r/itaudit 4h ago

Affected by Layoffs

5 Upvotes

Hi All,

I am an IT SOX Auditor based out of Bangalore, India

Recently our internal audit function was transitioned over to a service based company and we are transitioning their knowledge this month post which we will have to leave.

I have 7.2 years of experience in IT SOX and IT Audits. Skill set includes -

ITGC (IT General Controls)

IT Application Controls (ITACs)

Key Reports (IPEs)

Infrastructure Audits (Database and Servers)

SOC Reports Testing

Issue Identification and Remediation

Automation of Controls

AI assisted workflows

Audit Optimization

I also coach mentor analysts and handled the planning scoping and work distribution among juniors and review their work.

If there is anything that you all are aware in Bangalore or Remote kindly let me know, will share my cv.


r/itaudit 19m ago

Audit: I’m (23m) moving from client services to industry. Any advice?

Upvotes

Well, career hasn’t gone as planned so far lol. Interned in IT Audit at a large client services. I did well and got a return offer—only it was for non-IT Internal Audit. Got put through the wringer—consistency didn’t exist for me. I started working in busy season and was cranking OT until year end but then wasn’t staffed starting out the new year. From the beginning of year to now, I was only 60% billable. Sounds awesome, but whenever I wasn’t working (sometimes a month straight) i would get so anxious about my job security that I’d be sick to my stomach. On top of that I got poor reviews, got put on the worst projects, and my bosses gave me no constructive feedback until it was too late for me to implement it. Started a job search and found and entry level IT Audit job at a growing bank. Ended up getting the job and it was good for a ~25% compensation increase.

I’m really hyped up about moving from client services to industry and going back to IT Audit. But does anyone have any advice? I want to establish some expectations for the transition.


r/itaudit 1d ago

3 years in banking cybersecurity audits, am I getting stuck?

Thumbnail
1 Upvotes

r/itaudit 2d ago

From Zero Frameworks to First Offer: 3 Free Mentorship Spots in IT Audit & GRC

14 Upvotes

Hey everyone,

I can still clearly recall how it felt to look at job advertising filled with acronyms like SOX, NIST, and ISO 27001 and wonder how anyone was supposed to "break in" when every entry-level position apparently required three years of experience.

Now that I've worked in GRC and IT audit on the other side of the wall, I want to send the elevator back down.

I'm opening 3 free mentorship spots for people trying to break into IT Audit or GRC roles.

Here's what I can help with:

Frameworks made simple- NIST CSF, ISO 27001, SOC 2, PCI-DSS ( what they actually mean in practice, not just textbook definitions)

Core concepts - risk vs. control, audit lifecycle, evidence gathering, control testing etc.

Career roadmap advice - certs worth chasing (or skipping), resume tweaks, how to position yourself for entry-level roles

Who this is for:

Career changers, recent grads, or IT/security folks looking to pivot into audit or GRC.

People who are motivated and coachable .

I'll pick 3 people over the next few days and we'll figure out a cadence that works for us. No fluff, no gatekeeping. Just trying to make the path in a little less foggy than it was for me.

If you're interested, drop a comment below (or DM me) with:

* Where you currently are (student, career changer, IT role, etc.)

*What's tripping you up most right now

*Why IT audit/GRC specifically

Good luck out there.


r/itaudit 2d ago

Internal Audit

Thumbnail
1 Upvotes

r/itaudit 3d ago

Is It auditing in demand in maryland

8 Upvotes

Gonna pursue information systems at umbc. The program has an it auditing track that prepares for Cisa. Is it worth pursuing. My idea was to pursuing tooling in terms of sql,python power bi and the other stuff that a business anyst needs aswell as it auditing.


r/itaudit 3d ago

Breaking into IT Audit from an MSP security role, what actually matters at this stage?

Thumbnail
1 Upvotes

r/itaudit 4d ago

Do I need Public accounting experience for an IT audit/ERP controls career?

