SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
GitLab is seeking a Senior Internal Auditor to support its SOX compliance program and assess risk across a complex technology landscape spanning multi-cloud infrastructure, AI/ML systems, and modern development practices. Reporting to the Senior Manager of Technology Internal Audit, you will execute technology audits covering SOX compliance, cloud platforms (AWS, GCP), application controls, cybersecurity, AI/ML systems, and DevSecOps practices.
Key responsibilities include designing and testing IT general controls and application controls with minimal supervision; supporting the IT SOX program from planning through reporting; maintaining high-quality audit documentation including risk matrices, process flows, and findings; and owning remediation efforts by partnering with process owners on corrective action plans. You will collaborate with Engineering, IT Operations, Security, and business teams to assess emerging risks and evaluate new system implementations for control adequacy.
You will review controls across financial statement cycles (record to report, order to cash, hire to retire, procure to pay) and third-party SOC 1/2 reports. A key differentiator is your use of data analytics, automation, and generative AI tools to improve audit efficiency, coverage, and quality.
Required experience includes executing technology audits in complex environments, supporting IT SOX programs, and designing/testing IT general and application controls. You should be familiar with IT control frameworks (COBIT, NIST, ITIL, ISO 27001, COSO), cloud security principles, cybersecurity fundamentals (network security, encryption, IAM, vulnerability management, Zero Trust), and modern development practices (Agile, DevOps). Experience with data analytics and audit automation tools is expected. Strong written and verbal communication skills are essential for explaining technical findings and business impact to diverse audiences. A bachelor's degree in Accounting, IT, Computer Science, Finance, or related field is required, along with an active relevant professional certification (CPA, CIA, CISA, CISSP, or equivalent).