Senior Analyst - Internal Audit & Risk

Spotify Spotify · Consumer · New York, NY +1 · Finance Strategy, Operations & Risk

Senior Analyst for Internal Audit & Risk at Spotify, focusing on implementing audit strategy across the product lifecycle. The role involves building tools with AI agents, supporting SOX compliance, and conducting assurance/advisory projects in technology and product areas. Requires an engineering background, understanding of AI systems, and experience with AI coding assistants.

What you'd actually do

  1. Test technology components within the SOX framework, including planning, executing walkthroughs, reporting, and driving continuous improvements such as control rationalization.
  2. Design, build, and iterate on internal audit & risk tooling and systems using AI agents, leveraging modern cloud-native architectures and generative AI models to drive execution.
  3. Champion technology-enabled audit execution by embedding AI directly into core audit processes to deliver deeper, more effective results.
  4. Develop a deep understanding of the businesses, products, and processes you are auditing, including their strategy, product lifecycle, and associated business processes.
  5. Participate in complex assurance and advisory projects, covering risk assessment, testing, and reporting across various technical domains.

Skills

Required

  • at least 3 years of work experience
  • engineering role or similar
  • solid understanding of modern software development lifecycles (SDLC)
  • programming languages for AI development (Python)
  • cloud infrastructure
  • strong problem-solving skills
  • critical and logical thinking

Nice to have

  • Experience in technology audit
  • IT consulting
  • IT risk management
  • AI powered coding assistants such as Claude Code or Cursor
  • Professional certifications (e.g., CISA, CISSP, CIA)

What the JD emphasized

  • building AI systems
  • AI agents

Other signals

  • building tools leveraging AI agents
  • supporting the company's annual SOX compliance program
  • assurance and advisory projects across technology and product areas