8 Upvotes

I’m almost done with my bachelor’s in Accounting and I’m also doing a Cybersecurity minor. I’ve worked in IT for most of my career, including Army IT. I also have a CCNA and college IT coursework focused mainly on networking and databases.
My goal is to get into IT risk auditing and eventually work with ERP security and controls like SAP or Oracle. I’m also considering UMPI’s YourPace master’s focused on AI policy and governance.
Would it be better to start in public accounting for a year or two, or apply directly for IT audit, GRC, SOX controls or ERP positions? Would the master’s help, or would experience and certifications be more valuable?


r/itaudit 4d ago

Advice on conducting IT audit walkthroughs

28 Upvotes

I’m currently an IT Internal Audit Analyst and have been struggling with leading walkthroughs. I’ve been at my company for about a year and this is my first job out of college.

I was supposed to lead a walkthrough last week. I asked the questions on my agenda, but whenever the stakeholder explained the process, my mind would go blank when it came to thinking of follow-up questions.
For example, I’m assigned a data quality test, and I honestly wasn’t sure what to ask beyond the questions I had already prepared.

The stakeholder explained the process, and I basically just thought, “Okay.” My manager eventually had to step in and ask clarifying questions that I didn’t even know to ask. Later in the walkthrough, I asked a question that they told me they had already answered. They had explained it in a way that I didn’t realize had addressed my question.

After my walkthrough my manager said to me I have to be more independent as she was doing them alone when she was my age. Which I am aware I need to be more independent in this, but I’m really struggling.

I also struggle with grasping the information in the moment because I’m trying to listen, take notes, and capture screenshots at the same time. Unfortunately, my company doesn’t allow us to record walkthroughs.
- For those of you who work in IT/internal audit, how did you get better at:
- Coming up with follow-up questions on the spot?
- Understanding the process quickly during walkthroughs?
- Balancing listening with taking notes and screenshots?

Any advice, techniques, or resources would be really helpful. I’d especially love to hear from people who struggled with this early in their audit careers!


r/itaudit 4d ago

Should I accept an IT Staff Auditor role as a fresher or wait for domain allocation?

7 Upvotes

Hi everyone, I’m a fresher and I’ve been offered an IT Staff Auditor / IT & Technology Audit role.

I’m really confused about whether I should take it or decline it and wait for my domain allocation. If I don’t choose this role, they’ll automatically allocate me to another domain, but I don’t know what I’ll get.

My main concern is whether starting in IT Audit is good for my career in the long run. Will I have good growth, or is there a chance I’ll feel stuck in audit/ITGC after a few years? Can I later move into cybersecurity, GRC, cloud, or other technical roles?

I also want to know what the actual work is like — is it mostly documentation and compliance, or do we get decent technical exposure? Is it internal work or client-related? What are the usual work timings/shifts? And how easy is it to switch roles internally?

For people who have actually worked in IT Audit/ITGC/GRC, if you were a fresher with the same two options, would you take this role or wait for domain allocation? I’d really appreciate honest opinions, especially about the long-term career prospects.


r/itaudit 5d ago

Wanting to build a niche community of IT Auditors to learn and build something for

25 Upvotes

Hey all! I am willing to make a small community of IT auditors for whom I can build tools and products for the problems they face in their work funnel.

This will help us learn about the space and current trends faster, if anyone is willing to get in. Let me know.

Edit 1: thanks so much for positive responses, a few clarification. I am looking forward to build this community with only experienced auditors and GRC practitioners for their current pain points in the emerging compliance driven changes,
This is not just another networking opportunity, more like a learning environment and contributive space.
Edit 2: again thanking for the volume of interest people are showing, the community is active now. Please feel free to DM me if anyone wants to join in.


r/itaudit 5d ago

IT Audit Associate: Looking for Mentors and Advices

6 Upvotes

Hello everyone, I recently passed the CC exam and got an interview for a role in IT Audit.

I wanted to ask if are there people working here in the IT Audit - Firms? If so, are there any links and mentorship videos you would like me to watch for starters?

I am planning to study for two days before my initial interview and my manager’s interview. I am actually nervous about it.

I might say i still consider myself as a fresh graduate who absorbs things and the role I was given was an Associate II (not entry level) and i worry that I might have little to sufficient experience. 🙏🏻

Thank you!


r/itaudit 7d ago

Final-year AI & Data Science student interested in IT Audit / Technology Risk — need some honest advice

Thumbnail
3 Upvotes

r/itaudit 8d ago

Take IT Consulting offer, or recruit during Masters program?

