As an IT Audit Principal, you will lead and execute complex internal IT audits across a variety of technology environments, including cloud and on-premises infrastructure, with a focus on Cybersecurity, IT General Controls (ITGCs), and Application Controls. You will assess control design and operating effectiveness, evaluate technology and security risks, identify control gaps and root causes, and provide practical recommendations that strengthen the organization overall control environment.
In this role, you will serve as an independent and objective advisor, partnering with leaders across IT, Security, Finance, HR, and external audit teams. You will apply deep subject matter expertise through hands-on control evaluations, support major transformation initiatives, and advise leadership on effective ways to manage risk. We are seeking applicants with strong technical knowledge, sound judgment, and the ability to turn complex findings into clear actions that support a strong and sustainable control environment.
What you'll be doing
- Lead internal IT audit engagements from planning through reporting, including risk assessment, control evaluation, stakeholder communication, and remediation monitoring.
- Conduct cybersecurity audits using a comprehensive, risk-based approach to assess the design and effectiveness governance, risk management, and control processes established across key areas such as identity and access management, security monitoring, privileged access, vulnerability management, incident response, and other relevant cybersecurity domains.
- Lead evaluations of cybersecurity programs and controls against established frameworks and standards such as NIST and ISO 27001, in alignment with the Internal Audit plan and business risk priorities.
- Conduct ITGC SOX audits to assess the design and operating effectiveness of controls across key areas such as access management, change management, IT operations, interfaces, backups, and disaster recovery.
- Evaluate System Development Life Cycle (SDLC) controls for major implementations, upgrades, and transformation, including project governance, requirements and design, user acceptance testing (UAT), data conversion, access and security, deployment readiness, and post implementation.
- Provide thought leadership in the continuous development and execution of the risk based internal audit plan, supporting enterprise risk assessments, audit
- prioritization, scoping, and coordination across IT, SOX, and operational audit actives.
- Partner with GRC, security, and technology teams to evaluate risks across cloud, infrastructure, and application environments and assess whether key controls are appropriately designed and operating effectively.
- Act as a liaison to external auditors for ITGC and cybersecurity-related audits, ensuring alignment and timely communication of findings.
- Lead and perform root cause analysis and provide recommendations for control deficiencies, including those related to cybersecurity incidents and/or control gaps.
- Develop, review, and maintain IT control documentation, including process flows, narratives, and control matrices, and ensuring alignment with both SOX and cybersecurity requirements.
- Enable continuous improvement initiatives across IT Audit and cybersecurity programs, including automation and deployment of new technologies.
- Support executive leadership with special project advisory that inform strategic initiatives, risk assessments, and special transformational projects as needed.
- Build and leverage AI solutions and workflows to enable capacity or unlock capability for an Internal Audit function.
What you'll likely bring
8+ years of progressive experience in IT audit, IT compliance, SOX, and/or cybersecurity risk management (public accounting and/or industry). Big 4 is a plus.
Specialized experience in the Software industry.
Bachelor’s degree in Information Systems, Cybersecurity, Accounting, Finance, or related field.
Relevant certifications such as CISA, CISSP, CISM, CRISC, CIA, or CPA (or equivalent).
What can set you apart
- Deep experience performing cybersecurity audits.
- Strong knowledge of ITGC domains (Access Management, Change Management, Interfaces, Backups, Disaster Recovery), SDLC, and their intersection with cybersecurity controls.
- Deep experience auditing systems such as SalesForce, Workday, Kinetic, Microsoft Azure (Entra ID), Active Directory, and different types of cloud environments (IaaS, PaaS, and SaaS).
- Strong understanding of SOX requirements (e.g. 302, 404), principles-based internal control-integrated framework (COSO), IT Frameworks (e.g., COBIT) and cybersecurity control frameworks (e.g., NIST CSF, ISO 27001, CIS Critical Security Controls).
- Experience leveraging automation and tools such as Workiva’s Wdesk and AI tools (ChatGPT, Copilot, Claude, etc.).
- Excellent communication and stakeholder management skills, with the ability to influence at all levels of the organization.
#LI-CM1
#HYBRID
About Epicor
At Epicor, we’re truly a team. Join 5,000 talented professionals in creating a world of better business through data, AI, and cognitive ERP. We help businesses stay future-ready by connecting people, processes, and technology. From software engineers who command the latest AI technology to business development reps who help us seize new opportunities, the work we do matters. Together, Epicor employees are creating a more resilient global supply chain.
We’re Proactive, Proud, Partners.
Whatever your career journey, we’ll help you find the right path. Through our training courses, mentorship, and continuous support, you’ll get everything you need to thrive. At Epicor, your success is our success. And that success really matters, because we’re the essential partners for the world’s most essential businesses—the hardworking companies who make, move, and sell the things the world needs.
Competitive Pay & Benefits
Health and Wellness: Comprehensive health and wellness benefits designed to support your overall well-being.
Internal Mobility: Opportunities for mentorship, continuing education, and focused career goal setting, with 25% of positions filled internally.
Career Development: Free LinkedIn Learning licenses for everyone, along with our Mentoring Program to boost your personal development.
Education Support: Geographically specific programs to balance the cost of education with the benefits of continued learning and personal development.
Inclusive Workplace: Collaborate with a diverse team in an inclusive, global workplace that fosters innovation and celebrates partnership.
Work-Life Balance: Policies built on mutual trust and support, encouraging time off to rest, recharge, and reconnect.
Global Mobility: Comprehensive support for international relocations and permanent residency processes.
Equal Opportunities and Accommodations Statement
Epicor is committed to creating a workplace and global community where inclusion is valued; where you bring the whole and real you—that’s who we’re interested in. If you have interest in this or any role- but your experience doesn’t match every qualification of the job description, that’s okay- consider applying regardless.
We are an equal-opportunity employer.
Recruiter:
Christi McCallEpicor Austin, Texas, USA Office
Just 15 minutes West of downtown, our office is right across the street from some of Austin's favorite local restaurants and easy to access from MOPAC
Similar Jobs
What you need to know about the Austin Tech Scene
Key Facts About Austin Tech
- Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
- Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
- Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
- Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center



%20copy.jpg)