Full Time
2500 to 3000
40
Apr 17, 2026
We are looking for an IT Audit Associate with an active CISA certification to join our SOC 2 attestation practice. This role strengthens the firm’s IT audit competence by bringing formal information systems audit training and methodology to our evidence review and control evaluation processes. You will work alongside our evidence review team and the engagement partner to evaluate the design and operating effectiveness of controls across the trust services criteria.
This is a hands-on role. You will review technical evidence, assess control environments for startup-stage service organizations, identify exceptions and deviations, and help ensure our engagement files meet professional standards. You will also contribute to the firm’s internal quality by helping develop and deliver SOC 2 methodology training for the broader team and supporting our inspection and monitoring processes.
Required Qualifications
• Active CISA (Certified Information Systems Auditor) certification in good standing with ISACA
• Minimum 3 years of experience in information systems auditing, IT controls, or information security (consistent with CISA experience requirements)
• Familiarity with SOC 2 examinations, AICPA Trust Services Criteria, or SSAE attestation standards
• Working knowledge of cloud infrastructure (AWS required; GCP, Azure, or DigitalOcean a plus) including IAM, networking, logging, and security services
• Understanding of IT general controls: access management, change management, operations, and physical/logical security
• Available to work 40 hours per week during U.S. business hours (core hours overlap required; flexible within Eastern, Central, or Pacific time)
• Strong written communication skills — you will document findings, draft workpapers, and write assessment memos that need to withstand peer review scrutiny
• Ability to work independently within a structured methodology while knowing when to escalate