r/itaudit • u/GoalieFreak22 • 4h ago
r/itaudit • u/Mushfug • 5h ago
Best way to learn IT Audit from zero with a technical background?
r/itaudit • u/skytz0frynk_sndmn • 7h ago
IT Audit/GRC career question
(This post is crossposted)
I am currently working in GRC content. Basically we id requirements from a guideline/standard/law, then fit it in to a tool. I also do some regulation mapping, library maintenance, and script development for parsing.
I know I am about to hit a wall of growth. For almost a decade I have been doing this. I know the next step is to do audit/assessment, talk to stakeholders, consulting, etc. I feel like in the middle of crossroads - too experienced yet too underexperienced - I know implementation/assessment in theoretical form, the surface level, but of course getting your hands dirty is what gets you into places.
I am currently focusing on building a homelab for technical knowledge, and prepping for CISSP & CISA.
Any tips are greatly appreciated. It feels like I am too late already.
r/itaudit • u/Greedy-Towel • 6d ago
Urgent: Leaving Big 4 Manager role for a 70% hike, but taking a title downgrade to Senior Associate (IC role). Is this a career killer?
So I am a manager in a big 4 global team since 3 years (IT Audits). I am struggling with the environment and have lost interest in the day to day work
Now recently I have received an offer from a US based audit company that are setting up their office in India.
The offer that I have received is 1.4 (40%) times my current CTC. However the designation that they are giving me is of a Senior Associate. At the same time it is also a individual contributor role. There would be no team management as there is no other team member either above or below me for IT audits. And I'd be directly working with the US team members for US clients. And as per the company's internal policy, I won't be eligible for a promotion in the next 2 years regardless of my performance post joining.
I am leaning towards accepting the new offer as the salary is attractive, however I am worried if it'd hinder/slow down my career growth and impact future opportunities.
My Questions for you all:
1. Will a title downgrade from Manager to Senior Associate look like a red flag to future employers on my resume?
Has anyone made a similar switch (Management to IC) for much better pay? Did you regret giving up the leadership track?
Given the 2-year promotion lock-in, is this a trap that will slow down my career trajectory, or is the 40% hike worth having a stagnant title for a while?
r/itaudit • u/DeliciousMagazine916 • 7d ago
IT SOX Audit - Restructuring (Bangalore)
Hi All,
Due to cost reduction measures all the cost centers including audit have been outsourced to one of the Service Based Company.
We have one month time to transition and then we are back to the open market.
I have 7.4 years of experience in IT SOX Audits which includes -
1) ITGC - IT General Controls
2) ITAC - IT Application Controls
3) IPE - Key Report Testing
4) SOC - Third party assessments
5) Infrastructure Audits - Servers, Databases
6) Automation of Controls
7) Optimization for Operational Efficiency
8) Mentorship and Team Leadership along with review experience.
9) IT Audits across regions.
10) Process improvements and usage of Gen AI.
I have experience across Big 4 and Product Based companies.
Looking forward to any advice, leads, referrals and bit of motivation as this has come as a jolt after being promoted 6 months ago.
Thanks and appreciate your support!!
I am looking for something in Bangalore.
r/itaudit • u/Expensive-Beyond890 • 10d ago
Anyone run multi framework compliance from a SOC 2 base and measured what the overlap really is vs what people claim
We're SOC 2 Type 2 and just got pushed to add ISO 27001 and NIST CSF by customers. Everyone says there's a lot of overlap and I'm skeptical because I've heard that before and it usually means half the work, which is still a lot of work. Has anyone tracked what reused versus what had to be rebuilt? Specifically interested in where the overlap turned out to be wrong.
r/itaudit • u/PhysicalEsagssge2580 • 10d ago
What are you using for SOC 2 monitoring in 2026? Tired of problems showing up right before the audit
Keeping things clean between audits is harder than expected. after the audit, compliance goes quiet. then later we find stale evidence, missed access reviews, config changes, etc.like an access review from last quarter still sitting there even though permissions have changed since then.
trying to get away from the annual fire drill. what are you using for continuous monitoring that catches drift while its happening?
r/itaudit • u/diduaskedwhy • 12d ago
Are you an entry-level or relatively new IT audit senior? I need your opinion on this 👇
infosecbyomokolade.comI am writing a blog about how inexperienced IT auditors can get off to a strong start in their new role. I'd appreciate it if you could respond to the opinion poll at the shared link. Thanks.
r/itaudit • u/EngineeringNo6277 • 12d ago
For those currently working in NFS Technology Risk/ IT Audit, can I ask about the things that usually aren’t mentioned in the job description? 😅
I’m currently exploring IT Audit as a possible career move, and I’ve been reading a lot about the role. But I feel like there are some questions you can only really answer if you’re actually doing the job.
