Lead, IT Audit and Technology Risk
$185k - $220kNotion Labs
Who We AreNotion is the collaborative AI workspace where teams and agents think together. We're building one place where your knowledge, projects, meetings, and AI tools live side by side, so work is faster, clearer, and less fragmented. Millions of individuals, small teams, and large companies run their work on Notion.Notinos (our employees) are customer zero in bringing this future of work to life. We care about craft, building things that last, and the belief that great work is still fundamentally human. Our goal isn’t to ship the next feature. Each and every team of Notinos is working to set the standard for how humans work together in the AI era. From building a business’s system of record to making and managing AI agents to automating away the busy work, we care deeply about giving our customers more time for their life’s work.About the Role:We are seeking a strategic and technically fluent Lead, IT Audit to join our Finance team reporting to the Head of Internal Audit. This is a broad, high-impact role spanning both IT SOX compliance and operational IT audits. You will help establish and elevate our technology controls program end to end — owning the IT SOX lifecycle, designing the IT general and application controls framework, embedding AI and automation into how we test and monitor controls, and delivering value-added operational IT and cybersecurity audits that strengthen how the company builds and runs its systems. You will partner with leaders across Engineering, Security, IT, Finance, and the business to ensure sound technology controls are built into how the company operates as we scale. This role is ideal for someone who thinks like a builder, not just an auditor — someone who can translate complex control and security requirements into practical, scalable processes in a fast-moving SaaS environment with modern cloud architecture and complex data flows.This role can be based in either San Francisco or New York City. We work from our offices on Mondays, Tuesdays and Thursdays (our Anchor Days) because we do our best thinking and building together in person. We’re looking for someone who’s excited to work alongside the team during those days. What You'll Achieve:Own the full IT SOX lifecycle — scoping, risk assessment, documentation, walkthroughs, testing, deficiency evaluation, remediation, and reporting — driving automation and efficiency across IT general controls (ITGCs) and IT application controls (ITACs)Design, operate, and continuously improve technology controls spanning user access and segregation of duties, change management, SDLC and CI/CD pipelines, interfaces, data flows, and system-generated reportsDesign and execute value-added operational IT and cybersecurity audits — across cloud infrastructure, security operations, identity and access management, data protection and privacy, disaster recovery and resilience, and vendor and third-party risk — while driving enterprise-level technology risk assessment that anticipates emerging risks before they materializeServe as a strategic advisor on cross-functional initiatives (product launches, new systems, architecture changes, M&A) and as the primary point of contact for external auditors, ensuring sound controls are built in from day one and audit evidence is complete, clear, and timelyOwn IT control deficiencies from identification through sustained remediation while partnering with and educating system owners to build a culture of ownership and accountabilityChampion the adoption of AI and modern tooling — from automated control testing and anomaly detection to continuous monitoring and AI-assisted documentation — to make the IT audit function smarter, faster, and more forward-lookingSkills You'll Need to Bring: 12+ years of progressive IT audit, IT SOX, or technology risk experience, with a combination of Big 4 and high-growth technology company experienceDeep, hands-on ownership of IT SOX/ITGC programs, with a strong understanding of PCAOB standards, SEC requirements, and frameworks such as COSO, COBIT, NIST, and ITILDemonstrated experience designing and leading operational IT audits end to end — including annual planning, risk-based scoping, fieldwork, and reporting — across areas such as IT operations, infrastructure resilience, disaster recovery and business continuity, capacity and availability management, and IT vendor and third-party riskStrong cybersecurity audit experience with working fluency in frameworks and regulations such as NIST CSF, ISO 27001, SOC 2, GDPR, and CCPA, and the ability to translate them into practical, testable controlsSoftware or SaaS industry experience is a must — particularly modern cloud-based technology stacks (AWS, GCP, Azure), software development lifecycles, and complex data flows — paired with strong technical knowledge across cloud security configurations, identity and access management, change management, DevOps and CI/CD pipelines, and enterprise IT operations risks and controlsProcess leadership — a track record of building functions, designing new processes and policies, and driving continuous improvementBachelor's degree in Information Systems, Computer Science, Accounting, or a related field; CISA, CISSP, CISM, CIA, CPA, or equivalent certification requiredStrong stakeholder management and communication skills, with the ability to translate complex technical and audit topics into clear language and influence partners across all levels of the organizationNotion is committed to providing highly competitive cash compensation, equity, and benefits. The compensation offered for this role will be based on multiple factors such as location, the role’s scope and complexity, and the candidate’s experience and expertise, and may vary from the range provided below. For roles based in San Francisco, the estimated base salary range for this role is $185,000 - $220,000 per year.By clicking “Submit Application”, I understand and agree that Notion and its affiliates and subsidiaries will collect and process my information in accordance with Notion’s Global Recruiting Privacy Policy.