Senior Staff Internal Audit-IT
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, IT Business Analyst, IT Consultant, Information Security & Data Protection
We Are
Synopsys is the leader in engineering solutions from silicon to systems, enabling customers to rapidly innovate AI-powered products. We deliver industry-leading silicon design, IP, simulation and analysis solutions, and design services. We partner closely with our customers across a wide range of industries to maximize their R&D capability and productivity, powering innovation today that ignites the ingenuity of tomorrow.
You AreYou have spent years in the details of IT systems, not just reading documentation butdigginginto logs, configurations, and control environments to understand what is really happening versus what someone says is happening. Auditing, for you, is not about checklists. It is about understanding how a systemworks, where the gaps are, and what matters most when things go sideways.
You are comfortable sitting with a database administrator walking through access controls forone hour and then presenting findings to aVP,translating technical risk into business language without losing the substance. When you review an ERP system or a security process, you are not just checking boxes. You are thinking about what could break, what the business depends on, and where the real exposure sits.
Risk frameworks like COBIT and NIST are tools you use, notthe theoryyou studied. You know how to build an audit plan that reflects actual risk, not just what was audited last year. At Synopsys, you will work on systems that matter, with a team that takes this work seriously and expects you to bring a point of view, not just a process.
WhatYou'll Be Doing
- Plan and execute IT audits across infrastructure, applications, and security controls, working directly with system owners and IT teams to assess design and operating effectiveness
- Lead Risk Assessments that inform the annual IT audit plan, identifying where the company's technology exposure sits and what needs attention this year
- Develop and execute audits focused on technologies, including SAP and Oracle ERP, UNIX & Windows environments, cloud computing, cybersecurity, privacy, and emerging technologies (AI/ML)
- Test SOX General IT Controls and IT Application Controls, including evaluating access controls, change management, segregation of duties, and data integrity controls, documenting findings and working with process owners to drive remediation
- Evaluate IT processes and controls against regulatory requirements, internal policies, and frameworks like COBIT and NIST
- Prepare audit reports and present findings to senior management, translating technical issues into business risk language that drives action
- Collaborate with Information Security, IT Operations, and business teams to ensure audit coverage aligns with the company's evolving risk landscape
- Reduce the company's exposure to IT and security risk by identifying control gaps before they become incidents
- Strengthen Synopsys' compliance posture with SOX, regulatory requirements, and internal governance standards
- Provide leadership with clear, actionable insights into where IT risk sits and what needs to be addressed
- Improve the quality and reliability of IT controls across ERP, infrastructure, and application environments
- Help shape the IT audit strategy by contributing to risk-based planning and audit methodology development
- Build trust with IT and business teams by conducting audits that are rigorous, fair, and focused on real risk
- Support continuous improvement of IT governance and control frameworks across a global technology company
- Bachelor's or Master's degree in Computer Science, Information Science, IT, or a related field
- 5+ years of hands-on experience planning and executing IT audits or Information Security audits, including risk assessment and audit reporting
- Working knowledge of SAP and Oracle ERP systems, particularly around access controls, change management, and application-level controls
- Experience applying risk frameworks such as COBIT, NIST, or similar in audit planning and execution
- Strong analytical skills to assess technology controls, identify gaps, and evaluate risk in complex IT environments
- Experience testing SOX General IT Controls and IT Application Controls is a strong plus
- Professional certifications such as CISA, CIA, or CISSP are highly valued
- You can walk into a technical conversation about database permissions or network segmentation and walk out with a clear picture of what the risk is
- You write audit findings that are specific, fair, and focused on…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).