Lead Specialist, Internal Audit, Controls, Compliance, Risk

Job Description:

  • Lead the response across the internal audit lifecycle, including planning, fieldwork coordination, and reviewing draft observations, root causes, and risks
  • Challenge observation and management action plan ownership, wording, and feasibility
  • Draft and submit audit-closure proposals with stakeholder alignment
  • Own SOC 2 Type 1 and Type 2 coordination, including planning and bringing additional platforms into scope
  • Review evidence and return weak submissions for rework
  • Work with partner teams to assign resources, address gaps, and close them
  • Set standards for evidence, attestation, and documentation across services
  • Translate findings into structured remediation plans with owners, due dates, and evidence requirements
  • Maintain the audit-action tracker and hold action owners accountable
  • Coordinate audit actions owned by other teams and track them to closure
  • Govern the CMDB for audit scope, keeping ownership and classification accurate
  • Own the risk register, including quality, ownership, write-ups, closure, and escalation of risks beyond tolerance
  • Convert access-review and vulnerability gaps into formal risks or audit actions where appropriate
  • Govern the business continuity and disaster recovery program, including impact analyses, coverage and gaps, vendor continuity, annual reviews, tabletop exercises, and executive attestation
  • Partner with internal audit, cybersecurity, privacy, risk, and legal to close findings and prevent repeat observations
  • Prepare audit and GRC status updates for monthly operations reviews
  • Advise service owners and coach peers on governance expectations as an objective assurance partner

Requirements:

  • 5 or more years in internal audit, controls, compliance, or risk; IT audit or GRC strongly preferred
  • Hands-on coordination of SOC 2 or SOX programs, including evidence and attestation management
  • Demonstrated ownership of a risk register and the risk-management lifecycle
  • Experience governing or supporting business continuity and disaster recovery, including impact analyses, plans, tabletops, and attestation
  • A professional qualification is expected or strongly preferred, such as CISA, CIA, CRISC, ACA/ACCA, or CISSP
  • Proven ability to challenge peers and leaders and represent the organization to external auditors
  • Experience in EdTech, SaaS, regulated, or highly distributed environments is a plus
  • Familiarity with NIST CSF or ISO 22301 is a plus
  • Bachelor's degree in a relevant field
  • Advanced degree is a plus
  • Ability to work independently and objectively with professional skepticism and integrity
  • Ability to influence peers and leaders without formal authority
  • Ability to collaborate across security, engineering, privacy, legal, internal audit, and service-owner teams

Benefits:

  • Equal opportunity employer committed to diversity and an inclusive environment
Back to blog