It Audit Manager

Snowflake Snowflake · Data AI · CA-Menlo Park, United States · Finance

This role is for an IT Auditor at Snowflake, focusing on SOX compliance, cloud infrastructure audits, automated assurance using tools like Python and AI coding tools, product security audits, and compliance reviews. The role involves assessing IT control deficiencies, acting as a consultant for product teams on compliant-by-design systems, and participating in risk assessments. While the company is powering the 'agentic enterprise' and encourages AI adoption, the core function of this role is IT auditing and compliance, not direct AI/ML model development.

What you'd actually do

  1. Execute and support our IT internal controls assessments, other IT audits and investigations.
  2. Lead audits of cloud infrastructure (AWS, Azure, GCP) focusing on identity and access management (IAM), encryption, and network security configurations rather than just general IT controls
  3. Design and implement automated, data-driven audit procedures using SQL, Python, or AI coding tools like Cortex Code (in Snowflake) move toward real-time monitoring of security compliance.
  4. Partner with Engineering and Product teams to audit secure software development lifecycles (SDLC) and CI/CD pipeline security.
  5. Conduct internal compliance review, ensuring adherence to frameworks like ISO 27001, ISO 42001, ISO 22301, or ISO 27017.

Skills

Required

  • IT internal controls assessments
  • cloud infrastructure auditing (AWS, Azure, GCP)
  • identity and access management (IAM)
  • encryption
  • network security configurations
  • automated audit procedures
  • SQL
  • Python
  • secure software development lifecycles (SDLC)
  • CI/CD pipeline security
  • compliance frameworks (ISO 27001, ISO 42001, ISO 22301, ISO 27017)
  • documentation review
  • risk assessment
  • audit program design
  • SOX compliance
  • COSO principles
  • data interpretation
  • data-driven audit/analytics approach
  • problem-solving
  • collaboration
  • attention to detail
  • managing multiple projects

Nice to have

  • AI coding tools like Cortex Code
  • Salesforce auditing
  • Workday Financials auditing
  • Java readability
  • AWS certifications
  • Azure certifications
  • Google Cloud certifications

What the JD emphasized

  • SOX compliance
  • cloud infrastructure
  • automated, data-driven audit procedures
  • secure software development lifecycles (SDLC)
  • compliance review
  • IT control deficiencies
  • compliant-by-design systems
  • risk assessments
  • end-to-end IT SOX program