# Information Technology Auditor

*/JobTypes/Information_Technology_Auditor*

## Neighborhood

### Related (signature role)

- [Internal Audit Outsourcing Provider](/CompanyTypes/Internal_Audit_Outsourcing_Provider) — signature role · CompanyTypes
- [Internal Audit Co-Sourcing Provider](/CompanyTypes/Internal_Audit_Co-Sourcing_Provider) — signature role · CompanyTypes

### Related (delivered by)

- [Perform risk assessments and execute tests of data processing system to ensure functioning of data p...](/Tasks/Perform_risk_assessments_and_execute_tests_of_data_processing_system_to_ensure_functioning_of_data_p...) — delivered by · Tasks
- [Conduct pre-implementation audits to determine if systems and programs under development will work a...](/Tasks/Conduct_pre-implementation_audits_to_determine_if_systems_and_programs_under_development_will_work_a...) — delivered by · Tasks
- [Implement segregation of duties controls](/Processes/Implement_segregation_of_duties_controls) — delivered by · Processes

### Perform

- [Recommend Control Remediation](/Tasks/Recommend_Control_Remediation) — perform · Tasks
- [Test technology controls](/Tasks/Test_technology_controls) — perform · Tasks
- [Assess IT risks in audit scope](/Tasks/Assess_IT_risks_in_audit_scope) — perform · Tasks
- [Document IT audit findings](/Tasks/Document_IT_audit_findings) — perform · Tasks
- [Evaluate IT dependencies in processes](/Tasks/Evaluate_IT_dependencies_in_processes) — perform · Tasks
- [Review IT policies and procedures](/Tasks/Review_IT_policies_and_procedures) — perform · Tasks
- [Provide assistance to internal or external auditors in compliance reviews.](/Tasks/Provide_assistance_to_internal_or_external_auditors_in_compliance_reviews.) — perform · Tasks
- [Prepare detailed reports on audit findings.](/Tasks/Prepare_detailed_reports_on_audit_findings.) — perform · Tasks
- [Assess IT process and governance maturity](/Tasks/Assess_IT_process_and_governance_maturity) — perform · Tasks
- [Evaluate third-party and cloud risk](/Tasks/Evaluate_third-party_and_cloud_risk) — perform · Tasks
- [Plan IT governance and controls audits](/Tasks/Plan_IT_governance_and_controls_audits) — perform · Tasks
- [Recommend and track remediation](/Tasks/Recommend_and_track_remediation) — perform · Tasks
- [Report results to audit committee and management](/Tasks/Report_results_to_audit_committee_and_management) — perform · Tasks
- [Test controls over operations, security, and change](/Tasks/Test_controls_over_operations,_security,_and_change) — perform · Tasks
- [Coordinate with financial auditors on system reliance](/Tasks/Coordinate_with_financial_auditors_on_system_reliance) — perform · Tasks
- [Assess data integrity controls](/Tasks/Assess_data_integrity_controls) — perform · Tasks
- [Document control deficiencies](/Tasks/Document_control_deficiencies) — perform · Tasks
- [Track remediation of IT findings](/Tasks/Track_remediation_of_IT_findings) — perform · Tasks
- [Test automated application controls](/Tasks/Test_automated_application_controls) — perform · Tasks
- [Scope IT audit engagements](/Tasks/Scope_IT_audit_engagements) — perform · Tasks
- [Evaluate IT general controls](/Tasks/Evaluate_IT_general_controls) — perform · Tasks

### Required knowledge

- [Regulatory and compliance obligations](/Knowledge/Regulatory_and_compliance_obligations) — requires knowledge · Knowledge
- [Regulatory Compliance](/Knowledge/Regulatory_Compliance) — requires knowledge · Knowledge
- [Internal Control Concepts](/Knowledge/Internal_Control_Concepts) — requires knowledge · Knowledge
- [Audit Methodology and Standards](/Knowledge/Audit_Methodology_and_Standards) — requires knowledge · Knowledge
- [Audit Methodologies](/Knowledge/Audit_Methodologies) — requires knowledge · Knowledge
- [IT Audit Frameworks](/Knowledge/IT_Audit_Frameworks) — requires knowledge · Knowledge
- [Cloud and third-party risk](/Knowledge/Cloud_and_third-party_risk) — requires knowledge · Knowledge
- [IT governance and audit frameworks](/Knowledge/IT_governance_and_audit_frameworks) — requires knowledge · Knowledge
- [IT General Controls](/Knowledge/IT_General_Controls) — requires knowledge · Knowledge
- [Internal Control Frameworks](/Knowledge/Internal_Control_Frameworks) — requires knowledge · Knowledge

