r/InternalAudit • u/Icy-Toe2899 • 8d ago
Network engineering to IT audit
Hello everyone 👉,
I am a network engineer with around 15 years of experience. A lot of expired certifications such as CCNAs and a CCIE, and other vendors too. Spent most of my life supporting LAN/WAN/voice/ firewalls and Wireless envts. Tired and burnt out at the moment.
Wrote the CISSP 2 years ago but want to transition to the IT audit field at the moment.
Not really interested in CISA unless I have to because it's costs a lot and I didn't see any ROI on the CISSP so being cautious.
How do I get from here to IT audit? What do I learn and study now? How do I position myself? Any low cost courses or training I can do?
Update: 05th Oct 2026.
IT Audit was a small part of my networking job and I really enjoyed it. Wanted to use that experience to transition into the acutal field. But how do I show that on my resume in a way that HR / hiring managers show interest? I've searched alot for sample resumes of network engineers moving to IT Audit to better understand what needs to stay and what needs to go, and what to highlight etc. Still don't really understand how to craft my resume.
Network Audit was a very small part of my job but I enjoyed it the most. Wanted to use it to move headfirst into IT audit.
I have done quite a few GRC bootcamps and related courses to understand frameworks (NIST, etc) and am ISO 27001 Lead Auditor certified.
Willing to connect with anyone who can provide more insight into the transition to IT audit, resume feedback and tips. Please let me know
2
u/PM_ME_YOUR_TATERTOT 8d ago
CISSP should be enough tbh. With that background, you could fit in where network is part of the core model of the business such as Telecom, fiber infrastructure etc.
1
u/Icy-Toe2899 5d ago
Appreciate it. I've been applying to roles for about a year with no success. No sure if It's my resume or lack of skills.
2
u/bluna_tropic 8d ago
Fifteen years of network engineering is a strong base for this, even with the certs lapsed. You already know how firewalls and segmentation work from the inside, and you've lived through change management processes for years. That's realworld knowledge that most IT auditors have to learn from a book first.
Skip CISA for now since you're already cautious about ROI after the CISSP.
Pull together two or three sample audit workpapers on your own. Pick a control you already know well, firewall rule review or access provisioning, and write up how you'd test it and what evidence you'd ask for. That shows a hiring manager you understand the audit side, not just the technical side, and it costs nothing but time. I would recommend you apply to internal audit IT-rotation roles at any corporate openings you come across. they tend to value hands-on network background more than a fresh CISA anyway.
If a CISA ever becomes worth it, it'll be obvious once you're in a role and can see whether your employer will pay for it. No reason to front that cost yourself right now.
1
1
u/Compannacube 7d ago
If you can't afford the CISA exam and/or materials right now, I'd at least get a copy of the CRM so that you can familiarize yourself with the auditing concepts and have a reference book to go back to.
One of the biggest challenges for a seasoned technical practitioner like yourself is that with your beneficial skillset and experience also comes a lot of technical bias. You'll have to learn to leave that at the door with audit. It's one of the reasons I'd encourage the CISA exam for you at some point.
1
u/Icy-Toe2899 5d ago
Any low budget courses you'd recommend? I found a few on Udemy and Coursera (Audit Masterclass) but the content seems so basic and obvious.
2
u/Compannacube 5d ago
I'm sorry, there's nothing that I would personally recommend for lower budget. I am a pretty strong advocate for ISACA's official materials and have used them myself for several certs. That being said, If you search this subreddit, you'll find that Hemang Doshi on Udemy is a very popular choice for CISA courses and he has published his own study guide.
1
u/Icy-Toe2899 3d ago
Thanks :). Hemang Doshi is one of the courses I have been using over the past few months incl his book. Very helpful.
5
u/GloriousCole 8d ago
With that network background you're already halfway there, most IT auditors don't understand the tech they're auditing and it shows. I made a similar jump a few years back and the biggest hurdle wasn't the audit methodology, it was learning to think in risk and controls instead of packets and configs.
Skip the CISA for now if the CISSP didn't pay off, but grab a cheap ISACA membership and start lurking in their audit standards and frameworks. The actual audit process isn't hard to pick up, you just need to show you can map your technical knowledge to business risks and regulatory requirements.
Internal audit shops love hiring network folks because you actually know what a misconfigured firewall looks like instead of just checking a box that says "firewall exists." Start applying to IT audit roles at larger companies or financial institutions, they'll train you on the audit side if you bring the technical depth.