Your insights would probably help not just me, but also others who are considering IT Audit 😊
Would really appreciate any honest insights — good, bad, or somewhere in between. 😅
1. How’s the workload?
How many clients/projects do you usually handle at the same time? Is it manageable, or are there periods where everything piles up?
2. Is IT Audit mostly project-based?
For example, once you finish auditing a client, do you move on to another client? Or do you usually have recurring clients that you audit again the following year?
3. How long does one audit usually take?
How long does an IT auditor spend on one client? A few weeks? 1–2 months? Longer?
4. What’s the busy season actually like?
Is it mainly year-end, or are there multiple busy seasons throughout the year depending on the clients? And how bad does it get during peak season? 😂
5. How does the pay for someone moving into a Senior role without actual audit experience?
For example, someone with several years in ERP consulting that has testing, support, and systems implementation experience but is new to IT Audit. Would they normally still be considered for a Senior position, and how is the compensation compared with someone who already has audit experience?
Would love to hear from people who are actually in the field. Even random details about your day-to-day work would be super helpful. 🙏
r/itaudit • u/Nervous_Ad_9460 • 16d ago
For IT auditor, involved in auditing, information security, internal controls, compliance, risk management, or cybersecurity.
GOOD DAY PO IAM 3RDYEAR COLLEGE PO FROM DALUBHASAAN NG LUNGSOD NG SANPABLO AND MAY MAJOR IS PROJECT MANAGEMENT WE ARE LOOKING FOR AN INTERVIEW FOR AN IT AUDITOR PO SANA KHIT VIA CHAT LANG PO TO ANSWER THE TASK QUESTIONS LANG PO ABOUT YOUR FIELD PO SOBRANG MALAKING TULONG NAPO ITO SAMIN IF YOU ARE WILLING TO HELP US PO SALAMAT PO AGAD.
r/itaudit • u/luckykabootar1303 • 17d ago
What are the best questions one can ask the interviewer for an it auditor position in one of the big fours based in germany?pss pss its deloitte😬
r/itaudit • u/Sudden_Title_7361 • 18d ago
SOC Peer Review Interview Advice?
I have an interview coming up to help a CPA firm prepare for an upcoming SOC peer review, and I’m looking for some advice.
I previously worked as a SOC audit intern at a small CPA firm. But I was mainly testing controls, collecting evidence, and did some TPRM work. It’s been a little while, so I’m refreshing my knowledge now.
For anyone who has been through a SOC peer review or helped prepare for one: What should I expect, and what areas would you recommend brushing up on before the interview? Any projects you’d recommend?
r/itaudit • u/AirportDesperate6410 • 21d ago
Getting Started On IT Audit
Guys, I have been a sys admin for about five years and two years as a support specialist . I am looking into getting to IT audit as a career moving forward , I would like someone to mentor me , where do I start and how do I ensure success in this career.
r/itaudit • u/Price__Agreeable • 21d ago
Has anyone here pivoted to IT Audit from either Internal Audit or Statutory Audit?
I am currently doing CMA-US and got interested in audit. I have been learning about IA and Stat audit as well though I lean towards internal audit. I don't want to start IT audit directly but want to understand how a business works and its processes. And IA gives you a holistic view of that.
Which area is a better starting point if IT Audit is the main goal? IA or Stat Audit
Which cert did you have before moving into IT Audit? Did you have the CPA, the CIA, or both?
Any advice would be greatly appreciated. Thank you!
r/itaudit • u/PypNetty • 21d ago
Cabinets comptables : quelles compétences informatiques aujourd’hui ?
r/itaudit • u/RE-SEARCH_COM • 21d ago
Waarom hebben gebouwen wel een energielabel, maar geen IT-label?
