IT Audit Manager
GitLab
Job Overview
Who's the hiring manager?
Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Job Description
An Overview Of This Role
As an IT Audit Manager, you'll build and lead an IT audit function that helps GitLab teams ship quickly while staying secure and compliant. You'll connect fast-moving engineering, IT operations, and security teams with a practical control environment that supports how modern systems actually run, across multi-cloud infrastructure, AI and machine learning systems, and DevSecOps practices. You'll own end-to-end IT SOX program execution, design and test IT general controls and application controls, and use data analytics, automation, and GenAI tools to make audits more efficient, continuous, and insightful. Instead of handing off findings and walking away, you'll partner directly with leadership to turn those insights into concrete improvements in areas like cloud security, access management, and financial statement processes, positioning IT audit as a trusted advisor and strategic partner in GitLab's growth.
What You’ll Do
- Lead end-to-end IT audits covering SOX compliance, multi-cloud infrastructure (AWS, Azure, GCP), AI/ML systems, and application controls in complex environments.
- Design and execute testing of IT general controls, application controls, and entity-level controls, turning findings into clear, actionable improvements for technology and business teams.
- Manage the IT SOX program from planning through reporting, including risk-based scoping, coordination of co-source providers, documentation of risk and controls, and tracking of remediation efforts.
- Collaborate with engineering, IT operations, security, and business process owners to assess emerging risks, review new system implementations, and advise on practical, effective control designs.
- Drive audit innovation by using data analytics, automation, and GenAI tools to streamline procedures, implement continuous monitoring, and enhance audit quality and insight.
- Conduct walkthroughs and control evaluations across key financial statement processes (record to report, order to cash, hire to retire, procure to pay) and review SOC 1/SOC 2 reports for third-party vendors.
- Prepare clear, concise audit reports that explain issues, business impacts, and prioritized recommendations to senior leadership and other stakeholders.
- Mentor junior auditors and contribute to the evolution of IT audit methodologies, with a focus on emerging technologies, cybersecurity controls, and segregation of duties.
What You’ll Bring
- Experience leading end-to-end IT audit and SOX compliance programs in complex, fast-changing technology environments, including planning, fieldwork, reporting, and follow-up.
- Applied knowledge of IT general controls, application controls, entity-level controls, and key financial statement cycles (record-to-report, order-to-cash, hire-to-retire, procure-to-pay).
- Working knowledge of IT control and security frameworks (such as COBIT, NIST, ITIL, ISO 27001 and COSO) and how to interpret and apply them across cloud, on-premises, and hybrid environments.
- Hands-on familiarity with cloud platforms (for example AWS, Azure, GCP), cybersecurity concepts (network security, encryption, identity and access management, vulnerability management), and modern development practices (Agile, DevOps, or DevSecOps).
- Experience using data analytics, automation, and audit tools to design and execute testing, perform continuous monitoring, and improve audit quality and efficiency.
- Ability to translate technical risks and control issues into clear, actionable recommendations for business and technical stakeholders, including creating concise, executive-ready reports.
- Experience mentoring or guiding junior team members, collaborating with cross-functional partners, and managing multiple concurrent engagements with a self-directed, service-oriented approach.
- Bachelor's degree in Accounting, Information Technology, Computer Science, Finance, or a related field, and at least one relevant professional certification (for example CPA, CIA, CISA, CISSP, CISM, CRISC, or equivalent); candidates with transferable skills or adjacent backgrounds are encouraged to apply.
About The Team
We are responsible for assessing technology risk and strengthening controls across GitLab's AI-powered DevSecOps platform and internal systems. As a distributed, cross-functional group, we partner closely with engineering, IT operations, security, and business process owners to design and validate IT general controls, application controls, and cloud security controls that are practical in fast-moving, multi-cloud and AI/ML environments. We work asynchronously across regions, using data analytics, automation, and modern development practices to make audits more efficient and insight-driven. Our current priorities include maturing the IT SOX program, embedding control considerations into new system implementations, and positioning IT audit as a strategic advisor that supports secure, compliant, and scalable growth.
Key skills/competency
- IT Audit
- SOX Compliance
- Cloud Security
- Risk Management
- Data Analytics
- Automation
- GenAI Tools
- NIST/ISO 27001
- Access Management
- Financial Controls
How to Get Hired at GitLab
- Research GitLab's culture: Study their mission, values, recent news, and employee testimonials on LinkedIn and Glassdoor, focusing on their remote-first and AI-driven approach.
- Tailor your resume: Highlight extensive experience with IT SOX, multi-cloud platforms (AWS, Azure, GCP), DevSecOps, and applying data analytics/GenAI in audit contexts.
- Showcase technical auditing expertise: Be ready to discuss your in-depth knowledge of IT general controls, application controls, cybersecurity frameworks (NIST, ISO 27001), and cloud security concepts.
- Demonstrate leadership and strategic partnership: Prepare examples of how you've led audit programs, mentored junior team members, and acted as a trusted advisor to technical and business stakeholders.
- Understand the DevSecOps platform: Familiarize yourself with GitLab's product and how security and compliance are integrated into the software development lifecycle.
Frequently Asked Questions
Find answers to common questions about this job opportunity
Explore similar opportunities that match your background