Senior IT Auditor
Regeneron
August 29, 2026
On-site
Sleepy Hollow, NY
IT
Responsibilities:
- Contribute to planning, executing, and reporting on operational IT audits by evaluating risks and controls across applications, infrastructure, cloud, data management, SDLC, change management, and IT operations in accordance with IIA standards.
- Perform IT SOX control walkthroughs and testing; prepare related documentation.
- Assess cybersecurity control effectiveness, including identity and access management, vulnerability management, logging/monitoring, incident response, and security governance.
- Review controls for cloud (e.g., AWS, Azure), SaaS, data lakes, and analytics environments, including shared responsibility models.
- Design and execute data analytics-driven audit procedures (e.g., Dataiku or equivalent) to identify anomalies, trends, and control gaps.
- Apply automation, continuous auditing, and responsible use of AI to improve audit efficiency and insight, including AI-enabled process/control assessment.
- Manage timely completion of audit tasks; communicate status to auditees and Internal Audit leadership.
- Identify, document, and communicate control deficiencies, root causes, technology risks, and improvement opportunities; provide actionable recommendations.
- Present audit results and prepare clear, concise audit reports and executive-level presentations.
Qualifications:
- Bachelorβs degree; 3β4 years progressive experience in IT audit, information security, or technology risk.
- Preferred: CISA, CISM and/or CISSP; experience auditing/evaluating infrastructure, cybersecurity controls, and operating systems.
- Strong understanding of SOX, COSO, COBIT, NIST, GxP, GDPR, and other governance frameworks.
- Strong analytical, critical-thinking, problem-solving, and independent risk assessment skills.
- Experience with data analytics tools (e.g., Dataiku, Alteryx).
- Understanding of AI concepts and related risks (model governance, data quality, access, ethical use) and internal controls for AI-enabled processes.
- Strong communication, writing, organization, and attention to detail; comfortable working independently and in a team.
- Strongly preferred: pharmaceutical/life sciences or other regulated industry experience; Big 4/public accounting preferred but not required.
Application:
- Apply now.
- Contribute to planning, executing, and reporting on operational IT audits by evaluating risks and controls across applications, infrastructure, cloud, data management, SDLC, change management, and IT operations in accordance with IIA standards.
- Perform IT SOX control walkthroughs and testing; prepare related documentation.
- Assess cybersecurity control effectiveness, including identity and access management, vulnerability management, logging/monitoring, incident response, and security governance.
- Review controls for cloud (e.g., AWS, Azure), SaaS, data lakes, and analytics environments, including shared responsibility models.
- Design and execute data analytics-driven audit procedures (e.g., Dataiku or equivalent) to identify anomalies, trends, and control gaps.
- Apply automation, continuous auditing, and responsible use of AI to improve audit efficiency and insight, including AI-enabled process/control assessment.
- Manage timely completion of audit tasks; communicate status to auditees and Internal Audit leadership.
- Identify, document, and communicate control deficiencies, root causes, technology risks, and improvement opportunities; provide actionable recommendations.
- Present audit results and prepare clear, concise audit reports and executive-level presentations.
Qualifications:
- Bachelorβs degree; 3β4 years progressive experience in IT audit, information security, or technology risk.
- Preferred: CISA, CISM and/or CISSP; experience auditing/evaluating infrastructure, cybersecurity controls, and operating systems.
- Strong understanding of SOX, COSO, COBIT, NIST, GxP, GDPR, and other governance frameworks.
- Strong analytical, critical-thinking, problem-solving, and independent risk assessment skills.
- Experience with data analytics tools (e.g., Dataiku, Alteryx).
- Understanding of AI concepts and related risks (model governance, data quality, access, ethical use) and internal controls for AI-enabled processes.
- Strong communication, writing, organization, and attention to detail; comfortable working independently and in a team.
- Strongly preferred: pharmaceutical/life sciences or other regulated industry experience; Big 4/public accounting preferred but not required.
Application:
- Apply now.