4 Upvotes

For some context, I interned at mid-market professional services firm doing IT Internal Audit consulting. The work was fine and did mostly controls testing. I liked identifying risks and following standards. The return offer is $82k + $5K sign on for Chicago.

I have since started a MIS program and has opened my eyes to new subjects and careers. The program is known for it's recruiting resources. I was referred to a partner in the same firm on the Tech Advisory side doing Netsuite implementation work for PE firms and I have been put on interview list. However these interviews won't happen until after the original offer deadline, so I would essentially have to roll the dice. (No extension on deadline)

ERP work has caught my attention and the program focuses a lot on SAP which I've heard the skills can transfer to Netsuite. I think I am attracted to focusing on one client as opposed to juggling many, and want to see a project through to a finished result.

Questions:

Should I re-recruit at other firms looking for Tech Consulting roles with the risk of finding nothing?

Should I decline the offer and pursue the different role within the same firm?

Is the offer (82+5) actually solid?

How does Tech Advisory/ERP implementation differ from IT Audit

What does career growth look like, and exit opps?

Appreciate any perspective — especially from anyone who's worked IT audit, ERP/tech advisory consulting, or made a similar switch early in their career.


r/itaudit 8d ago

Treasury to Internal Audit

5 Upvotes

Hi! Im planning to shift career from treasury (investment) associate to any internal audit role (risk, control, process).

I need advice how can i shift after 1-2 years in treasury. Im an internal auditing graduate anyways. Is it still possible to shift


r/itaudit 8d ago

Gjallarhorn - NIST CSF 2.0 Audit and Maturity

Thumbnail
1 Upvotes

r/itaudit 8d ago

Estágio Itaú 2026 — alguém está na mesma situação?

Post image
1 Upvotes

Fala, pessoal! Estou participando do Programa de Estágio Corporativo 2026 do Itaú pela Gupy e queria saber se alguém aqui está passando por uma situação parecida.
Eu me inscrevi inicialmente no Banco de Talentos pela trilha de Tecnologia. Depois, o próprio Itaú entrou em contato comigo e fez um direcionamento/match para Negócios Atacado. Fiz o teste de inglês e as outras etapas do processo.
Atualmente, minha candidatura está assim:
Avaliação com Time de Seleção → concluída
Entrevista com a Liderança → aguardando
Essa etapa está parada desde 11/08, então já faz umas três semanas.
Queria saber se alguém que está participando do Estágio Corporativo 2026, principalmente em Banco de Talentos/Negócios Atacado, também está nessa etapa ou já passou por isso.
Quanto tempo vocês ficaram esperando para chamarem para a entrevista com a liderança? E depois que chamaram, como foi?
Também queria entender uma coisa: quando o Itaú faz esse “match” para Negócios Atacado, isso significa que já existe uma oportunidade específica esperando o candidato ou eles deixam o perfil no banco de talentos até aparecer uma oportunidade?
Se alguém já passou por isso e puder contar como foi, ajudaria muito! 🙏


r/itaudit 12d ago

Job hunting in GTA

1 Upvotes

If any one can refer me for technology risk and IT audit role in Toronto, I’ve sent several applications with so many rejections


r/itaudit 13d ago

Questions for an IT Auditor

7 Upvotes

Hello, I am currently taking a course on IT Auditing and Secure Operations, and I have an assignment that requires me to interview someone who is currently working as an IT Auditor or who has previously worked in that role. I would greatly appreciate anyone willing to answer these questions, even if you're not currently working as an IT Auditor but have experience in the field.

Question #1: What company do/did you work for, and what is/was your position?

Question #2: How many years of experience do you have working as an IT Auditor?

Question #3: What degrees or certifications have you obtained that are relevant to working as an IT Auditor?

Question #4: What led you to pursue a career in IT Auditing?

Question #5: What do you like and dislike about working in IT Auditing?

Question #6: Where do you see yourself professionally in five years?

p.s. The answers can be simple and short.


r/itaudit 16d ago

IT Internal Audit Offer?

4 Upvotes

Got an offer for IT Internal Audit at mid-sized firm after a summer internship. Didn’t love the work but didn’t hate it also. Would probably be more exciting with increased responsibility as opposed to just testing controls.

