Sr. IT Internal Auditor
Listed on 2026-05-01
-
IT/Tech
Cybersecurity, IT Business Analyst, IT Consultant, IT Project Manager
Job Description
Sompo has a unique opportunity for a Senior IT Auditor to join our Global IT Internal Audit team.
This role will work with our US Senior IT Audit Manager; the successful candidate will perform and oversee IT Internal Audits and IT SOX work across North America, the UK and European business lines (part of Sompo International), with opportunities to perform and oversee IT Internal Audits and IT SOX work across South America and the Asia region.
The successful candidate will be required to proactively perform and oversee IT Internal audits of IT Governance, IT General Controls, Cybersecurity, and IT Infrastructure, in line with standard third line Institute of Internal Auditors (IIA) audit methodology.
Location:
This position will be based out of our Purchase, NY office. We strive for collaboration which is why we offer a work environment where our employees thrive and develop long lasting careers.
Our business, your impact, our opportunity:
What you’ll be doing :- Performing a variety of third-line IT Internal Audits, completing audit fieldwork testing to assess the design and operating effectiveness of IT processes and related controls, within agreed timelines (with a strong delivery focus).
- Standard Internal Audit methodology will be followed, populating audit work performed within Team Mate (our Internal Audit system).
- Clear IT Audit reports will be drafted containing IT Audit Issues with agreed management action plans.
- Open IT Audit issues will be proactively tracked through to remediation / closure.
- Performing rolling IT SOX (Sarbanes‑Oxley Act) testing the design and operating effectiveness of IT Entity Level Controls (IT ELCs), IT General Controls (ITGCs) and IT Application Controls (ITACs) across key financial applications and supporting tools, within agreed timelines (with a strong delivery focus).
- Standard Financial Controls / ICoFR (Internal Control over Financial Reporting) methodology will be followed, populating SOX control design and operation within Team Mate (our Internal Audit system).
- Clear IT control deficiencies will be drafted with agreed management action plans.
- Open IT deficiencies will be proactively tracked through to remediation / closure.
- Collaboration with IT External Audit teams (including EY and Mazars) across Sompo International entities.
- While the role will focus on North America and Europe (including UK) IT Internal Audits, and IT SOX work, this role will also assist with IT Internal Audits and IT SOX work across other regions globally, where required.
- Bachelor’s degree in Computer Science, Accounting, Finance, Economics, or related IT Audit subject – required.
- Numerous years of relevant IT Audit experience from a “Big 4” professional services firm (Deloitte, PwC, KPMG, EY, or similar, such as BDO, Grant Thornton, Forvis, Mazars, etc.) – required.
- Certified Information Systems Auditor Certification (CISA) from the Information Systems Audit and Control Association (ISACA) – required.
- Base knowledge, skills, and experience in the principles and practices of technology, IT industry trends, IT Governance controls, IT General Controls (including IT Service Management), Cybersecurity controls (including network security), and IT infrastructure controls (including Cloud).
- Experience in standard Institute of Internal Auditors (IIA) audit methodology (audit planning, fieldwork, and reporting), with an attention to quality to meet methodology requirements with minimal review.
- Other relevant professional certifications are beneficial, such as the Certified Information Systems Security Professional Certification (CISSP) and/or Certified Internal Auditor Certification (CIA).
- Working knowledge of IT industry frameworks (including COBIT, NIST, ITIL) and IT Industry standards (such as ISO 27001, the Information Security Standard, and ISO 27017, the Cloud Security Standard, etc.).
- An understanding of the base requirements of key IT regulations such as the expected IT control requirements of the:
- Sarbanes‑Oxley Act of 2002 (SOX).
- Japan Sarbanes‑Oxley Act of 2006 (J‑SOX)
- New York State Department of Financial Services (NY DFS) Part 500 Cybersecurity Regulation.
- EU’s…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).