IT Senior Internal Auditor
- Full-time
Company Description
At National Vision we believe everyone deserves to see their best to live their best. We help people by making quality eye care and eyewear more affordable and accessible. National Vision is one of the largest optical retail companies in the United States with over 1,200 stores. We operate four retail brands: America’s Best Contacts & Eyeglasses, Eyeglass World, and Vista Optical inside select Fred Meyer stores and on select military bases. We offer an innovative culture where training is a priority, hard work is praised, and career growth is a reality.
We are hiring for a IT Senior Internal Auditor to join our growing team!
Job Description
The Senior IT Internal Auditor is responsible for independently planning and executing IT audits to evaluate the effectiveness of technology controls, risk management practices, and regulatory compliance across National Vision's retail, laboratory, corporate, and technology operations. As a member of the Global Internal Audit team, this role partners with business leaders, IT management, and risk and compliance stakeholders to assess and improve controls supporting enterprise systems, cybersecurity, data integrity, and technology-enabled business processes. The position conducts audits and advisory reviews related to SOX, SOC, ISO, cybersecurity, privacy, third-party risk management, system development life cycle (SDLC), user access management, IT automated controls (ITACs), key reports and calculations, and supporting infrastructure to enhance operational efficiency, compliance, and risk mitigation across the organization.
What Would You Do? The Specifics.
- Execute risk-based IT audits across applications, infrastructure, cybersecurity, SOX, and technology operations.
- Perform IT risk assessments and evaluate the design and effectiveness of key controls.
- Assess controls over user access, system development, automated controls, key reports, data integrity, and third-party risk.
- Identify control gaps, root causes, and opportunities to strengthen risk management and compliance.
- Communicate audit observations, recommendations, and project results to management.
- Lead multiple audit engagements and provide guidance and feedback to junior team members.
- Partner with business, IT, compliance, and external stakeholders throughout the audit lifecycle.
- Support control remediation efforts and monitor corrective action plan implementation.
- Drive continuous improvement through audit automation, continuous monitoring, and process enhancements.
- Maintain current knowledge of emerging technologies, cybersecurity risks, regulatory requirements, and industry best practices.
- Maintain confidentiality and uphold the highest standards of integrity and objectivity.
- Support continuous improvement initiatives within the Internal Audit function.
- Develop and maintain effective working relationships across the organization.
Qualifications
Work Experience
- 4-6 years in an audit capacity in either a publicly traded company and/or with a public accounting firm (Required)
- 2-4 years experience leading and executing IT audits, including ITGCs, ITACs, key reports/calculations, SOX, SOC, and ISO-related controls (Required)
Education
- Four year college degree or equivalent experience. in Information Systems, Cybersecurity, Computer Science, or a related field (Required)
Licenses, Certifications, Professional Affiliations
- Certified Information Systems Auditor (CISA) (Preferred)
- Certified Internal Auditor (CIA) (Preferred)
- Certified Information Systems Security Professional (CISSP) (Preferred)
- Certified in Risk and Information Systems Control (CRISC) (Preferred)
- Certified Information Security Manager (CISM) (Preferred)
- Cloud security certifications (e.g., AWS, Azure, or Google Cloud) (Preferred)
- Additional certifications related to IT governance, cybersecurity, privacy, risk management, or data analytics (Preferred)
Additional Skills
- Advance skills in Microsoft tool suite (Excel, Power Point, Word). (Required)
- Working knowledge of IT environments, including applications, databases, operating systems, cloud platforms, infrastructure, and networks (Required)
- Understanding of IT control frameworks and risk management concepts, including ITGCs, ITACs, cybersecurity, IT operations, and technology governance (Required)
- Strong verbal and written communication skills, including the ability to communicate technical concepts to non-technical audiences and strong analytical, critical-thinking, and problem-solving skills with the ability to identify risks and develop practical recommendations. (Required)
- Knowledge of cybersecurity domains, including identity and access management, vulnerability management, data protection, incident response, and third-party risk management. (Preferred)
- Experience auditing cloud environments, operational technology (OT), cybersecurity programs, or digital transformation initiatives. (Preferred)
- Experience using data analytics, reporting, automation, or visualization tools (e.g., Power BI, SQL, UiPath,Alteryx, Python). (Preferred)
Additional Information
Taking Care of our People!
We understand the importance of financial health and security, and because of that, we provide competitive compensation to all associates. We also offer a comprehensive benefits package including health and dental insurance, 401k retirement savings with company match, flex spending account, paid personal time off, paid company holidays, parental leave, employee eyewear discount, and much, much more. At National Vision, we strive to deliver opportunities for professional growth and long-term career fulfillment. We provide training programs and access to educational courses and pride ourselves on the ever-increasing amount of promotions from within.
We are an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, disability, veteran status, and other legally protected characteristics.
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply