GitLab Logo

GitLab

Senior Internal Auditor

Posted Yesterday
Be an Early Applicant
Easy Apply
Remote
Hiring Remotely in Canada
Senior level
Easy Apply
Remote
Hiring Remotely in Canada
Senior level
Lead and execute technology audits across cloud, application, and cybersecurity domains to support SOX compliance. Design and test IT general, application, and entity-level controls; perform risk-based planning, testing, and reporting; drive remediation with process owners; and apply data analytics, automation, and generative AI to improve audit quality and efficiency.
The summary above was generated by AI

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster.

The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software.

*Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab.

An overview of this role

As a Senior Internal Auditor reporting to the Senior Manager, Technology Internal Audit, you’ll help GitLab assess risk and strengthen controls across a technology landscape that includes multi-cloud infrastructure, artificial intelligence and machine learning systems, and modern development practices. This USA-based role supports our Sarbanes-Oxley Act (SOX) program while partnering with Engineering, IT Operations, Security, and business teams to build controls that work in practice, not just on paper.

You’ll execute technology audits, turn findings into practical improvements, and use data analytics, automation, and generative artificial intelligence tools to improve audit quality and efficiency. You’ll work as a trusted advisor who connects technical risks to business impact, helps leaders anticipate emerging risks, and supports remediation through closure.

What You’ll Do  

  • Execute technology audits covering SOX compliance, cloud infrastructure across Amazon Web Services, and Google Cloud Platform, application controls, cybersecurity, artificial intelligence and machine learning systems, and DevSecOps practices.
  • Design and test IT general controls, application controls, and entity-level controls with minimal supervision.
  • Support the IT SOX program from planning through reporting, including risk-based audit planning, process walkthroughs, testing, and coordination with external co-source providers.
  • Maintain clear, high-quality audit documentation, including risk and control matrices, process flows, test procedures, findings, and business impact assessments.
  • Own remediation efforts by partnering with process owners on practical corrective action plans, validating effectiveness before closure, and preparing status updates for leadership.
  • Collaborate with Engineering, IT Operations, Security, and business process owners to assess emerging risks and evaluate new system implementations for control adequacy and SOX relevance.
  • Review controls across financial statement cycles, including record to report, order to cash, hire to retire, and procure to pay, as well as third-party System and Organization Controls 1 and 2 reports.
  • Use data analytics, automation, and generative artificial intelligence tools to improve audit efficiency, coverage, and quality.

What You’ll Bring 

  • Experience executing technology audits and risk management work in complex technology environments, including audit planning, testing, reporting, and remediation.
  • Experience supporting IT SOX programs and designing and testing IT general controls and application controls.
  • Knowledge of IT control frameworks such as COBIT, the National Institute of Standards and Technology framework, Information Technology Infrastructure Library, ISO 27001, and the Committee of Sponsoring Organizations of the Treadway Commission Internal Control Framework.
  • Knowledge of cloud security principles and cybersecurity fundamentals, including network security, encryption, identity and access management, vulnerability management, and Zero Trust principles.
  • Experience with modern development practices, including Agile and DevOps, and with data analytics and audit automation tools.
  • Clear written and verbal communication skills, with the ability to explain technical findings, business impact, and practical recommendations to technical and business audiences.
  • A self-directed, collaborative approach to managing multiple priorities, adapting to change, and helping teams improve their risk and control environments.
  • A bachelor’s degree in Accounting, Information Technology, Computer Science, Finance, or a related field, and an active relevant professional certification such as Certified Public Accountant, Certified Internal Auditor, Certified Information Systems Auditor, Certified Information Systems Security Professional, Certified Information Security Manager, Certified in Risk and Information Systems Control, or an equivalent certification.

About the team

The Technology Internal Audit team helps GitLab understand and manage technology risk while supporting a secure and effective control environment. The team partners across Engineering, IT Operations, Security, Finance, and other business functions to support SOX compliance, assess emerging technologies, and turn audit insights into practical improvements. We work as solution-driven partners, communicate risks in business terms, build trust with stakeholders, connect audit work to GitLab’s priorities, and use technology to scale our impact.

How GitLab will support you
  • Benefits to support your health, finances, and well-being
  • Flexible Paid Time Off 
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental leave 
  • Home office support

Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to assess your application.

The base salary range for this role’s listed level is currently for residents of the United States only. This range is intended to reflect the role's base salary rate in locations throughout the US. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, alignment with market data, and geographic location. The base salary range does not include any bonuses, equity, or benefits. See more information on our benefits and equity. Sales roles are also eligible for incentive pay targeted at up to 100% of the offered base salary.

United States Salary Range
$86,400$146,400 USD
How GitLab Supports Full-Time Employees
  • Benefits to support your health, finances, and well-being
  • Flexible Paid Time Off 
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave 

Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to assess your application.

Country Hiring Guidelines: GitLab hires new team members in countries around the world. All of our roles are remote, however some roles may carry specific location-based eligibility requirements. Our Talent Acquisition team can help answer any questions about location after starting the recruiting process.  

Privacy Policy: Please review our Recruitment Privacy Policy. Your privacy is important to us.

GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab’s policies and practices relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit, regardless of race, color, religion, ancestry, sex (including pregnancy, lactation, sexual orientation, gender identity, or gender expression), national origin, age, citizenship, marital status, mental or physical disability, genetic information (including family medical history), discharge status from the military, protected veteran status (which includes disabled veterans, recently separated veterans, active duty wartime or campaign badge veterans, and Armed Forces service medal veterans), or any other basis protected by law. GitLab will not tolerate discrimination or harassment based on any of these characteristics. See also GitLab’s EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know during the recruiting process.

Similar Jobs at GitLab

3 Hours Ago
Easy Apply
Remote
Easy Apply
Senior level
Senior level
Cloud • Security • Software • Cybersecurity • Automation
Own lifecycle communications strategy for prospects, build and optimize automated email journeys, execute campaigns end-to-end (copy, segmentation, QA, testing, launch), collaborate cross-functionally, use data to drive improvements in engagement and funnel progression, and act as the email marketing SME for best practices and deliverability.
Top Skills: AICRMCSSHTMLMarketo
3 Hours Ago
Easy Apply
Remote
India
Easy Apply
Mid level
Mid level
Cloud • Security • Software • Cybersecurity • Automation
As a Backend Engineer, you'll improve Git and Gitaly by contributing features, bug fixes, and performance improvements, collaborating with the open source community, and participating in architectural discussions.
Top Skills: CGitGitalyGoLinux
3 Hours Ago
Easy Apply
Remote
Easy Apply
Expert/Leader
Expert/Leader
Cloud • Security • Software • Cybersecurity • Automation
The Distinguished Engineer will pioneer autonomous SDLC capabilities by integrating AI into software development workflows, driving productivity and innovation across teams. Responsibilities include defining technical vision, conducting experiments, mentoring engineers, and ensuring compliance and safety of AI systems.
Top Skills: AICi/CdDevsecopsGitlabLarge Language ModelsMlScalable Distributed Systems

What you need to know about the Delhi Tech Scene

Delhi, India's capital city, is a place where tradition and progress co-exist. While Old Delhi is known for its rich history and bustling markets, New Delhi is defined by its modern architecture. It's clear the region places a strong emphasis on preserving its cultural heritage while embracing technological advancements, particularly in artificial intelligence, which plays a central role in shaping the city's tech landscape, fueled by investments in research and development.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account