Senior IT Internal Auditor

Okta Inc

San Francisco, CA

JOB DETAILS
SALARY
$117,000–$160,600 Per Year
SKILLS
Accounting, Adobe Product Family, Alliance/Partner Management, Analysis Skills, Application Integration, Artificial Intelligence (AI), Auditing, Autism, Autoimmune Disease, Benchmarking, Business Process Management, Business Processes, CEH - Certified Ethical Hacker, CISA - Certified Information Systems Auditor, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, COPD (Chronic Obstructive Pulmonary Disease), Cancer, Cardiovascular Disease, Certified Internal Auditor (CIA), Change Management, Cloud Applications, Cloud Computing, Coaching, Communication Skills, Computer Science, Conflict Resolution, Continuous Improvement, Control Objectives for Information and related Technology (COBIT), Corrective Action, Cross-Functional, Customer Relations, Customer Relationship Management (CRM), Data Analysis, Data Modeling, Design Evaluation, Develop and Maintain Customers, Developmental Disabilities, Diabetes, Disaster Recovery, Disease, Documentation, Editing, Emerging Technology, Equal Employment Opportunity (EEO), Establish Priorities, Government Contracts, HIV/AIDS (Acquired Immune Deficiency Syndrome), Hearing Impairment, ISO (International Organization for Standardization), IT Governance, Identity Data Management, Information Technology & Information Systems, Information Technology/Systems Audit, Information/Data Security (InfoSec), Internal Audit, Internet Security, Interpersonal Skills, Interviewing Skills, Learning Disabilities, Legal, LinkedIn, Mathematics, Mentoring, Multiple Sclerosis, Multitasking, Neurotrauma (Traumatic Brain Injury), OFCCP (Office of Federal Contract Compliance Programs), Onboarding, Operating Systems, Operations Processes, People Management, Post Traumatic Stress Disorder (PTSD), Power BI, Presentation/Verbal Skills, Private Cloud, Problem Solving Skills, Process Improvement, Psychiatry and Mental Health, Public Accounting, Public Cloud, Pulmonary Disease, Python Programming/Scripting Language, Quality Assurance Methodology, Regulations, Reporting Skills, Right-Sizing, Risk, Risk Analysis, Risk Management, Risk Modeling, Root Cause Analysis, SQL (Structured Query Language), Slack, Software Development Lifecycle (SDLC), Software as a Service (SaaS), System Integration (SI), Tableau, Technical Leadership, Technology Analysis, Test Strategy, Testing, Time Management, Training Program, Training/Teaching, U.S. National Institute of Standards and Technology (NIST), United States Department of Labor (DOL), United States Military, Wound Care, Writing Skills
LOCATION
San Francisco, CA
POSTED
2 days ago

