HERE

Sr IT Auditor

Job Locations IN-MH-Mumbai
Requisition ID
2026-83451
Category
Corporate

What's the role?

The Team

You will join our Global Internal Audit team, partnering with technology, cybersecurity, privacy, compliance, and business stakeholders across the organization. The team provides independent assurance on technology risks and controls while supporting the company's transformation across cloud, cybersecurity, artificial intelligence, privacy, and digital innovation initiatives. We operate in a collaborative environment that values curiosity, continuous learning, and practical solutions to complex technology challenges
 
As a Senior IT Auditor, you will independently execute risk-based IT audit engagements across SOX 404 IT General Controls (ITGCs), application controls, cybersecurity, cloud technologies, privacy, artificial intelligence (AI), Generative AI (GenAI), and technology governance domains.
Working under the direction of the Lead IT Auditor, you will perform audit planning, risk assessments, control testing, reporting, and remediation validation activities while partnering with global stakeholders to strengthen governance, risk management, and compliance across the organization.

Your Responsibilities

  • Execute risk-based IT audit engagements from planning through reporting and remediation validation.
  • Perform SOX 404 IT General Controls (ITGC) testing covering access management, segregation of duties, change management, computer operations, and software development lifecycle (SDLC) controls.
  • Conduct application control testing supporting financial and operational business processes.
  • Evaluate the design and operating effectiveness of technology, cybersecurity, and privacy controls.
  • Assess cybersecurity controls aligned with NIST Cybersecurity Framework (CSF), ISO 27001, CIS Controls, and COBIT.
  • Review governance and controls related to identity and access management (IAM), privileged access management (PAM), cloud security, vulnerability management, incident response, and technology operations.
  • Assess privacy and data governance controls related to data classification, retention, protection, and regulatory compliance.
  • Evaluate governance, risk management, and control frameworks for AI, Generative AI, and emerging technologies, including alignment to Responsible AI principles and ISO 42001.
  • Review SOC 1 and SOC 2 Type II reports and assess third-party technology and cloud service provider risks.
  • Collaborate with internal stakeholders and external auditors to support compliance, audit coordination, and remediation activities.
  • Prepare clear, concise, and actionable audit reports for management and senior leadership.
  • Contribute to the continuous enhancement of audit methodologies, automation, analytics, and risk assessment practices.

 

Who are you?

 

You are an experienced IT audit professional who enjoys understanding complex technology environments and translating technical risks into practical business insights. You bring strong audit execution skills, sound professional judgment, and the ability to build productive relationships across global teams.
 
To be successful in this role, you will have:
  • A bachelor's degree in Information Systems, Information Technology, Computer Science, Cybersecurity, Accounting Information Systems, or a related field.
  • 5+ years of IT audit experience within a Big Four or national public accounting firm or experience in Internal IT Audit, Technology Risk Management, Cybersecurity Assurance, Risk & Compliance, or related disciplines.
  • Experience executing audit engagements through planning, fieldwork, reporting, and remediation follow-up activities.
  • Strong knowledge of SOX 404 compliance, including IT General Controls (ITGCs), automated controls, and application controls testing.
  • Experience auditing enterprise applications, cloud environments, technology operations, databases, and IT processes.
  • Experience conducting cybersecurity risk assessments, technology governance reviews, compliance assessments, and privacy reviews.
  • Professional certification such as CISA or CISSP.
  • Knowledge of industry frameworks including NIST, ISO/IEC 27001, CIS Controls, COBIT, ISO 27701, and ISO 42001.
  • Experience reviewing SOC 1 and SOC 2 Type II reports.
  • Understanding of cloud security and governance controls within Microsoft Azure and AWS environments.
  • Familiarity with DevOps practices, CI/CD pipelines, and modern software development methodologies.
  • Understanding of AI governance, Generative AI risks, Responsible AI principles, and large language model technologies.
  • Experience using data analytics techniques and audit management platforms such as AuditBoard or similar solutions.

 

 

HERE is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, age, gender identity, sexual orientation, marital status, parental status, religion, sex, national origin, disability, veteran status, and other legally protected characteristics.

 

Who are we?

HERE Technologies is a location data and technology platform company. We empower our customers to achieve better outcomes – from helping a city manage its infrastructure or a business optimize its assets to guiding drivers to their destination safely.

 

At HERE we take it upon ourselves to be the change we wish to see. We create solutions that fuel innovation, provide opportunity and foster inclusion to improve people’s lives. If you are inspired by an open world and driven to create positive change, join us. Learn more about us on our YouTube Channel.

 

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed