Description
We are looking for an experienced IT Auditor to join a 100% remote, Long-term Contract opportunity supporting complex technology audit initiatives.
This role focuses on reviewing cloud environments, cybersecurity safeguards, service reliability practices, and governance models for AI-driven capabilities.
The ideal candidate brings a blend of audit judgment and technical depth to assess how modern platforms are built, protected, and operated.
You will work closely with cross-functional teams to highlight risk exposures, strengthen control design, and provide practical recommendations for improvement.
Responsibilities
- Plan and carry out audits across cloud infrastructure, cybersecurity domains, and enterprise technology risk areas.
- Examine security measures within cloud platforms, including access controls, infrastructure protections, and governance practices that support day-to-day operations.
- Review software delivery pipelines, release procedures, and engineering checkpoints to confirm that development and deployment activities follow established control standards.
- Assess DevSecOps practices, vulnerability remediation workflows, and software supply chain protections to identify gaps that could affect platform security.
- Evaluate credential handling, secrets storage approaches, and key management configurations, including the effectiveness of rotation and access restrictions.
- Analyze service reliability and operational quality disciplines such as monitoring, resiliency testing, error management, and production health oversight.
- Review incident response processes, observability capabilities, and service telemetry used to detect, investigate, and resolve issues in live environments.
- Examine governance structures for AI-enabled solutions, including model oversight, lifecycle controls, and risk management practices related to responsible use of AI.
- Partner with engineering, security, data, and governance stakeholders to communicate findings, recommend corrective actions, and support stronger control maturity.
Requirements
- At least 5 years of experience in technology auditing, cybersecurity, cloud engineering, DevOps, platform engineering, or a closely related field.
- Strong understanding of cloud security principles, cybersecurity frameworks, identity and access management, and Azure-based services.
- Experience assessing CI/CD pipelines and secure software development or release management practices.
- Familiarity with tools and concepts such as Azure DevOps, GitHub Actions, infrastructure as code, vulnerability management, and secrets management.
- Knowledge of operational quality, production reliability, and service monitoring practices within large-scale technology environments.
- Ability to interpret complex technical issues and turn them into clear audit observations, risk statements, and executive-ready recommendations.
- Working knowledge of audit and control concepts such as IT audit programs, audit findings, and COBIT.
- Preferred credentials may include Azure security or DevOps certifications, cloud architecture certifications, AI governance certifications, or other relevant audit and security qualifications.
Technology Doesn't Change the World, People Do.