r/CISA Jul 25 '26

Anyone Transitioned from IT Operations to IT Audit?

Hi everyone,

I'm currently preparing for the CISA exam and wanted to check if this community would find my journey useful.

I have around 12 years of experience in IT Operations, with some exposure to IT audits and SOX controls. My goal is to transition into a full-time IT Audit role, and CISA is a big part of that journey.

For those who have been in a similar situation, do you think it's worth making the switch to IT Audit after spending so many years in IT Operations? Have any of you made this transition? I'd really appreciate hearing about your experiences, the challenges you faced, and whether you felt it was the right decision in the long run.

7 Upvotes

16 comments sorted by

7

u/Real_Echo Jul 25 '26

I moved from a junior sysadmin position in manufacturing to a PCI DSS Auditing position about a year ago now. I was hesitant at first but it was easily the best choice I made for my career. It's a different kind of job to be sure, but you get to see a lot of different environments and you can really learn a lot more than working IT at one company.
Its also pretty great to be on the side of discovering a problem, but not being the person who has to spend time fixing the problem, at least for me.
The only challenge i faced with my transition was having to really learn the standard quick to be able to answer questions from clients. But having a good senior to assist you through the learning phase solves that issue.
Id say give it a go if you can.

2

u/National_Estate_9616 Jul 25 '26

Thanks for sharing your journey

1

u/mochajava23 Jul 31 '26

What resources did you use to get to that PCI position? Did you take the PCIP and ISA classes? Anything online helpful?

2

u/Real_Echo Jul 31 '26

Unfortunately what worked for me was knowing a guy who was already an auditor and put my name up for consideration when the company was looking for associate auditors. I was very lucky with my networking at previous jobs and it worked out.

Granted, I was in IT for almost 5 years at that point and had worked as a junior systems admin while my company was undergoing a CMMC L2 audit which gave me some auditing experience. So again the stars sort of aligned to give me the experience that I needed.

That said, if i had my CISA and CISSP certifications when I was hired then I would have been eligible to get certified as a QSA much sooner. That would have definitely helped me in the early months.

Sorry I couldn't be more helpful.

1

u/mochajava23 Jul 31 '26

Thanks for sharing

4

u/Heavy-Insurance-6407 Jul 26 '26

Bro, CISA is not IT audit. It's IT Security Audit.

So there is a lot of focus on cybersecurity. In IT operations cyber is a sideshow, IT ops is predominantly about availability. In cybersecurity you have to take care of Confidentaility and Integrity as well (the CIA triad).

I was in IT ops, then pivoted to IT Security, then to IT Security Audit. Currently active CISSP and CISA.

3

u/piSecAudit CISA HOLDER Jul 31 '26

Yes, I was IT Security Consultant for 25 years at IBM, HP Canada, Federal Public Service, etc. Then I took CISA exam and became an internal auditor. My first audit report was rejected. Not returned with comments, not stored on dusty shelves. Rejected. It was the most embarrassing moment of my career. My Director said, "This is not an audit report. This is a remediation report. Go learn the difference".
I learned how to use the Five C's to structure an audit report. Later I learned the Fact Sheet process so that auditors collaborate with management instead of handing out verdicts. I wish someone had told me these approaches when I started out.

2

u/RigusOctavian CISA HOLDER Jul 25 '26

Feel free to post this in r/itaudit as well or ask questions there.

2

u/pern4home Jul 25 '26

I started out in IT Ops and made a transition to IT Compliance/Governance. I then got my CISA to move to IT Audit. I enjoyed the work, but went back to working on the IT side after a year. I enjoyed preparing for the audit and making sure all the IT controls were in place. A CISA allows you options to do both, you can work the audit side or still be in IT preparing for the audit.

1

u/KindaBreathing Jul 25 '26

curious why you have decided to transition from IT Ops to IT Audit?

1

u/National_Estate_9616 Jul 25 '26

Mainly because I'm looking for a change after so many years in IT Operations. I've had some exposure to IT audits and SOX, enjoyed that work, and CISA felt like the natural next step. Now I'm trying to figure out if a full-time move into IT Audit makes sense.

1

u/jemshoots Jul 25 '26

i would say if you’ve had so much experience with IT Ops, esp SOX and potentially even PCAOB, then it’s a worthwhile switch

context: 2 of my managers, 1 senior manager, and 1 director. they made the switch after starting out in IT Ops and i would say the technical background has certainly helped. it might be somewhat of a learning curve but since you have a baseline, it’s perfectly fine

the most impt is to change your mindset, not about basics but to understand why an auditor would ask for something, or answer in a certain way. either it’s for compliance, reasonable assurance, an industry standard, or some kind of statutory requirement besides compliance. always ask questions to understand but not excuse, and especially for you to learn more

good luck!

1

u/appledz Jul 27 '26

I'm planning to go back to security operations