
IT Audit Contractor, SOX IT & Application Controls
Overview
You will execute the SOX compliance program for a fast-paced Internal Audit organization in Palo Alto. Handle IT General Controls (ITGC), IT Application Controls (ITAC), Key Report Testing, and SOC 1 reviews across the audit lifecycle. Collaborate with control owners, external auditors, and IT teams to drive audit readiness and remediation. This contract role offers a direct impact on audit quality with a hybrid schedule (2 days onsite).
What You'll Do9
- 1Execute ITGC and ITAC testing procedures for in-scope applications, databases, and operating systems.
- 2Perform Key Report Testing to validate data completeness and accuracy for financial reporting.
- 3Review SOC 1 reports and map user controls to support SOX reliance.
- 4Document audit evidence and findings in workpapers with clear, concise narratives.
- 5Drive walkthroughs with control owners to assess design and implementation of controls.
- 6Coordinate with external auditors to align testing approach and ensure coverage.
- 7Identify control gaps and recommend practical remediation actions.
- 8Track audit issues and validate remediation plans through to closure.
- 9Support the annual risk assessment and scoping for IT systems and processes.
Requirements7
- 13+ years in IT audit or SOX compliance, focusing on ITGC, ITAC, and SOC 1 reviews.
- 2Hands-on experience with Key Report Testing and data analytics.
- 3Strong knowledge of COBIT and COSO frameworks.
- 4Experience with AuditBoard or similar audit management tools.
- 5Bachelor's degree in Information Systems, Accounting, or related field.
- 6Professional certification preferred: CISA, CISM, CIA, or CPA.
- 7Ability to work hybrid (2 days onsite) in Palo Alto, CA.
Salary Insight
Salary not disclosed in listing
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.
WithumSmith+Brown
VerifiedIT SOX Senior Consultant
WithumSmith+Brown seeks an experienced IT SOX Senior Consultant to lead Risk Advisory growth. This hybrid role involves leading audits across multiple locations and driving improvements in internal controls.

Innovative Information Technologies, Inc
VerifiedSenior Internal Auditor, SOX & Public Accounting
You will own the internal audit plan for a $500M technology company, reporting directly to the Audit Director. You will lead audits across SOX, ITGC, and operational processes, partnering with finance and engineering teams. You will work in a hybrid model from Calabasas, CA, with 3 days onsite. This role offers direct exposure to executive leadership and a clear path to Audit Manager.

Mercor
VerifiedAudit & Controls Specialist (External / Internal SOX) | $80-$120/hr Remote
This is a remote, hourly contract role with Mercor, supporting a leading AI lab. You'll turn your real-world audit and controls experience into structured training data that helps AI reason like a seasoned auditor. If you've worked in external audit, internal audit, or SOX compliance, you'll design realistic scenarios, review AI outputs, and provide written feedback to sharpen the model's professional judgment. It's a unique way to apply your expertise without traditional client engagements.
Beacon Staffing
VerifiedIT Risk and Compliance Analyst - Beacon Staffing
Lead ownership of IT governance and compliance initiatives at Beacon Staffing. Own development of controls and drive continuous monitoring. Impact visibility across 2-3 days weekly onsite. Differentiate through expertise in SOX and COSO frameworks.
KBR
VerifiedIT Audit Manager KBR Houston Texas
The IT Audit Manager at KBR leads IT Sarbanes-Oxley compliance programs for a global organization. This role oversees ITGCs application controls automated controls interface controls and SDLC controls. It involves partnering with IT leadership and external auditors to ensure compliance with SOX 404 requirements.
LPL Financial Corp
VerifiedAnalyst II Tech Governance & Assurance
We seek a skilled IT Risk & Controls professional to lead our first line of defense in IT compliance. You will own daily readiness testing and audit facilitation for critical programs like SOX SOC 1 SOC 2 CCPA/CPRA cybersecurity audits and NYDFS attestation. This hands-on role embeds within control owners to perform self-testing and drive automation reducing manual effort. Expect collaboration with IT Engineering Security and external auditors to maintain audit readiness year-round.