#LI-OnsiteA Note on AIYou don’t need deep AI expertise for every role, but we do expect every Notino to be intellectually curious, drawn to tinkering and discovery, and excited to use AI as a real collaborator in their work. For some roles, AI fluency is a core requirement — when that’s the case, we'll say so explicitly in the qualifications. People who thrive here don’t treat AI as a novelty. They use it to think better, and make their work easier for others to build on.Equal Opportunity & AccommodationsWe hire talented people from a wide range of backgrounds. If you’re excited about this role but don’t meet every bullet, we still encourage you to apply. Notion is an equal opportunity employer and does not discriminate on the basis of any legally protected characteristic. Consistent with applicable law, we will consider for employment qualified applicants with arrest and conviction records. Notion provides reasonable accommodations during the application process; if you need one, please let your recruiter know.Notion is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic. Notion considers qualified applicants with criminal histories, consistent with applicable federal, state and local law. Notion is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, please let your recruiter know.LocationSan Francisco, CaliforniaEmployment TypeFull timeLocation TypeHybridDepartmentFinance
- Okta in San Francisco is seeking a Senior IT Internal Auditor to lead technology, cybersecurity, and AI-related audits on an agile team. You will guide audit scope, test controls, and document evidence with minimal supervision. You will mentor junior auditors, apply data...Risk
- ...Rothschild LLP is seeking an IS Project Manager to lead and execute technology projects, coordinating scope, risk, and schedule across the program. You will work with... .... Essential experience includes 5 years in IT and 5 years in project management, with #J-18808-Ljbffr...Risk
- Column is seeking a seasoned IT risk/audit leader to own the end-to-end audit lifecycle in a software company that operates a regulated bank. You will partner with Engineering, Information Security, BSA/AML, and Compliance teams to drive risk-informed audits and governance...RiskWork at office
- PwC in San Francisco is seeking a Senior Manager for Digital Assurance and Transparency to lead large projects, oversee IT controls, and guide clients through governance and risk management. You will manage financial reporting and IT risks, collaborate with senior clients...Risk
- Column is seeking a seasoned audit professional to own and run end-to-end audits focused on IT risk, cybersecurity, and fintech governance. You will collaborate closely... ...'s software-driven banking model. You will lead risk assessment, planning, fieldwork, reporting,...Risk
$150k - $205k
...San Francisco seeks an Assurance Senior Manager for Technology Risk Assurance. In this role, you will lead audit teams, ensuring adherence to established standards... ...ideal candidate has over eight years of experience in IT audit and relevant certifications like CPA or CISA....Risk$191.2k - $286.8k
About the RoleThe Technology Risk Manager is a senior individual contributor... ..., infrastructure, and IT. You’ll act as the primary owner... ...experience in technology risk, IT audit, cybersecurity, or... ...track record as a senior IC leading complex, cross-functional risk...RiskWork at officeLocal areaRemote workWorldwide3 days per week- Perplexity is seeking a governance, risk, and compliance analyst to shape and lead our program. You will drive... ...regulatory alignment and scalable audit processes. Join a fast-growing startup... ...cross-functional collaboration across IT, Security, GTM, and Engineering in...Risk
- ..., let's talk. As a Senior IT Internal Auditor, you will serve as a technical lead and subject matter resource... ...operating across complex, technology, cybersecurity, and AI-related audit engagements. Reporting to... ...within the company's broader risk and governance landscape,...Risk
$170k - $190k
About the TeamOur Internal Audit team plays a strategic... ...the business navigate risk while enabling growth and... ...meaningful improvements across technology, finance, operations,... ...Audit, you will lead our Technology Risk & Assurance... ...oversight of our global IT SOX program and risk-...RiskH1bWork at officeLocal areaRemote workHome officeRelocation packageMonday to Thursday- ...Senior Manager | San Francisco (Hybrid)I'm partnering with a leading global consulting firm to identify a Senior Manager for its... ...San Francisco practice.If you're currently in Big 4 IT Audit, Technology Risk, Internal Audit, SOX, or IT Controls and are looking for broader...Risk
- ...legacy systems with AI-native technology that automates 90% of the manual... ...founded by a team of Banking IT experts and AI researchers... ...What you'll do As an Engagement Lead, you will translate ambitious... ...outcomes, expansion strategy, and risk management. You'll own the...Risk
- Perplexity is seeking a Governance, Risk & Compliance Analyst to shape... ...management program. You will lead the implementation of... ...regulations, and build scalable audit systems in a fast‑growing startup... ...using AI, and collaboration across IT, Security, GTM, and Engineering...Risk
$186.1k - $300.55k
....What you'll doWe are hiring a Lead Product Manager to lead Finance... ...design, financial controls, and audit readinessDefine, prioritize,... ...communicate progress, trade-offs, risks, and decisions to executive... ...: US-CA-San FranciscoCategory: IT Infrastructure & OperationsPosition...RiskContract workWork at officeLocal areaRemote work2 days per week$72k - $184.44k
