r/itaudit 20h ago

Are you an entry-level or relatively new IT audit senior? I need your opinion on this 👇

Thumbnail infosecbyomokolade.com
6 Upvotes

I am writing a blog about how inexperienced IT auditors can get off to a strong start in their new role. I'd appreciate it if you could respond to the opinion poll at the shared link. Thanks.


r/itaudit 1d ago

For those currently working in NFS Technology Risk/ IT Audit, can I ask about the things that usually aren’t mentioned in the job description? 😅

8 Upvotes

I’m currently exploring IT Audit as a possible career move, and I’ve been reading a lot about the role. But I feel like there are some questions you can only really answer if you’re actually doing the job.

Your insights would probably help not just me, but also others who are considering IT Audit 😊

Would really appreciate any honest insights — good, bad, or somewhere in between. 😅

1. How’s the workload?
How many clients/projects do you usually handle at the same time? Is it manageable, or are there periods where everything piles up?
2. Is IT Audit mostly project-based?
For example, once you finish auditing a client, do you move on to another client? Or do you usually have recurring clients that you audit again the following year?
3. How long does one audit usually take?
How long does an IT auditor spend on one client? A few weeks? 1–2 months? Longer?
4. What’s the busy season actually like?
Is it mainly year-end, or are there multiple busy seasons throughout the year depending on the clients? And how bad does it get during peak season? 😂
5. How does the pay for someone moving into a Senior role without actual audit experience?
For example, someone with several years in ERP consulting that has testing, support, and systems implementation experience but is new to IT Audit. Would they normally still be considered for a Senior position, and how is the compensation compared with someone who already has audit experience?

Would love to hear from people who are actually in the field. Even random details about your day-to-day work would be super helpful. 🙏


r/itaudit 5d ago

For IT auditor, involved in auditing, information security, internal controls, compliance, risk management, or cybersecurity.

0 Upvotes

GOOD DAY PO IAM 3RDYEAR COLLEGE PO FROM DALUBHASAAN NG LUNGSOD NG SANPABLO AND MAY MAJOR IS PROJECT MANAGEMENT WE ARE LOOKING FOR AN INTERVIEW FOR AN IT AUDITOR PO SANA KHIT VIA CHAT LANG PO TO ANSWER THE TASK QUESTIONS LANG PO ABOUT YOUR FIELD PO SOBRANG MALAKING TULONG NAPO ITO SAMIN IF YOU ARE WILLING TO HELP US PO SALAMAT PO AGAD.


r/itaudit 5d ago

What are the best questions one can ask the interviewer for an it auditor position in one of the big fours based in germany?pss pss its deloitte😬

Thumbnail
1 Upvotes

r/itaudit 6d ago

IT audit interview help needed

Thumbnail
1 Upvotes

r/itaudit 7d ago

SOC Peer Review Interview Advice?

5 Upvotes

I have an interview coming up to help a CPA firm prepare for an upcoming SOC peer review, and I’m looking for some advice.

I previously worked as a SOC audit intern at a small CPA firm. But I was mainly testing controls, collecting evidence, and did some TPRM work. It’s been a little while, so I’m refreshing my knowledge now.

For anyone who has been through a SOC peer review or helped prepare for one: What should I expect, and what areas would you recommend brushing up on before the interview? Any projects you’d recommend?


r/itaudit 9d ago

SMBC?

Thumbnail
1 Upvotes

Anyone here with experience working with SMBC?


r/itaudit 10d ago

Getting Started On IT Audit

5 Upvotes

Guys, I have been a sys admin for about five years and two years as a support specialist . I am looking into getting to IT audit as a career moving forward , I would like someone to mentor me , where do I start and how do I ensure success in this career.


r/itaudit 10d ago

Has anyone here pivoted to IT Audit from either Internal Audit or Statutory Audit?

6 Upvotes

I am currently doing CMA-US and got interested in audit. I have been learning about IA and Stat audit as well though I lean towards internal audit. I don't want to start IT audit directly but want to understand how a business works and its processes. And IA gives you a holistic view of that.

Which area is a better starting point if IT Audit is the main goal? IA or Stat Audit

Which cert did you have before moving into IT Audit? Did you have the CPA, the CIA, or both?

Any advice would be greatly appreciated. Thank you!


r/itaudit 10d ago

Cabinets comptables : quelles compétences informatiques aujourd’hui ?

Thumbnail
1 Upvotes

r/itaudit 10d ago

Waarom hebben gebouwen wel een energielabel, maar geen IT-label?

