit and cybersecurity programs, including automation and...