...OpportunityAs a Digital Assurance & Transparency - IT Audit Senior Associate, you will focus on... ...their stakeholders build trust in their technology while complying with relevant... ...regulations, including assessing governance and risk management processes and related...RiskFull timeH1b$201.37k - $236.9k
...seeking a Senior Manager for Internal IT & Security Audit to lead their global audit program. This role... ...across various regions, enhancing risk management. With a minimum of 12 years... ...initiatives that incorporate cutting-edge technology. The base salary ranges from $201,365...RiskRemote job$77k - $202k
...OpportunityAs a SAP Business Process & IT Controls Sr Associate, you... ...consulting. Within our Technology Consulting practice, you will... ...pivotal in helping clients mitigate risks and protect sensitive data.As... ...- Conducting compliance audits and reviews to maintain adherence...RiskFull timeH1b$133k
...integrity. Our Financial Risk Management (FRM)... ...greater. As an AI Governance Lead on this team, you will... ...at the cutting edge of technological advancement, Uber is committed... ...in a repeatable, audit-ready format that... ...relevant experience in IT audit, internal audit,...RiskFull timeWork experience placementWork at officeRemote work$180k - $230k
...seeking an Incident & Crisis Management Lead to join Anthropic's Global Safety,... ...While this role does not directly manage technology incidents (such as IT outages, disaster recovery, or... ...operations and advise leadership on emerging risks Support broader enterprise...RiskFlexible hoursNight shiftAfternoon shift$2,000 per month
...Column For companies building financial technology and transforming the financial services space... ...with Solutions Engineering, Legal, Risk, and Compliance to structure solutions that... ...you’re building pipeline, not waiting for it. Team & Playbook Building Contribute to the...RiskWork at officeRemote workFlexible hours$249.6k - $312k
...TeamDoorDash’s Internal Audit team provides independent... ...that the company’s risk management, governance,... ..., regulatory, security, IT, and more. About the RoleWe... ...Director, IT Internal Audit to lead the strategy, execution... ...you will help shape the technology risk management...RiskHourly payWork at officeLocal areaRemote workFlexible hours- GSPANN Technologies, Inc. is seeking an accomplished Project Manager to lead the migration of applications as part of an acquisition integration... ...stakeholder engagement, manage risks, and coordinate cross-functional teams across IT leadership, application administrators...Risk
$150k - $205k
Job Summary The Assurance Senior Manager, Technology Risk Assurance is responsible for acting as an IT audit technical resource to clients and internal stakeholders... ...process. In this role, the Assurance Senior Manager leads teams in planning and performing IT risk and...RiskWork at office- Peregrine Technologies seeks a Procurement Manager to become our first in-house buyer, handling software/IT, marketing, travel, and services. You will own vendor negotiations, renewals... ...while balancing business needs and risk with Security and Legal. You will collaborate...Risk
$126.64k - $210.91k
...career, KPMG provides audit, tax and advisory services... ...seeking a Manager, IT Internal Audit to join... ...areas such as, Information Technology (IT) strategy and... ...DevOps controls against leading practice, industry, or... ..., and implement new IT risk and control frameworks,...RiskH1bLocal area$128.1k - $239.6k
...a better working world. EY Technology: Technology has always been... ...responds and mitigates cyber-risk, protecting EY and client data... ...system owners, custodians, and IT stakeholders to facilitate security... ...response or penetration audits. What we offer you The...RiskSummer holidayLocal areaRemote workFlexible hoursNight shiftWeekend work$180k - $202.5k
...playing games. the company's Internal Audit team exists to demonstrate effective risk management, process optimization,... ...control environment. This Technology Risk Audit Manager role owns the... ...Internal Audit. What You'll Be Doing Lead IT SOX/ITGC strategy and continuous...RiskFull timeFor contractorsWork at officeWorldwideRelocationRelocation package2 days per week1 day per week- ...able to interact with naturally. It will help people in their real... ...rapidly to develop technology for its next stage. This presents... ...seeking a hands‑on Evaluation Lead to build and assess model performance... ...model weaknesses or risks, and tracking competitive industry...Risk
- ...excellence, human resources, and technology infrastructure. The CFIO... ..., ensuring compliance and risk management, and overseeing... ...executive role involves leading teams across finance, HR, IT, and internal operations... ..., compliance, and audit coordination, as well as strong...Risk
$124.9k - $229.1k
...change. And with change comes risk. As a Risk Technology professional, you will be... ...controls monitoring, and IT risk management. You will belong... .... Since EY is a global leading service provider in this... ...Foundational understanding of auditing and assessing Oracle...RiskWork experience placementSummer holidayFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead, IT Audit and Technology Risk. Be the first to apply!
- risk adjustment San Francisco, CA
- technology risk San Francisco, CA
- risk assurance San Francisco, CA
- high risk San Francisco, CA
- risk underwriter San Francisco, CA
- antepartum high risk ob nurse San Francisco, CA
- geopolitical risk San Francisco, CA
- risk intern San Francisco, CA
- at risk youth San Francisco, CA
- risk San Francisco, CA

