Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI
Agile @ 4
Audit @ 4
Compliance
DevOps @ 4
Machine Learning
Planning @ 4
Reporting @ 4
Security @ 4
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
An overview of this role
As a Senior Internal Auditor reporting to the Senior Manager, Technology Internal Audit, you’ll help GitLab assess risk and strengthen controls across a technology landscape that includes multi-cloud infrastructure, artificial intelligence and machine learning systems, and modern development practices. This USA-based role supports our Sarbanes-Oxley Act (SOX) program while partnering with Engineering, IT Operations, Security, and business teams to build controls that work in practice, not just on paper.
You’ll execute technology audits, turn findings into practical improvements, and use data analytics, automation, and generative artificial intelligence tools to improve audit quality and efficiency. You’ll work as a trusted advisor who connects technical risks to business impact, helps leaders anticipate emerging risks, and supports remediation through closure.
What You’ll Do
- Execute technology audits covering SOX compliance, cloud infrastructure across Amazon Web Services, and Google Cloud Platform, application controls, cybersecurity, artificial intelligence and machine learning systems, and DevSecOps practices.
- Design and test IT general controls, application controls, and entity-level controls with minimal supervision.
- Support the IT SOX program from planning through reporting, including risk-based audit planning, process walkthroughs, testing, and coordination with external co-source providers.
- Maintain clear, high-quality audit documentation, including risk and control matrices, process flows, test procedures, findings, and business impact assessments.
- Own remediation efforts by partnering with process owners on practical corrective action plans, validating effectiveness before closure, and preparing status updates for leadership.
- Collaborate with Engineering, IT Operations, Security, and business process owners to assess emerging risks and evaluate new system implementations for control adequacy and SOX relevance.
- Review controls across financial statement cycles, including record to report, order to cash, hire to retire, and procure to pay, as well as third-party System and Organization Controls 1 and 2 reports.
- Use data analytics, automation, and generative artificial intelligence tools to improve audit efficiency, coverage, and quality.
What You’ll Bring
- Experience executing technology audits and risk management work in complex technology environments, including audit planning, testing, reporting, and remediation.
- Experience supporting IT SOX programs and designing and testing IT general controls and application controls.
- Knowledge of IT control frameworks such as COBIT, the National Institute of Standards and Technology framework, Information Technology Infrastructure Library, ISO 27001, and the Committee of Sponsoring Organizations of the Treadway Commission Internal Control Framework.
- Knowledge of cloud security principles and cybersecurity fundamentals, including network security, encryption, identity and access management, vulnerability management, and Zero Trust principles.
- Experience with modern development practices, including Agile and DevOps, and with data analytics and audit automation tools.
- Clear written and verbal communication skills, with the ability to explain technical findings, business impact, and practical recommendations to technical and business audiences.
- A self-directed, collaborative approach to managing multiple priorities, adapting to change, and helping teams improve their risk and control environments.
- A bachelor’s degree in Accounting, Information Technology, Computer Science, Finance, or a related field, and an active relevant professional certification such as Certified Public Accountant, Certified Internal Auditor, Certified Information Systems Auditor, Certified Information Systems Security Professional, Certified Information Security Manager, Certified in Risk and Information Systems Control, or an equivalent certification.
About the team
The Technology Internal Audit team helps GitLab understand and manage technology risk while supporting a secure and effective control environment. The team partners across Engineering, IT Operations, Security, Finance, and other business functions to support SOX compliance, assess emerging technologies, and turn audit insights into practical improvements. We work as solution-driven partners, communicate risks in business terms, build trust with stakeholders, connect audit work to GitLab’s priorities, and use technology to scale our impact.
How GitLab will support you
- Benefits to support your health, finances, and well-being
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental leave
- Home office support
The base salary range for this role’s listed level is currently for residents of the United States only. This range is intended to reflect the role's base salary rate in locations throughout the US. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, alignment with market data, and geographic location. The base salary range does not include any bonuses, equity, or benefits.