Senior Internal It Auditor

PagerDuty PagerDuty · Enterprise · Lisbon, Portugal · Internal Audit

This role is for a Senior Internal IT Auditor at PagerDuty, focusing on IT General Controls (ITGCs), Business Process Controls, and SOX compliance within a SaaS environment. A key aspect is evaluating the impact of emerging technologies like AI and machine learning on the corporate risk landscape and control environment, particularly within the Finance function. The role involves analyzing automated workflows, system integrations, and data pipelines, and translating technical processes into audit-ready documentation. While the company uses AI/ML, this role is not building AI models but rather auditing the controls and risks associated with their integration into business processes.

What you'd actually do

  1. Execute end-to-end testing for both IT General Controls (ITGCs) and Business Process Controls. Lead the comprehensive review of SOC 1 (Type 2) reports, ensuring all Complementary User Entity Controls (CUECs) are accurately mapped, aligned, and validated.
  2. Direct the evaluation and testing of complex IT Automated Controls (ITACs) and Key Reports (IPE/IUC). Review application configurations, system logic, and custom code integrations to ensure the accuracy of SaaS revenue recognition metrics and general ledger impacts.
  3. Monitor and assess the deployment of AI, machine learning, and advanced automation within the Finance function. Evaluate how these emerging technologies alter the control environment, identify novel risk vectors, and design appropriate governance frameworks and audit procedures.
  4. Analyze end-to-end automated workflows across the enterprise software ecosystem (e.g., NetSuite, Salesforce, Billing/CPQ engines, and AWS). Scope and mitigate financial and operational risks associated with system integrations, APIs, and data pipelines.
  5. Translate complex technical, data science, and engineering workflows into audit-ready documentation that maps directly to financial, operational, and compliance control objectives.

Skills

Required

  • IT auditing
  • SOX 404 compliance
  • IT General Controls (ITGCs)
  • Business Process Controls
  • SOC 1 (Type 2) report review
  • IT Automated Controls (ITACs)
  • SaaS revenue recognition
  • financial and operational risk assessment
  • process documentation
  • enterprise software ecosystem analysis (NetSuite, Salesforce, Billing/CPQ)
  • API and data pipeline risk mitigation
  • technical documentation
  • modern cloud-first enterprise software architectures
  • corporate data structures

Nice to have

  • Big 4 or large regional public accounting firm experience
  • in-house internal audit experience at a technology or SaaS company
  • CISA, CPA, CIA, or CITP certification

What the JD emphasized

  • AI
  • machine learning
  • automation
  • control environment
  • risk landscape
  • audit procedures
  • financial workflows
  • data flows
  • emerging technologies
  • technical architectures
  • automated workflows
  • system integrations
  • data pipelines
  • technical curiosity
  • financial integrity
  • internal data controls
  • ITACs
  • data completeness and accuracy
  • upstream data integrity
  • enterprise software architectures
  • corporate data structures