Senior IT Internal Controls Auditor
Listed on 2026-09-12
-
IT/Tech
IT Business Analyst, Cybersecurity, Information Security & Data Protection
About Tilray Brands, Inc. Tilray Brands, Inc. ("Tilray") (Nasdaq: TLRY; TSX: TLRY), is leading global lifestyle and consumer packaged goods company with operations in Canada, the United States, Europe, Australia, and Latin America that is leading as a transformative force at the nexus of cannabis, beverage, wellness, and entertainment, elevating lives through moments of connection. Tilray’s mission is to be a leading premium lifestyle company with a house of brands and innovative products that inspire joy, wellness and create memorable experiences.
Tilray’s unprecedented platform supports over 40 brands in over 20 countries, including comprehensive cannabis offerings, hemp-based foods, and craft beverages.
Reporting to the Manager, Internal Audit, the Senior IT Internal Controls Auditor is responsible for supporting the planning and execution of IT audit engagements in alignment with departmental standards and regulatory requirements. This role will execute walkthroughs, review control evidence, test the design and operating effectiveness of IT controls, document testing results, and identify exceptions or control deficiencies. The position will work closely with control owners from IT Business Applications, IT Operations, and external auditors to support timely, accurate, and well-documented control testing across the Company’s operations.
Roleand Responsibilities
- Plan and perform SOX and IT controls testing, including walkthroughs, evidence review, sample selection, and test execution.
- Evaluate the design and operating effectiveness of internal controls over key IT systems.
- Review control evidence for completeness, accuracy, timeliness, and alignment with defined control requirements.
- Document test procedures, results, exceptions, and conclusions in accordance with Internal Audit standards.
- Identify, document, and communicate control exceptions, deficiencies, and potential gaps in control design or operation.
- Support walkthroughs with control owners to confirm process understanding, validate key control activities, and assess control design.
- Maintain and update risk and control matrices, narratives, and testing documentation based on process or control changes.
- Track remediation activities and perform follow-up testing to validate corrective actions.
- Coordinate with IT control owners and external auditors to support SOX testing, audit requests, and reliance procedures.
- Bachelor’s degree in Information Technology, Accounting, Finance, or a related field.
- Minimum of 5 years of experience in IT internal audit, SOX compliance, or a related controls-focused role.
- Professional certification such as CISA, CISM, CRISC, CIA, or equivalent is preferred.
- Strong understanding of internal control frameworks, including SOX, COSO, COBIT, and risk-based audit methodologies.
- Experience with IT audit testing, including ITGCs, ITACs, and system implementation or SDLC audits.
- Ability to identify control deficiencies, assess risk, and develop practical remediation recommendations.
- Strong documentation skills, including the ability to prepare clear work papers, narratives, control matrices, and audit findings.
- Advanced proficiency in Microsoft Office, particularly Excel, Word, Outlook, and PowerPoint.
- Experience with audit management, SOX, data analytics, or ERP systems is preferred.
- Cybersecurity audit experience, including knowledge of NIST, ISO 27001, or other security frameworks, is a strong asset.
- Excellent verbal and written communication skills, with the ability to work effectively with stakeholders across countries and functions.
- Strong analytical, organizational, and project management skills, with the ability to manage multiple priorities and meet deadlines.
- Flexi…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).