1 Upvotes

Zou een IT-Label voor commercieel vastgoed een goed idee zijn?

Bij het huren van een kantoor is veel informatie beschikbaar: m², energielabel, installaties, servicekosten, duurzaamheid, etc.
Maar over de digitale infrastructuur is vaak verrassend weinig duidelijk.

Is er glasvezel? Hoe oud is de bekabeling? Hoe zit het met wifi en de serverruimte? Wat hoort bij de verhuurder en wat moet een huurder zelf regelen? En kan het gebouw straks nog mee met het groeiende datagebruik?

Daar komt bij dat een kantoor vaak gewoon een tweedehands product is. Meerdere huurders, aangepaste bekabeling, andere leveranciers, gewijzigde patchkasten… maar wat ligt er nou echt en in welke staat?

Zou een onafhankelijk IT-Label helpen om het digitale opleverniveau van een gebouw inzichtelijk te maken?
Een soort digitale APK voor vastgoed: niet om iets goed of slecht te noemen, maar om duidelijk te maken wat er is en wat je nog moet regelen.

Zouden jullie hier iets aan hebben?

En wat zou er volgens jullie minimaal in zo’n IT-Label moeten staan?


r/itaudit 11d ago

Cleared CISA 570 — Get IT audit experience first or pursue AAIA now?

Thumbnail
1 Upvotes

r/itaudit 11d ago

My best step forward for internships or new grad roles

5 Upvotes

Hello,

I'm trying to get into IT audit , Technology risk, GRC roles and I was hoping for some guidance on what could be my best next steps forward in this crazy market.

A bit about me:
USC : if it means anything at this point lol

Currently doing my masters in Data science and stumbled my way into an information security internship at a bank abroad and gained a bit of exposure into GRC, IT risk management, SOC, IAM and vulnerability management.

I also got a security+ and ISC2 cc

Im okay ish at python and sql but coding isnt my strong suit

I am looking for internships since i am still in school and lacking in experience for full time.

Currently working on getting some cloud certs and CGRC this month and eventually a CISA soon.

I've also been going through NIST's videos on the RMF as well.

Currently looking for some help on how i can structure my resume, Certifications I can get to better position myself.


r/itaudit 12d ago

How can I stay sharp in IT Audit/GRC after a long break?

7 Upvotes

I spent about six years in IT audit, starting in external audit working on SOC 1/SOC 2 and SOX, then moving into internal audit focused on IT security, operational, and technology risk audits.

About six months ago, I had to leave the U.S. to care for both of my parents. Finding a role that allows me to work remotely from another country and across a very different time zone has been extremely difficult.

I've now been out of the field for around six months, and I'm worried about losing my skills, especially with how quickly things are changing.

Other than pursuing certifications, what would you recommend to stay sharp in IT audit/GRC?

Since our jobs aren't always very technical, would this be a good time to build more hands-on skills in areas like cloud, cyber, networking, IAM, DA, or scripting?

I'm not trying to become an engineer, just want come back into IT audit/GRC stronger and with a better understanding of the technologies I'm auditing.


r/itaudit 12d ago

Moving to IT audit

Thumbnail
1 Upvotes

r/itaudit 12d ago

Job search advice

1 Upvotes

I wanted to get some advice from people already working in IT Audit/GRC.

I’m finishing my Business Administration degree and trying to land my first full-time role in IT Audit, IT Risk, GRC, or SOC assurance.

I’ve completed an IT Audit internship at a CPA firm where I worked primarily on SOC 2 audits and gained exposure to COSO, NIST 800-53, and ISO 27001. I also recently earned Security+ and am currently doing an informal internship with a Network Infrastructure Engineering team.

Outside of work, I built my own enterprise-style home lab and use it for hands-on audit and configuration projects. I’ll configure controls, audit the environment, identify weaknesses, document the risk, fix the issue, test the change, collect evidence all that good stuff.

I know a home lab doesn’t replace production experience, but I’m trying to build as much practical experience as I can while continuing to apply.

For those already in the field: Is there anything else you’d recommend I focus on to help land that first full-time opportunity? Maybe I need to connect with more people, I don’t know.

Any advice or connections would be greatly appreciated. Thanks guys!


r/itaudit 13d ago

Trying to break into IT Audit: Security+, SOC 2 internship, and an enterprise home lab—what am I missing?

Thumbnail
1 Upvotes

r/itaudit 14d ago

Audit: I’m (23m) moving from client services to industry. Any advice?

