Senior Technology Auditor

Gap

Gap

IT
Folsom, CA, USA
Posted on Aug 15, 2025

About the Role

We are seeking a highly motivated IT Audit Senior to join our Internal Audit team in the retail industry. This role is ideal for a detail-oriented professional with a strong background in IT operational audits and a passion for improving IT governance, risk, and control environments. The ideal candidate will have 3–4 years of relevant experience and a solid understanding of Technical Audits. This role is based in the San Francisco Office.

What You'll Do

  • Execute IT operational audits, including planning, fieldwork, testing, reporting, and facilitating meetings with stakeholders.

  • Evaluate the design and effectiveness of IT controls across infrastructure, applications, and data environments.

  • Identify control gaps and recommend practical, risk-based solutions.

  • Collaborate with IT, Security, and Compliance teams to assess risks and improve control frameworks.

  • Prepare clear, concise audit documentation and communicate findings to stakeholders.

  • Assist in the development and enhancement of audit methodologies and tools.

  • Use data analytics to enhance effectiveness and efficiency of audit projects and to identify improvement opportunities

  • Organize, prepare and present proposals, analyses, and other strategic and value add projects

  • Use advanced communication skills to exchange complex information

  • Manage projects and program execution within area of specialty and ensures quality of work

Who You Are

Required:

  • 3-4 years of experience in IT auditing, risk management, or information security.

  • Understanding of networks, servers, databases, cloud platforms (e.g., AWS, Azure), and endpoint systems.

  • Familiarity with security frameworks (e.g., NIST, ISO 27001), access controls, encryption, vulnerability management, and incident response.

  • Familiarity with compliance and related testing procedures.

  • Excellent analytical, communication, and project management skills.

Nice to Have:

  • Professional certifications such as CSX-P, CISA, CRISC, or CISSP.

  • Experience with audit tools and GRC platforms.