Lead, It Audit and Technology Risk

Notion Notion · Enterprise · San Francisco, CA · Finance

This role is for a Lead, IT Audit and Technology Risk at Notion, a company building a collaborative AI workspace. The position focuses on establishing and elevating the technology controls program, including IT SOX compliance, operational IT audits, and embedding AI and automation into control testing and monitoring. The role requires a strategic and technically fluent individual to partner with various departments and ensure sound technology controls in a fast-moving SaaS environment.

What you'd actually do

  1. Own the full IT SOX lifecycle — scoping, risk assessment, documentation, walkthroughs, testing, deficiency evaluation, remediation, and reporting — driving automation and efficiency across IT general controls (ITGCs) and IT application controls (ITACs)
  2. Design, operate, and continuously improve technology controls spanning user access and segregation of duties, change management, SDLC and CI/CD pipelines, interfaces, data flows, and system-generated reports
  3. Design and execute value-added operational IT and cybersecurity audits — across cloud infrastructure, security operations, identity and access management, data protection and privacy, disaster recovery and resilience, and vendor and third-party risk — while driving enterprise-level technology risk assessment that anticipates emerging risks before they materialize
  4. Serve as a strategic advisor on cross-functional initiatives (product launches, new systems, architecture changes, M&A) and as the primary point of contact for external auditors, ensuring sound controls are built in from day one and audit evidence is complete, clear, and timely
  5. Own IT control deficiencies from identification through sustained remediation while partnering with and educating system owners to build a culture of ownership and accountability

Skills

Required

  • 12+ years of progressive IT audit, IT SOX, or technology risk experience
  • Deep, hands-on ownership of IT SOX/ITGC programs
  • Demonstrated experience designing and leading operational IT audits end to end
  • Strong cybersecurity audit experience
  • Software or SaaS industry experience
  • Process leadership
  • Bachelor's degree in Information Systems, Computer Science, Accounting, or a related field
  • CISA, CISSP, CISM, CIA, CPA, or equivalent certification required
  • Strong stakeholder management and communication skills

Nice to have

  • Big 4 and high-growth technology company experience
  • modern cloud-based technology stacks (AWS, GCP, Azure)
  • software development lifecycles
  • complex data flows
  • cloud security configurations
  • identity and access management
  • change management
  • DevOps and CI/CD pipelines
  • enterprise IT operations risks and controls

What the JD emphasized

  • Own the full IT SOX lifecycle
  • Design and execute value-added operational IT and cybersecurity audits
  • Own IT control deficiencies
  • Champion the adoption of AI and modern tooling