{"schemaVersion":"jobsearcher.job.v1","id":"f5fe87f2efcd1d36d276dc21","url":"https://jobsearcher.com/jobs/f5fe87f2efcd1d36d276dc21","canonicalUrl":"https://jobsearcher.com/jobs/f5fe87f2efcd1d36d276dc21","title":"Senior IT Internal Auditor","description":"Secure Every Identity, from AI to Human\n\nIdentity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.\n\nThis is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.\nAs a Senior IT Internal Auditor, you will serve as a technical lead and subject matter resource on an agile, high-impact team operating across complex, technology, cybersecurity, and AI-related audit engagements. Reporting to the Internal Audit Manager, you will independently drive audit execution across Technology Data & Insights (TDI), Security, Engineering, and cross-functional business stakeholders — with minimal supervision.\nThis role requires a practitioner who can move beyond task execution: you will contextualize control gaps within Okta's broader risk and governance landscape, mentor junior team members, and bring a continuous improvement mindset to everything you deliver.\nCompany Description\nOkta is the foundation for secure connections between people and technology. By harnessing the power of the cloud, Okta allows people to access applications on any device at any time, while still enforcing strong security protections. It integrates directly with an organization's existing directories and identity systems. Because Okta runs on an integrated platform, organizations can implement the service quickly at large scale and low total cost. Thousands of customers, including Adobe, Allergan, Chiquita, LinkedIn, and Western Union, trust Okta to help their organizations work faster, boost revenue, and stay secure. To learn more about Okta, visit: https://www.okta.com.\nWhat You Will Own\nAudit Planning & Risk Assessment\nIndependently lead technology,cybersecurity, and AI-related risk assessments to identify key enterprise risks, define audit scope, and prioritize testing strategies with limited management direction\nDesign comprehensive, risk-based audit programs and testing procedures tailored to the technology environment.\nApply professional judgment in setting audit objectives, sequencing fieldwork, and managing competing priorities across simultaneous engagements\nAudit Fieldwork & Testing\nIndependently lead process walkthroughs and execute fieldwork in strict alignment with Internal Audit methodology, actively championing methodology standards with limited guidance\nEvaluate the design and operational effectiveness of key technology, cybersecurity, and AI-related controls\nPrepare high-quality, self reviewed detailed workpapers that clearly document scope, testing results, evidence, and conclusions; requiring minimal editorial revision\nLeverage data analytics, AI tools, and emerging technologies to enhance audit efficiency, automate workpapers, and evaluate AI/ML controls and governance\nContribute to the identification and documentation of process improvements within the Internal Audit methodology, templates, and testing procedures\nReporting & Remediation\nPinpoint systemic root causes of control weaknesses and associate those causes with the specific business processes that generated or permitted them — going beyond symptom identification\nContextualize audit findings and recommendations within Okta's wider risk, control, and governance environment, providing analysis that contributes to the annual audit opinion\nDraft clear, concise audit reports that require minimal revision, presenting findings with appropriate business impact framing for management and senior stakeholders\nGain independent stakeholder agreement on root cause conclusions and right-sized corrective actions, while maintaining positive client relationships\nPartner with TDI, Security, Engineering, and cross-functional teams to track and ensure the timely completion of agreed-upon remediation activities\nAdvisory & Collaboration\nProvide risk-based advisory support to management during business process improvements, new system implementations, or emerging technology assessments\nMentor and provide structured guidance to Associate and Staff Auditors on audit methodology, workpaper standards, and root cause analysis techniques\nChampion Internal Audit methodology standards across the team, identifying and proposing improvements to templates, processes, and quality benchmarks\nWhat You Bring\nBachelor's degree in Computer Science, Information Systems, STEM (Science, Technology, Engineering, and Math), Accounting, or a related field\n3-6 years of audit experience with a focus on technology, cybersecurity, or related field\n2+ years of audit experience in diverse technology environments (e.g. operating systems, networks, public/private cloud, third-party cloud-based applications and platforms)\n2+ years of audit experience with technology operational processes (e.g. software development lifecycle, system integration