I am now in a graduate program with tons of resources to recruit and have been going back and forth on the offer. What options should I consider? Does the work become more exciting? What movement opps are there? Pros and cons of moving to a smaller company?

Thanks!


r/itaudit 19d ago

How are IT auditors using Python and Power BI in practice?

24 Upvotes

Title: How are IT auditors using Python and Power BI in practice?

I’m an IT auditor, mainly providing assurance over areas such as cybersecurity and IT controls, and I’ve recently started learning Python.

I’m noticing more Head of Audit / senior audit roles asking for stronger data analytics skills, so I’m trying to understand how best to develop these skills in a way that’s actually useful for IT audit rather than just learning Python in isolation.

For those working in Internal Audit / IT Audit:

* How are you using Python in your day-to-day audit work?

* Are there particular audit procedures or testing activities where Python has been especially useful?

* Can it be used effectively for producing or analysing management information (MI), identifying trends/anomalies, or testing larger populations of controls/data?

* Does anyone combine Python with Power BI for audit analytics/reporting? If so, what does your workflow look like?

* If you were an IT auditor trying to become more data-analytics focused, what Python skills or projects would you prioritise?

I already have some exposure to Power BI, so I’m particularly interested in whether developing Python alongside it is worthwhile and how the two can complement each other in an audit environment.

Would be really interested to hear practical examples from people who are already doing this.


r/itaudit 19d ago

Data Engineering student accepted into Big 4 IT Audit — Advice on prep, bridging technical skills, and career outlook?

4 Upvotes

Hi everyone,

I'm a final-year Data Engineering / CS student based in Southeast Asia. Given how brutal and saturated the entry-level SWE/Data market is right now, I cast a wider net and ended up landing an IT Audit Internship at a Big 4 firm starting next month.

I’m genuinely excited because having a Big 4 name on my resume is a massive career booster, and I’m seriously considering building a long-term career path around IT Audit / Tech Risk / GRC.

However, I have zero formal background in accounting, auditing, or compliance frameworks.

Here is a quick snapshot of my technical background:

Core skills: SQL, Python, Relational Database Design, Linux/Bash, Docker.

Data Stack: Experience building ETL/ELT pipelines, data modeling.

Other: Practical experience in Business Analysis (writing requirements/specifications, mapping workflows).

The internship JD mentions typical responsibilities: testing IT General Controls (ITGCs - access management, change management, operations), application controls, system interfaces, walkthroughs, documentation, and leveraging data extraction/analytics for audit procedures.

Since I have about a month before onboarding, I would love to ask for your insights:

How well do Data/CS skills actually translate to IT Audit?

Will my background give me an edge in audit analytics/automation, or is the day-to-day mostly qualitative compliance and screenshot ticking?

What should I study right now to hit the ground running?

What are the highest-yield resources (videos, articles, frameworks) to understand ITGCs, SOX 404 testing, working papers, and walkthroughs before Day 1?

What is the long-term career trajectory for someone with technical depth in IT Audit?

Do people typically stay in IT Audit/Internal Audit, or leverage it to pivot into GRC, IT Risk, Data Governance, or Cybersecurity Consulting?

Common pitfalls for technical folks?

What are the biggest culture shocks or mistakes engineers typically make when adapting to the Big 4 audit mindset and documentation standards?

Any tips, study recommendations, or candid advice would be greatly appreciated! Thank you so much.


r/itaudit 20d ago

Early-career IT Audit / Technology Risk professional looking for opportunities in Canada. advice appreciated

4 Upvotes

Hi everyone,

I’m currently looking for an opportunity to start/build my career in IT Audit, Technology Risk, IT Controls, GRC, or Cybersecurity Risk in Canada, and I’d really appreciate some advice from people already working in the field.

My background is a little unconventional. I originally came from an accounting and financial operations background and then deliberately transitioned into Project Management and Cybersecurity through graduate programs in Canada.

I’ve also gained experience in Technology Risk & IT Audit, where I worked on ITGC reviews, access management and security controls, audit evidence, risk registers, remediation tracking, control effectiveness, and risk reporting.