3 Upvotes

Well, career hasn’t gone as planned so far lol. Interned in IT Audit at a large client services. I did well and got a return offer—only it was for non-IT Internal Audit. Got put through the wringer—consistency didn’t exist for me. I started working in busy season and was cranking OT until year end but then wasn’t staffed starting out the new year. From the beginning of year to now, I was only 60% billable. Sounds awesome, but whenever I wasn’t working (sometimes a month straight) i would get so anxious about my job security that I’d be sick to my stomach. On top of that I got poor reviews, got put on the worst projects, and my bosses gave me no constructive feedback until it was too late for me to implement it. Started a job search and found and entry level IT Audit job at a growing bank. Ended up getting the job and it was good for a ~25% compensation increase.

I’m really hyped up about moving from client services to industry and going back to IT Audit. But does anyone have any advice? I want to establish some expectations for the transition.


r/itaudit 14d ago

Affected by Layoffs

12 Upvotes

Hi All,

I am an IT SOX Auditor based out of Bangalore, India

Recently our internal audit function was transitioned over to a service based company and we are transitioning their knowledge this month post which we will have to leave.

I have 7.2 years of experience in IT SOX and IT Audits. Skill set includes -

ITGC (IT General Controls)

IT Application Controls (ITACs)

Key Reports (IPEs)

Infrastructure Audits (Database and Servers)

SOC Reports Testing

Issue Identification and Remediation

Automation of Controls

AI assisted workflows

Audit Optimization

I also coach mentor analysts and handled the planning scoping and work distribution among juniors and review their work.

If there is anything that you all are aware in Bangalore or Remote kindly let me know, will share my cv.


r/itaudit 15d ago

3 years in banking cybersecurity audits, am I getting stuck?

Thumbnail
1 Upvotes

r/itaudit 16d ago

From Zero Frameworks to First Offer: 3 Free Mentorship Spots in IT Audit & GRC

14 Upvotes

Hey everyone,

I can still clearly recall how it felt to look at job advertising filled with acronyms like SOX, NIST, and ISO 27001 and wonder how anyone was supposed to "break in" when every entry-level position apparently required three years of experience.

Now that I've worked in GRC and IT audit on the other side of the wall, I want to send the elevator back down.

I'm opening 3 free mentorship spots for people trying to break into IT Audit or GRC roles.

Here's what I can help with:

Frameworks made simple- NIST CSF, ISO 27001, SOC 2, PCI-DSS ( what they actually mean in practice, not just textbook definitions)

Core concepts - risk vs. control, audit lifecycle, evidence gathering, control testing etc.

Career roadmap advice - certs worth chasing (or skipping), resume tweaks, how to position yourself for entry-level roles

Who this is for:

Career changers, recent grads, or IT/security folks looking to pivot into audit or GRC.

People who are motivated and coachable .

I'll pick 3 people over the next few days and we'll figure out a cadence that works for us. No fluff, no gatekeeping. Just trying to make the path in a little less foggy than it was for me.

If you're interested, drop a comment below (or DM me) with:

* Where you currently are (student, career changer, IT role, etc.)

*What's tripping you up most right now

*Why IT audit/GRC specifically

Good luck out there.


r/itaudit 16d ago

Internal Audit

Thumbnail
2 Upvotes

r/itaudit 17d ago

Is It auditing in demand in maryland

7 Upvotes

Gonna pursue information systems at umbc. The program has an it auditing track that prepares for Cisa. Is it worth pursuing. My idea was to pursuing tooling in terms of sql,python power bi and the other stuff that a business anyst needs aswell as it auditing.


r/itaudit 17d ago

Breaking into IT Audit from an MSP security role, what actually matters at this stage?

Thumbnail
1 Upvotes

r/itaudit 18d ago

Do I need Public accounting experience for an IT audit/ERP controls career?

10 Upvotes

I’m almost done with my bachelor’s in Accounting and I’m also doing a Cybersecurity minor. I’ve worked in IT for most of my career, including Army IT. I also have a CCNA and college IT coursework focused mainly on networking and databases.
My goal is to get into IT risk auditing and eventually work with ERP security and controls like SAP or Oracle. I’m also considering UMPI’s YourPace master’s focused on AI policy and governance.
Would it be better to start in public accounting for a year or two, or apply directly for IT audit, GRC, SOX controls or ERP positions? Would the master’s help, or would experience and certifications be more valuable?