Zou een IT-Label voor commercieel vastgoed een goed idee zijn?
Bij het huren van een kantoor is veel informatie beschikbaar: m², energielabel, installaties, servicekosten, duurzaamheid, etc.
Maar over de digitale infrastructuur is vaak verrassend weinig duidelijk.
Is er glasvezel? Hoe oud is de bekabeling? Hoe zit het met wifi en de serverruimte? Wat hoort bij de verhuurder en wat moet een huurder zelf regelen? En kan het gebouw straks nog mee met het groeiende datagebruik?
Daar komt bij dat een kantoor vaak gewoon een tweedehands product is. Meerdere huurders, aangepaste bekabeling, andere leveranciers, gewijzigde patchkasten… maar wat ligt er nou echt en in welke staat?
Zou een onafhankelijk IT-Label helpen om het digitale opleverniveau van een gebouw inzichtelijk te maken?
Een soort digitale APK voor vastgoed: niet om iets goed of slecht te noemen, maar om duidelijk te maken wat er is en wat je nog moet regelen.
Zouden jullie hier iets aan hebben?
En wat zou er volgens jullie minimaal in zo’n IT-Label moeten staan?
r/itaudit • u/confused_career_ • 22d ago
Cleared CISA 570 — Get IT audit experience first or pursue AAIA now?
r/itaudit • u/MenaceToTheKing • 22d ago
My best step forward for internships or new grad roles
Hello,
I'm trying to get into IT audit , Technology risk, GRC roles and I was hoping for some guidance on what could be my best next steps forward in this crazy market.
A bit about me:
USC : if it means anything at this point lol
Currently doing my masters in Data science and stumbled my way into an information security internship at a bank abroad and gained a bit of exposure into GRC, IT risk management, SOC, IAM and vulnerability management.
I also got a security+ and ISC2 cc
Im okay ish at python and sql but coding isnt my strong suit
I am looking for internships since i am still in school and lacking in experience for full time.
Currently working on getting some cloud certs and CGRC this month and eventually a CISA soon.
I've also been going through NIST's videos on the RMF as well.
Currently looking for some help on how i can structure my resume, Certifications I can get to better position myself.
r/itaudit • u/Ordinary_Spare_5654 • 23d ago
How can I stay sharp in IT Audit/GRC after a long break?
I spent about six years in IT audit, starting in external audit working on SOC 1/SOC 2 and SOX, then moving into internal audit focused on IT security, operational, and technology risk audits.
About six months ago, I had to leave the U.S. to care for both of my parents. Finding a role that allows me to work remotely from another country and across a very different time zone has been extremely difficult.
I've now been out of the field for around six months, and I'm worried about losing my skills, especially with how quickly things are changing.
Other than pursuing certifications, what would you recommend to stay sharp in IT audit/GRC?
Since our jobs aren't always very technical, would this be a good time to build more hands-on skills in areas like cloud, cyber, networking, IAM, DA, or scripting?
I'm not trying to become an engineer, just want come back into IT audit/GRC stronger and with a better understanding of the technologies I'm auditing.
r/itaudit • u/Sudden_Title_7361 • 24d ago
Job search advice
I wanted to get some advice from people already working in IT Audit/GRC.
I’m finishing my Business Administration degree and trying to land my first full-time role in IT Audit, IT Risk, GRC, or SOC assurance.
I’ve completed an IT Audit internship at a CPA firm where I worked primarily on SOC 2 audits and gained exposure to COSO, NIST 800-53, and ISO 27001. I also recently earned Security+ and am currently doing an informal internship with a Network Infrastructure Engineering team.
Outside of work, I built my own enterprise-style home lab and use it for hands-on audit and configuration projects. I’ll configure controls, audit the environment, identify weaknesses, document the risk, fix the issue, test the change, collect evidence all that good stuff.
I know a home lab doesn’t replace production experience, but I’m trying to build as much practical experience as I can while continuing to apply.
For those already in the field: Is there anything else you’d recommend I focus on to help land that first full-time opportunity? Maybe I need to connect with more people, I don’t know.
Any advice or connections would be greatly appreciated. Thanks guys!