IT Audit Principal

RXinsider LTD.

Austin (TX)

Hybrid

USD 140,000 - 200,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health and Wellness
Internal Mobility
Career Development
Education Support
Inclusive Workplace
Work-Life Balance
Global Mobility

Job summary

Epicor seeks an IT Audit Principal to lead and execute complex internal IT audits across cyber, ITGCs, and application controls in diverse tech environments. You will assess risk, design effective controls, and advise leadership on strengthening the control environment.

You will collaborate with IT, Security, Finance, HR, and external auditors, applying hands-on control evaluations and enabling automation to improve audit programs. Hybrid work model and competitive benefits offered.

Qualifications

  • 8+ years in IT audit, IT compliance, SOX, or cybersecurity risk management.
  • Bachelor’s degree in information systems, cybersecurity, accounting, finance, or related field.
  • Certifications such as CISA, CISSP, CISM, CRISC, CIA, or CPA.

Responsibilities

  • Lead internal IT audit engagements from planning through reporting, including risk assessment and remediation monitoring.
  • Conduct cybersecurity audits across identity access, security monitoring, privileged access, vulnerability management, incident response.
  • Lead evaluations of cybersecurity programs against NIST and ISO 27001 aligned with audit plan and risk priorities.
  • Conduct ITGC SOX audits to assess access, change management, IT operations, interfaces, backups, and disaster recovery.
  • Evaluate SDLC controls for major implementations, upgrades, and transformations including governance, testing, and deployment readiness.
  • Provide thought leadership in risk-based internal audit planning, enterprise risk assessments, and scoping.
  • Partner with GRC, security, and technology teams to evaluate risks across cloud, infrastructure, and applications and assess control design/operating effectiveness.
  • Liaise with external auditors for ITGC and cybersecurity audits, ensuring timely communication of findings.
  • Lead root cause analysis and provide remediation recommendations for control deficiencies.
  • Develop, review, and maintain IT control documentation aligning SOX and cybersecurity requirements.
  • Enable continuous improvement initiatives including automation and new technology deployment.
  • Support executive leadership with special projects informing risk assessments and strategic initiatives.
  • Build and leverage AI workflows to enhance Internal Audit capacity.

Skills

IT audit
Cybersecurity risk
SOX
Big 4 experience

Education

Bachelor’s degree in Information Systems, Cybersecurity, Accounting, Finance, or related field

Tools

Workiva Wdesk
ChatGPT/Copilot/Claude AI tools
Salesforce
Workday
Azure Entra ID
Active Directory

Job description

As an IT Audit Principal, you will lead and execute complex internal IT audits across a variety of technology environments, including cloud and on-premises infrastructure, with a focus on Cybersecurity, IT General Controls (ITGCs), and Application Controls. You will assess control design and operating effectiveness, evaluate technology and security risks, identify control gaps and root causes, and provide practical recommendations that strengthen the organization overall control environment.

In this role, you will serve as an independent and objective advisor, partnering with leaders across IT, Security, Finance, HR, and external audit teams. You will apply deep subject matter expertise through hands‑on control evaluations, support major transformation initiatives, and advise leadership on effective ways to manage risk. We are seeking applicants with strong technical knowledge, sound judgment, and the ability to turn complex findings into clear actions that support a strong and sustainable control environment.

What you'll be doing
  • Lead internal IT audit engagements from planning through reporting, including risk assessment, control evaluation, stakeholder communication, and remediation monitoring.
  • Conduct cybersecurity audits using a comprehensive, risk-based approach to assess the design and effectiveness governance, risk management, and control processes established across key areas such as identity and access management, security monitoring, privileged access, vulnerability management, incident response, and other relevant cybersecurity domains.
  • Lead evaluations of cybersecurity programs and controls against established frameworks and standards such as NIST and ISO 27001, in alignment with the Internal Audit plan and business risk priorities.
  • Conduct ITGC SOX audits to assess the design and operating effectiveness of controls across key areas such as access management, change management, IT operations, interfaces, backups, and disaster recovery.
  • Evaluate System Development Life Cycle (SDLC) controls for major implementations, upgrades, and transformation, including project governance, requirements and design, user acceptance testing (UAT), data conversion, access and security, deployment readiness, and post implementation.
  • Provide thought leadership in the continuous development and execution of the risk based internal audit plan, supporting enterprise risk assessments, audit
  • prioritization, scoping, and coordination across IT, SOX, and operational audit actives.
  • Partner with GRC, security, and technology teams to evaluate risks across cloud, infrastructure, and application environments and assess whether key controls are appropriately designed and operating effectively.
  • Act as a liaison to external auditors for ITGC and cybersecurity-related audits, ensuring alignment and timely communication of findings.
  • Lead and perform root cause analysis and provide recommendations for control deficiencies, including those related to cybersecurity incidents and/or control gaps.
  • Develop, review, and maintain IT control documentation, including process flows, narratives, and control matrices, and ensuring alignment with both SOX and cybersecurity requirements.
  • Enable continuous improvement initiatives across IT Audit and cybersecurity programs, including automation and deployment of new technologies.
  • Support executive leadership with special project advisory that inform strategic initiatives, risk assessments, and special transformational projects as needed.
  • Build and leverage AI solutions and workflows to enable capacity or unlock capability for an Internal Audit function.
What you'll likely bring
  • 8+ years of progressive experience in IT audit, IT compliance, SOX, and/or cybersecurity risk management (public accounting and/or industry). Big 4 is a plus.
  • Specialized experience in the Software industry.
  • Bachelor’s degree in Information Systems, Cybersecurity, Accounting, Finance, or related field.
  • Relevant certifications such as CISA, CISSP, CISM, CRISC, CIA, or CPA (or equivalent).
What can set you apart
  • Deep experience performing cybersecurity audits.
  • Strong knowledge of ITGC domains (Access Management, Change Management, Interfaces, Backups, Disaster Recovery), SDLC, and their intersection with cybersecurity controls.
  • Deep experience auditing systems such as SalesForce, Workday, Kinetic, Microsoft Azure (Entra ID), Active Directory, and different types of cloud environments (IaaS, PaaS, and SaaS).
  • Strong understanding of SOX requirements (e.g. 302, 404), principles-based internal control-integrated framework (COSO), IT Frameworks (e.g., COBIT) and cybersecurity control frameworks (e.g., NIST CSF, ISO 27001, CIS Critical Security Controls).
  • Experience leveraging automation and tools such as Workiva’s Wdesk and AI tools (ChatGPT, Copilot, Claude, etc.).
  • Excellent communication and stakeholder management skills, with the ability to influence at all levels of the organization.