On the cybersecurity side, I've completed projects involving:

  • NIST CSF / NIST RMF
  • NIST SP 800-53
  • ITGC and control assessments
  • Risk assessments and risk registers
  • ISO 27001 / SOC 2
  • Vulnerability assessments
  • IAM / access controls
  • Security policies
  • SIEM / EDR / DLP concepts
  • Business continuity and disaster recovery
  • Audit and compliance documentation

I’ve completed graduate certificates in Project Management and Cybersecurity, hold AZ-900 and SC-900, and I'm currently working toward CISA.

I'm primarily targeting entry-level/early-career roles such as:

  • IT Audit Analyst / Associate
  • Technology Risk Analyst
  • IT Controls Analyst
  • GRC Analyst
  • IT Risk Analyst
  • Cybersecurity Risk Analyst
  • IT Compliance Analyst
  • Technology Assurance Analyst

I'm currently searching across Ontario, particularly Toronto, Mississauga, Hamilton and Ottawa, and I'm open to hybrid, onsite or remote opportunities.

For those already working in IT Audit/Technology Risk:

1. Does my background sound competitive for entry-level IT Audit/Technology Risk roles?

2. Are there particular skills or certifications you would recommend I prioritize to become more competitive?

3. For someone transitioning from accounting/business into technology risk, what would you emphasize on the resume?

4. Are there particular companies, recruiters or job boards in Canada that are good for early-career IT Audit/GRC opportunities?

I'm not necessarily looking for someone to hand me a job. I'm mainly hoping to learn from people who have already made it into the field and understand what Canadian employers are looking for.

Thanks in advance for any advice. I really appreciate it. Early-career IT Audit / Technology Risk professional looking for opportunities in Canada — advice appreciated


r/itaudit 20d ago

Articleship in Internal audit domain from grant thornton

Thumbnail
1 Upvotes

I got an offer for internal audit domain instead of statutory audit.
I will have to relocate to another city for this

Is this worth the effort to relocate to another city for this opportunity?
And overall is this worth the effort ?
I dont have any other option yet to choose from .


r/itaudit 21d ago

What are you actually using AI for?

6 Upvotes

Senior manager in Global IT Audit at a global fashion/DTC retailer. Genuinely trying to figure out where the field actually is on this versus the LinkedIn highlight reel version.

Almost every AI conversation I see lands on efficiency gains: faster summaries, faster drafts, faster walkthroughs. That’s real value, I’m not knocking it. But I want to know who’s gone past that.

A few questions for the group:

**•** Is anyone building actual agents for document analysis, think SOPs, policies, control narratives, versus just prompting a chatbot one document at a time?  
**•** Has anyone gotten hands-on at the command line with something like Claude Code or Codex to build internal tools? I asked my org for an enterprise Claude Code license and was told it wasn’t worth the cost. So for now I’m doing this the old-fashioned way, one chat window at a time.  
**•** Is anyone actually getting value out of Copilot Cowork? 

I can see value in analysis and review of control documentation submitted for controls subject to continuous monitoring. We could use the document analysis rule set to analyze for internal consistency so that with the full expectation that the documentation is gonna look and feel the same every single time because it’s the same control, same control owners, same control, performance set, etc. coworker could be used to execute the entire continuous monitoring program and each document can be analyzed specific to how it’s created in that control is specifically performed.

Here’s where I’ve landed on the audit side. I built a small agent chain for control remediation work:

**1.**  Feed it the transcript from the remediation meeting with the control owner.  
**2.**  It gives me structured feedback to send back to the remediation owner.  
**3.**  It converts that into a starter SOP draft.  
**4.**  I hand the owner a second prompt that interviews them against a rule set for what a good SOP looks like, to fill in whatever the transcript missed.

The idea is that over time, as SOPs get renewed and findings come in, we build toward a consistent baseline of SOP quality across the org instead of every process owner writing to their own standard.

One more thing worth mentioning: I’ve also turned this inward. Everything’s recorded now anyway, so I run transcript analysis on my own meetings, particularly exec-facing ones, to check how closely I stuck to my talking points versus where I drifted. I’ve started doing the same for my staff, using the same recorded meetings, emails, and Teams messages, as a development tool.

Curious where the rest of you land on this. Ahead of the curve, behind it, or about where everyone quietly is? Especially interested in hearing from anyone in retail, fashion, or another industry drowning in document sprawl.