IT Audit Contractor II SOX ITGC & IT Application Controls
Location: Palo Alto, CA (Hybrid 2 days onsite)
Duration: 9-Month Contract
About the Role
We are seeking an experienced IT Audit Contractor to support a fast-paced Internal Audit organization in executing its Sarbanes-Oxley (SOX) compliance program. The ideal candidate will have strong hands-on experience with IT General Controls (ITGCs), IT Application Controls (ITACs), Key Report Testing, and SOC 1 reviews, along with the ability to partner effectively with internal stakeholders and external auditors.
This is an excellent opportunity for professionals with a Big 4, consulting, or public company internal audit background who thrive in dynamic technology environments.
Key Responsibilities
Execute SOX IT General Controls (ITGC) testing across logical access, change management, computer operations, and program development.
Perform IT Application Controls (ITAC) testing, including input, processing, interface, and output controls across financial applications.
Manage end-to-end Key Report Testing by validating report logic, report parameters, completeness, and accuracy while maintaining audit-ready documentation.
Perform SOC 1 review activities, including evaluation of SOC reports, bridge letters, control exceptions, subservice organizations, and Complementary User Entity Controls (CUECs).
Coordinate walkthroughs, collect audit evidence, and prepare high-quality workpapers that support internal and external audit requirements.
Partner with external auditors to facilitate audit reliance and ensure timely completion of SOX activities.
Track audit observations, control deficiencies, and remediation efforts while validating corrective actions.
Maintain audit documentation within AuditBoard or similar GRC platforms.
Contribute to process improvements that enhance the efficiency and effectiveness of the SOX compliance program.
Support additional IT internal audit and operational audit initiatives as required.
Required Qualifications
Bachelor's degree in Information Systems, Computer Science, Accounting, or a related discipline.
4+ years of experience in IT Audit, IT Risk, or Internal Audit.
Strong hands-on experience with SOX compliance, ITGC testing, and IT Application Controls (ITAC).
Experience performing Key Report Testing, including validation of report logic, parameters, completeness, and accuracy.
Experience reviewing SOC 1 reports, bridge letters, control exceptions, and Complementary User Entity Controls (CUECs).
Knowledge of IT control domains including logical access, change management, computer operations, and SDLC controls.
Experience preparing audit documentation and workpapers suitable for internal and external audit review.
Strong communication, documentation, stakeholder management, and analytical skills.
Ability to manage multiple audit workstreams and meet project deadlines.
Preferred Qualifications
Big 4 consulting or public accounting experience.
Experience within a public company's Internal Audit function.
CISA certification or equivalent.
Experience with AuditBoard or similar Governance, Risk & Compliance (GRC) platforms.
Familiarity with Google Workspace, Lucidchart, Visio, or similar documentation tools.