and monitoring, data protection, identity and access management)\nExperience assessing emerging AI risks (e.g. generative AI, ML models, automated decisioning, AI-enabled third-party services)\nDemonstrated ability to execute complex audit engagements independently, with minimal supervisory oversight\nProven ability to identify and articulate systemic root causes of control deficiencies, linking causes to the business processes that generated them\nStrong understanding of IT general controls (ITGCs) and IT application controls (ITACs), including cybersecurity, Software Development Life Cycle (SDLC), access and change management, logging and monitoring, disaster recovery, and cloud computing\nTechnical expertise in IT systems including infrastructure, cybersecurity, and familiarity with IT governance frameworks (e.g. NIST CSF, COBIT, ISO 27001)\nStrong analytical and critical thinking skills, with proficiency in analyzing complex data and extracting meaningful insights\nStrong written and verbal communication skills, including interviewing skills and the ability to effectively present audit findings with business partners, and minimal revisions on audit reports and workpapers\nProficiency in data analytics tools (e.g., SQL, Python, Tableau, Power BI, or equivalent) and familiarity with AI-assisted audit tools (e.g., Claude, NotebookLM, Gemini)\nExcellent interpersonal skills, with demonstrated ability to independently manage client relationships and gain stakeholder agreement on sensitive findings\nWhat Sets You Apart\nBig 4 public accounting or IT audit advisory experience at a comparable firm\nActive Certified Information Systems Auditor (CISA) (strongly preferred); or Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Internal Auditor (CIA), or Certified Ethical Hacker (CEH)\nExperience auditing within cloud-based or Software-as-a-Service (SaaS) environments - IAM, identity governance, or zero-trust architectures a significant plus\nAwareness of AI governance, ethics, and emerging risks such as model bias, data privacy, and hallucination\nExperience contributing to internal audit methodology improvements, templates, or training programs\nWhat Success Looks Like\nIndependence : Executes complex engagements start-to-finish with minimal direction; delivers on commitments with a high say/do ratio — what is promised is what is delivered, at the quality level expected\nJudgment: Distinguishes between a symptomatic finding and a systemic root cause without coaching; defends conclusions with sound argumentation and answers the \"why\"\nRisk Management: Applies a structured, process-level approach to risk — forms data- and experience-informed points of view and navigates ambiguity without hesitation\nCommunication: Drafts findings and reports requiring minimal editing; presents independently to business partners with clarity and credibility\nProblem-Solving Transparency: Articulates their analytical approach — can walk a stakeholder or junior team member through how they reached a conclusion, not just what it is\nIntellectual Honesty: Demonstrates candor when challenged — comfortable acknowledging knowledge gaps and escalating rather than overreaching on conclusions\nStakeholder Navigation: Maintains composure and credibility when findings are contested; resolves conflict without unnecessary escalation\nMethodology: Champions IA standards actively — identifies improvement opportunities without being asked\nIntellectual Curiosity: Proactively tracks emerging risks, regulatory changes, and technology shifts relevant to identity and access management — brings new intelligence to the team without being asked\nCollaboration: Elevates junior team members through structured guidance; viewed as a go-to resource by peers\nOwnership: Takes end-to-end accountability for assigned engagements — from planning through remediation closure — without requiring follow-up from management\nAdaptability: Thrives in a fast-paced, cloud-first environment; comfortable with ambiguity and shifting priorities\nHow We Work\nThis role operates in Okta's hybrid work environment. You are expected to go to the San Francisco office two days per week.\n#LI-hybrid\nP21169_3499823\nThe Okta Experience\nSupporting Your Well-Being\nDriving Social Impact\nDeveloping Talent and Fostering Connection + Community\nWe are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.\n\nOkta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.\n\nIf reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.\n\nNotice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.","company":"Okta","rawCompany":"okta","city":"Millbrae","state":"CA","isRemote":false,"isActive":true,"createdAt":"2026-08-01T08:56:58.229Z","occupations":[{"code":"13-2011.00","title":"Accountants and Auditors","slug":"accountants-and-auditors"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"11-3021.00","title":"Computer and Information Systems Managers","slug":"computer-and-information-systems-managers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541611","title":"Administrative Management and General Management Consulting Services","slug":"administrative-management-and-general-management-consulting-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Senior IT Internal Auditor","description":"Secure Every Identity, from AI to Human\n\nIdentity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.