Senior IT Internal Auditor

San Francisco, California

Secure Every Identity, from AI to HumanIdentity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.This is an opportunity to do career-defining work. Were all in on this mission. If you are too, lets talk.As a Senior IT Internal Auditor, you will serve as a technical lead and subject matter resource on an agile, high-impact team operating across complex, technology, cybersecurity, and AI-related audit engagements. Reporting to the Internal Audit Manager, you will independently drive audit execution across Technology Data & Insights (TDI), Security, Engineering, and cross-functional business stakeholders - with minimal supervision. This role requires a practitioner who can move beyond task execution: you will contextualize control gaps within Oktas broader risk and governance landscape, mentor junior team members, and bring a continuous improvement mindset to everything you deliver. Company Description Okta is the foundation for secure connections between people and technology. By harnessing the power of the cloud, Okta allows people to access applications on any device at any time, while still enforcing strong security protections. It integrates directly with an organizations existing directories and identity systems. Because Okta runs on an integrated platform, organizations can implement the service quickly at large scale and low total cost. Thousands of customers, including Adobe, Allergan, Chiquita, LinkedIn, and Western Union, trust Okta to help their organizations work faster, boost revenue, and stay secure. To learn more about Okta, visit: https://www.okta.com. What You Will Own Audit Planning & Risk Assessment Independently lead technology,cybersecurity, and AI-related risk assessments to identify key enterprise risks, define audit scope, and prioritize testing strategies with limited management direction Design comprehensive, risk-based audit programs and testing procedures tailored to the technology environment. Apply professional judgment in setting audit objectives, sequencing fieldwork, and managing competing priorities across simultaneous engagements Audit Fieldwork & Testing Independently lead process walkthroughs and execute fieldwork in strict alignment with Internal Audit methodology, actively championing methodology standards with limited guidance Evaluate the design and operational effectiveness of key technology, cybersecurity, and AI-related controls Prepare high-quality, self reviewed detailed workpapers that clearly document scope, testing results, evidence, and conclusions; requiring minimal editorial revision Leverage data analytics, AI tools, and emerging technologies to enhance audit efficiency, automate workpapers, and evaluate AI/ML controls and governance Contribute to the identification and documentation of process improvements within the Internal Audit methodology, templates, and testing procedures Reporting & Remediation Pinpoint systemic root causes of control weaknesses and associate those causes with the specific business processes that generated or permitted them - going beyond symptom identification Contextualize audit findings and recommendations within Oktas wider risk, control, and governance environment, providing analysis that contributes to the annual audit opinion Draft clear, concise audit reports that require minimal revision, presenting findings with appropriate business impact framing for management and senior stakeholders Gain independent stakeholder agreement on root cause conclusions and right-sized corrective actions, while maintaining positive client relationships Partner with TDI, Security, Engineering, and cross-functional teams to track and ensure the timely completion of agreed-upon remediation activities Advisory & Collaboration Provide risk-based advisory support to management during business process improvements, new system implementations, or emerging technology assessments Mentor and provide structured guidance to Associate and Staff Auditors on audit methodology, workpaper standards, and root cause analysis techniques Champion Internal Audit methodology standards across the team, identifying and proposing improvements to templates, processes, and quality benchmarks What You Bring Bachelors degree in Computer Science, Information Systems, STEM (Science, Technology, Engineering, and Math), Accounting, or a related field 3-6 years of audit experience with a focus on technology, cybersecurity, or related field 2+ years of audit experience in diverse technology environments (e.g. operating systems, networks, public/private cloud, third-party cloud-based applications and platforms) 2+ years of audit experience with technology operational processes (e.g. software development lifecycle, system integration and monitoring, data protection, identity and access management) Experience assessing emerging AI risks (e.g. generative AI, ML models, automated decisioning, AI-enabled third-party services) Demonstrated ability to execute complex audit engagements independently, with minimal supervisory oversight Proven ability to identify and articulate systemic root causes of control deficiencies, linking causes to the business processes that generated them Strong understanding of IT general controls (ITGCs) and IT application controls (ITACs), including cybersecurity, Software Development Life Cycle (SDLC), access and change management, logging and monitoring, disaster recovery, and cloud computing Technical expertise in IT systems including infrastructure, cybersecurity, and familiarity with IT governance frameworks (e.g. NIST CSF, COBIT, ISO 27001) Strong analytical and critical thinking skills, with proficiency in analyzing complex data and extracting meaningful insights Strong written and verbal communication skills, including interviewing skills and the ability to effectively present audit findings with business partners, and minimal revisions on audit reports and workpapers Proficiency in data analytics tools (e.g., SQL, Python, Tableau, Power BI, or equivalent) and familiarity with AI-assisted audit tools (e.g., Claude, NotebookLM, Gemini) Excellent interpersonal skills, with demonstrated ability to independently manage client relationships and gain stakeholder agreement on sensitive findings What Sets You Apart Big 4 public accounting or IT audit advisory experience at a comparable firm Active Certified Information Systems Auditor (CISA) (strongly preferred); or Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Internal Auditor (CIA), or Certified Ethical Hacker (CEH) Experience auditing within cloud-based or Software-as-a-Service (SaaS) environments - IAM, identity governance, or zero-trust architectures a significant plus Awareness of AI governance, ethics, and emerging risks such as model bias, data privacy, and hallucination Experience contributing to internal audit methodology improvements, templates, or training programs What Success Looks Like Independence : Executes complex engagements start-to-finish with minimal direction; delivers on commitments with a high say/do ratio - what is promised is what is delivered, at the quality level expected Judgment: Distinguishes between a symptomatic finding and a systemic root cause without coaching; defends conclusions with sound argumentation and answers the "why" Risk Management: Applies a structured, process-level approach to risk - forms data- and experience-informed points of view and navigates ambiguity without hesitation Communication: Drafts findings and reports requiring minimal editing; presents independently to business partners with clarity and credibility Problem-Solving Transparency: Articulates their analytical approach - can walk a stakeholder or junior team member through how they reached a conclusion, not just what it is Intellectual Honesty: Demonstrates candor when challenged - comfortable acknowledging knowledge gaps and escalating rather than overreaching on conclusions Stakeholder Navigation: Maintains composure and credibility when findings are contested; resolves conflict without unnecessary escalation Methodology: Champions IA standards actively - identifies improvement opportunities without being asked Intellectual Curiosity: Proactively tracks emerging risks, regulatory changes, and technology shifts relevant to identity and access management - brings new intelligence to the team without being asked Collaboration: Elevates junior team members through structured guidance; viewed as a go-to resource by peers Ownership: Takes end-to-end accountability for assigned engagements - from planning through remediation closure - without requiring follow-up from management Adaptability: Thrives in a fast-paced, cloud-first environment; comfortable with ambiguity and shifting priorities How We Work This role operates in Oktas hybrid work environment. You are expected to go to the San Francisco office two days per week. #LI-hybrid P21169_3499823The annual base salary range for this position for candidates located in the San Francisco Bay area is between:$117,000-$160,600 USDBelow is the annual base salary range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: https://rewards.okta.com/us. The annual base salary range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington is between:$104,000-$143,000 USDThe Okta Experience Supporting Your Well-Being Driving Social Impact Developing Talent and Fostering Connection + Community We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.

U.S. Equal Opportunity Employment Information

Read more

Individuals seeking employment at this company are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation. When submitting your application above, you are being given the opportunity to provide information about your race/ethnicity, gender, and veteran status.

Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veterans discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Pay Transparency

Okta complies with all applicable federal, state, and local pay transparency rules. For additional information about the federal requirements, click here.

Voluntary Self-Identification of Disability Form CC-305 Page 1 of 1 OMB Control Number 1250-0005 Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years. Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labors Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor's Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/agencies/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your "major life activities." If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

Alcohol or other substance use disorder (not currently using drugs illegally) Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS Blind or low vision Cancer (past or present) Cardiovascular or heart disease Celiac disease Cerebral palsy Deaf or serious difficulty hearing Diabetes Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders Epilepsy or other seizure disorder Gastrointestinal disorders, for example, Crohns Disease, irritable bowel syndrome Intellectual or developmental disability Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD Missing limbs or partially missing limbs Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports Nervous system condition, for example, migraine headaches, Parkinson's disease, multiple sclerosis (MS) Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities Partial or complete paralysis (any cause) Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema Short stature (dwarfism) Traumatic brain injury

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.

Okta

The foundation for secure connections between people and technology

Okta is the leading independent provider of identity for the enterprise. The Okta Identity Cloud enables organizations to securely connect the right people to the right technologies at the right time. With over 7,000 pre-built integrations to applications and infrastructure providers, Okta customers can easily and securely use the best technologies for their business. More than 19,300 organizations, including JetBlue, Nordstrom, Slack, T-Mobile, Takeda, Teach for America, and Twilio, trust Okta to help protect the identities of their workforces and customers.

Follow Okta

About the Company

O

Okta Inc