#LI-CM1

#HYBRID

About Epicor

At Epicor, we're truly a team. Join 5,000 talented professionals in creating a world of better business through data, AI, and cognitive ERP. We help businesses stay future-ready by connecting people, processes, and technology. From software engineers who command the latest AI technology to business development reps who help us seize new opportunities, the work we do matters. Together, Epicor employees are creating a more resilient global supply chain.

We're Proactive, Proud, Partners

Whatever your career journey, we'll help you find the right path. Through our training courses, mentorship, and continuous support, you'll get everything you need to thrive. At Epicor, your success is our success. And that success really matters, because we're the essential partners for the world's most essential businesses the hardworking companies who make, move, and sell the things the world needs.

Competitive Pay & Benefits
  • Health and Wellness: Comprehensive health and wellness benefits designed to support your overall well-being.
  • Internal Mobility: Opportunities for mentorship, continuing education, and focused career goal setting, with 25% of positions filled internally.
  • Career Development: Free LinkedIn Learning licenses for everyone, along with our Mentoring Program to boost your personal development.
  • Education Support: Geographically specific programs to balance the cost of education with the benefits of continued learning and personal development.
  • Inclusive Workplace: Collaborate with a diverse team in an inclusive, global workplace that fosters innovation and celebrates partnership.
  • Work-Life Balance: Policies built on mutual trust and support, encouraging time off to rest, recharge, and reconnect.
  • Global Mobility: Comprehensive support for international relocations and permanent residency processes.
Equal Opportunities and Accommodations Statement

Epicor is committed to creating a workplace and global community where inclusion is valued; where you bring the whole and real you-that’s who we're interested in. If you have interest in this or any role- but your experience doesn't match every qualification of the job description, that's okay- consider applying regardless.

We are an equal-opportunity employer.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Audit Principal
IT Audit Principal

Grow • Austin (TX)

Hybrid
USD 90,000 - 120,000
Comprehensive health and wellness benefits
Opportunities for mentorship and continuing education
Free LinkedIn Learning licenses
+4
IT Security Analyst
IT Security Analyst

Epicor • Austin (TX)

On-site
USD 65,000 - 90,000
Health and wellness benefits
Internal mobility
Career development
+5
Product Developer, Sr
Product Developer, Sr

Epicor • Solon (OH)

Hybrid
USD 120,000 - 160,000
Health and Wellness
Internal Mobility
Career Development
+4
Director of IT | Service Reliability & Operations Governance
Director of IT | Service Reliability & Operations Governance

Epicor • Philadelphia

On-site
USD 163,000 - 277,000
Health and Wellness
Internal Mobility
Career Development
+3
Director of IT | Service Reliability & Operations Governance
Director of IT | Service Reliability & Operations Governance

Epicor • Maryland

On-site
USD 163,000 - 277,000
Health & Wellness
Internal Mobility
Career Development
+3
Platform Delivery Lead
Platform Delivery Lead

Epicor • Washington

On-site
USD 120,000 - 160,000
Health and Wellness
Internal Mobility
Career Development
+4
Platform Delivery Lead
Platform Delivery Lead

Epicor • Philadelphia

On-site
USD 110,000 - 140,000
Health & Wellness
Internal Mobility
Career Development
+4
Director of IT | Service Reliability & Operations Governance
Director of IT | Service Reliability & Operations Governance

Epicor • Lehi (UT)

On-site
USD 163,000 - 277,000
Health benefits
Mentoring program
LinkedIn Learning
+4
Product Developer, Sr
Product Developer, Sr

EPIND Epicor India • Solon (IA)

Hybrid
USD 120,000 - 160,000
Health and Wellness
Internal Mobility
Career Development
+4
Platform Delivery Lead
Platform Delivery Lead

Grow • Herndon (VA)

Hybrid
USD 120,000 - 190,000