\n\nThis is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.\nAs a Senior IT Internal Auditor, you will serve as a technical lead and subject matter resource on an agile, high-impact team operating across complex, technology, cybersecurity, and AI-related audit engagements. Reporting to the Internal Audit Manager, you will independently drive audit execution across Technology Data & Insights (TDI), Security, Engineering, and cross-functional business stakeholders — with minimal supervision.\nThis role requires a practitioner who can move beyond task execution: you will contextualize control gaps within Okta's broader risk and governance landscape, mentor junior team members, and bring a continuous improvement mindset to everything you deliver.\nCompany Description\nOkta is the foundation for secure connections between people and technology. By harnessing the power of the cloud, Okta allows people to access applications on any device at any time, while still enforcing strong security protections. It integrates directly with an organization's existing directories and identity systems. Because Okta runs on an integrated platform, organizations can implement the service quickly at large scale and low total cost. Thousands of customers, including Adobe, Allergan, Chiquita, LinkedIn, and Western Union, trust Okta to help their organizations work faster, boost revenue, and stay secure. To learn more about Okta, visit: https://www.okta.com.\nWhat You Will Own\nAudit Planning & Risk Assessment\nIndependently lead technology,cybersecurity, and AI-related risk assessments to identify key enterprise risks, define audit scope, and prioritize testing strategies with limited management direction\nDesign comprehensive, risk-based audit programs and testing procedures tailored to the technology environment.\nApply professional judgment in setting audit objectives, sequencing fieldwork, and managing competing priorities across simultaneous engagements\nAudit Fieldwork & Testing\nIndependently lead process walkthroughs and execute fieldwork in strict alignment with Internal Audit methodology, actively championing methodology standards with limited guidance\nEvaluate the design and operational effectiveness of key technology, cybersecurity, and AI-related controls\nPrepare high-quality, self reviewed detailed workpapers that clearly document scope, testing results, evidence, and conclusions; requiring minimal editorial revision\nLeverage data analytics, AI tools, and emerging technologies to enhance audit efficiency, automate workpapers, and evaluate AI/ML controls and governance\nContribute to the identification and documentation of process improvements within the Internal Audit methodology, templates, and testing procedures\nReporting & Remediation\nPinpoint systemic root causes of control weaknesses and associate those causes with the specific business processes that generated or permitted them — going beyond symptom identification\nContextualize audit findings and recommendations within Okta's wider risk, control, and governance environment, providing analysis that contributes to the annual audit opinion\nDraft clear, concise audit reports that require minimal revision, presenting findings with appropriate business impact framing for management and senior stakeholders\nGain independent stakeholder agreement on root cause conclusions and right-sized corrective actions, while maintaining positive client relationships\nPartner with TDI, Security, Engineering, and cross-functional teams to track and ensure the timely completion of agreed-upon remediation activities\nAdvisory & Collaboration\nProvide risk-based advisory support to management during business process improvements, new system implementations, or emerging technology assessments\nMentor and provide structured guidance to Associate and Staff Auditors on audit methodology, workpaper standards, and root cause analysis techniques\nChampion Internal Audit methodology standards across the team, identifying and proposing improvements to templates, processes, and quality benchmarks\nWhat You Bring\nBachelor's degree in Computer Science, Information Systems, STEM (Science, Technology, Engineering, and Math), Accounting, or a related field\n3-6 years of audit experience with a focus on technology, cybersecurity, or related field\n2+ years of audit experience in diverse technology environments (e.g. operating systems, networks, public/private cloud, third-party cloud-based applications and platforms)\n2+ years of audit experience with technology operational processes (e.g. software development lifecycle, system integration and monitoring, data protection, identity and access management)\nExperience assessing emerging AI risks (e.g. generative AI, ML models, automated decisioning, AI-enabled third-party services)\nDemonstrated ability to execute complex audit engagements independently, with minimal supervisory oversight\nProven ability to identify and articulate systemic root causes of control deficiencies, linking causes to the business processes that generated them\nStrong understanding of IT general controls (ITGCs) and IT application controls (ITACs), including cybersecurity, Software Development Life Cycle (SDLC), access and change management, logging and monitoring, disaster recovery, and cloud computing\nTechnical expertise in IT systems including infrastructure, cybersecurity, and familiarity with IT governance frameworks (e.g. NIST CSF, COBIT, ISO 27001)\nStrong analytical and critical thinking skills, with proficiency in analyzing complex data and extracting meaningful insights\nStrong written and verbal communication skills, including interviewing skills and the ability to effectively present audit findings with business partners, and minimal revisions on audit reports and workpapers\nProficiency in data analytics tools (e.g., SQL, Python, Tableau, Power BI, or equivalent) and familiarity with AI-assisted audit tools (e.g., Claude, NotebookLM, Gemini)\nExcellent interpersonal skills, with demonstrated ability to independently manage client relationships and gain stakeholder agreement on sensitive findings\nWhat Sets You Apart\nBig 4 public accounting or IT audit advisory experience at a comparable firm\nActive Certified Information Systems Auditor (CISA) (strongly preferred); or Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Internal Auditor (CIA), or Certified Ethical Hacker (CEH)\nExperience auditing within cloud-based or Software-as-a-Service (SaaS) environments - IAM, identity governance, or zero-trust architectures a significant plus\nAwareness of AI governance, ethics, and emerging risks such as model bias, data privacy, and hallucination\nExperience contributing to internal audit methodology improvements, templates, or training programs\nWhat Success Looks Like\nIndependence : Executes complex engagements start-to-finish with minimal direction; delivers on commitments with a high say/do ratio — what is promised is what is delivered, at the quality level expected\nJudgment: Distinguishes between a symptomatic finding and a systemic root cause without coaching; defends conclusions with sound argumentation and answers the \"why\"\nRisk Management: Applies a structured, process-level approach to risk — forms data- and experience-informed points of view and navigates ambiguity without hesitation\nCommunication: Drafts findings and reports requiring minimal editing; presents independently to business partners with clarity and credibility\nProblem-Solving Transparency: Articulates their analytical approach — can walk a stakeholder or junior team member through how they reached a conclusion, not just what it is\nIntellectual Honesty: Demonstrates candor when challenged — comfortable acknowledging knowledge gaps and escalating rather than overreaching on conclusions\nStakeholder Navigation: Maintains composure and credibility when findings are contested; resolves conflict without unnecessary escalation\nMethodology: Champions IA standards actively — identifies improvement opportunities without being asked\nIntellectual Curiosity: Proactively tracks emerging risks, regulatory changes, and technology shifts relevant to identity and access management — brings new intelligence to the team without being asked\nCollaboration: Elevates junior team members through structured guidance; viewed as a go-to resource by peers\nOwnership: Takes end-to-end accountability for assigned engagements — from planning through remediation closure — without requiring follow-up from management\nAdaptability: Thrives in a fast-paced, cloud-first environment; comfortable with ambiguity and shifting priorities\nHow We Work\nThis role operates in Okta's hybrid work environment. You are expected to go to the San Francisco office two days per week.\n#LI-hybrid\nP21169_3499823\nThe Okta Experience\nSupporting Your Well-Being\nDriving Social Impact\nDeveloping Talent and Fostering Connection + Community\nWe are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.\n\nOkta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.\n\nIf reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.\n\nNotice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.","datePosted":"2026-08-01T08:56:58.229Z","dateModified":"2026-08-01T08:56:58.229Z","hiringOrganization":{"@type":"Organization","name":"Okta","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Millbrae","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"f5fe87f2efcd1d36d276dc21"},"url":"https://jobsearcher.com/jobs/f5fe87f2efcd1d36d276dc21"}}