### Required skills

- [Control Testing](/Skills/Control_Testing) — requires skill · Skills
- [Audit Documentation](/Skills/Audit_Documentation) — requires skill · Skills
- [IT Risk Assessment](/Skills/IT_Risk_Assessment) — requires skill · Skills
- [Critical Thinking](/Skills/Critical_Thinking) — requires skill · Skills
- [Audit planning](/Skills/Audit_planning) — requires skill · Skills
- [Findings documentation](/Skills/Findings_documentation) — requires skill · Skills
- [Governance maturity assessment](/Skills/Governance_maturity_assessment) — requires skill · Skills
- [IT controls testing](/Skills/IT_controls_testing) — requires skill · Skills
- [Stakeholder reporting](/Skills/Stakeholder_reporting) — requires skill · Skills
- [IT Control Testing](/Skills/IT_Control_Testing) — requires skill · Skills

### Uses software

- [Data Analysis Software](/Software/Data_Analysis_Software) — uses software · Software
- [Governance Risk and Compliance Platform](/Software/Governance_Risk_and_Compliance_Platform) — uses software · Software
- [TeamMate](/Software/TeamMate) — uses software · Software
- [ACL Analytics](/Software/ACL_Analytics) — uses software · Software
- [Microsoft Visio](/Software/Microsoft_Visio) — uses software · Software
- [ServiceNow GRC](/Software/ServiceNow_GRC) — uses software · Software
- [Data Analytics Software](/Software/Data_Analytics_Software) — uses software · Software
- [Microsoft Excel](/Software/Microsoft_Excel) — uses software · Software
- [Audit Management Software](/Software/Audit_Management_Software) — uses software · Software

### Engage in

- [Assess IT risks in audit scope](/Activities/Assess_IT_risks_in_audit_scope) — engage in · Activities
- [Test technology controls](/Activities/Test_technology_controls) — engage in · Activities
- [Plan IT governance and controls audits](/Activities/Plan_IT_governance_and_controls_audits) — engage in · Activities
- [Test controls over operations, security, and change](/Activities/Test_controls_over_operations,_security,_and_change) — engage in · Activities
- [Assess IT process and governance maturity](/Activities/Assess_IT_process_and_governance_maturity) — engage in · Activities
- [Coordinate with financial auditors on system reliance](/Activities/Coordinate_with_financial_auditors_on_system_reliance) — engage in · Activities
- [Evaluate IT general controls](/Activities/Evaluate_IT_general_controls) — engage in · Activities

### Requires ability

- [Inductive Reasoning](/Ability/Inductive_Reasoning) — requires ability · Ability
- [Attention to detail](/Ability/Attention_to_detail) — requires ability · Ability
- [Deductive reasoning](/Ability/Deductive_reasoning) — requires ability · Ability
- [Problem sensitivity](/Ability/Problem_sensitivity) — requires ability · Ability
- [Written expression](/Ability/Written_expression) — requires ability · Ability
- [Selective Attention](/Ability/Selective_Attention) — requires ability · Ability

### Type of

- [Auditors](/Occupations/Auditors) — type of · Occupations
- [Accountants and Auditors](/Occupations/Accountants_and_Auditors) — type of · Occupations

### Problems this exposes

- [testing change-management tickets against actual Git/CI deploys to catch unauthorized prod pushes](/Problems/testing_change-management_tickets_against_actual_Git%2FCI_deploys_to_catch_unauthorized_prod_pushes) — exposes problem · Problems
- [scoping in-scope systems when shadow SaaS bypasses the CMDB](/Problems/scoping_in-scope_systems_when_shadow_SaaS_bypasses_the_CMDB) — exposes problem · Problems
- [mapping the same control evidence across SOC2, ISO 27001, and PCI request lists without re-pulling it](/Problems/mapping_the_same_control_evidence_across_SOC2,_ISO_27001,_and_PCI_request_lists_without_re-pulling_it) — exposes problem · Problems
- [chasing control owners for screenshots that go stale before fieldwork sign-off](/Problems/chasing_control_owners_for_screenshots_that_go_stale_before_fieldwork_sign-off) — exposes problem · Problems
- [sampling privileged-access reviews from IAM logs when joiner/mover/leaver records are incomplete](/Problems/sampling_privileged-access_reviews_from_IAM_logs_when_joiner%2Fmover%2Fleaver_records_are_incomplete) — exposes problem · Problems
