As passionate about our people as we are about our mission.
Why Join Q2?
Q2 is a leading provider of digital banking and lending solutions to banks, credit unions, alternative finance companies, and fintechs in the U.S. and internationally. Our mission is simple: build strong and diverse communities through innovative financial technology—and we do that by empowering our people to help create success for our customers.
What Makes Q2 Special?
Being as passionate about our people as we are about our mission. We celebrate our employees in many ways through our year-round Q2 ChangeMakers awards program and global moments of recognition and connection. We invest in the growth and development of our team members through ongoing learning opportunities, internal mobility, and meaningful leadership relationships. We also know that nothing builds trust and collaboration like having fun and giving back together. From company-wide volunteer days to events like our Q2 Homecoming Week—featuring learning, community service, and culture-building experiences—we create opportunities to connect, grow, and make an impact.
SUMMARY
This position is an individual contributor within the Internal Audit Team responsible for leading and executing high-impact, risk-based IT audit engagements aligned with regulatory frameworks (e.g., SOX, FFIEC, NIST) and organizational priorities. The ideal candidate will possess extensive experience auditing complex IT environments, supported by a strong foundation in cybersecurity, IT governance, and technology risk. They should have proven expertise in independently leading audit walkthroughs, managing stakeholder relationships end-to-end, coordinating and communicating audit requests effectively, and driving collaboration to ensure audits are executed efficiently and deliver value-added insights and outcomes.
This role contributes to the annual IT audit plan by assessing risk, planning and scoping audits, and delivering assurance and advisory services across areas including financial reporting, cloud computing (mainly Azure and AWS), data protection, third-party risk, and IT operations. The Senior IT Internal Auditor will collaborate with stakeholders across Accounting, Technology, Information Security, Risk, and Compliance to drive risk mitigation and control improvement efforts.
RESPONSIBILITIES:
- Execute SOX IT and information systems testing program, including conducting walkthroughs, understand processes and procedures, policies, analysing audit evidence, executing controls testing, identifying and defining issues or recommendations, effectively communicating and managing stakeholders of audit program and manage the documentation at each step of audit phases.
- Experience in conducting Audits that involve IT Technical areas such as IT Infrastructure controls around network security, business resiliency (BCP/DR), configuration management, AWS/Azure Cloud infrastructure and security controls along with basic Cybersecurity related controls in line with NIST framework.
- Support the creation of status reports and planning materials assist with overall and collaborate closely with internal and external stakeholders for the IT Program. Perform the end-to-end planning, execution, and reporting with the IT Internal Audit Manager of risk-based IT audit engagements across domains such as:
- Information Security Program
- Network & System Security
- Business Continuity and Disaster Recovery (BC/DR)
- Change Management and Software Development Lifecycle (SDLC)
- Cloud Security Controls (specifically Azure and AWS)Identity & Access Management (I&AM)
- IT Operations and Asset Management
- Privacy and Data Protection
- Third-Party Risk Management (TPRM)
- Evaluate IT risks, control maturity, and alignment with regulatory expectations.
- Provide risk advisory and control consultation to IT and business leadership on strategic technology initiatives, regulatory obligations, and emerging threats.
- Collaborate closely with cross-functional stakeholders, including Accounting, Information Security, Compliance, Legal, and Engineering teams, to understand business processes and evaluate control effectiveness.
- Develop and deliver clear, concise, risk-focused audit reports dealing with complex and sensitive issues, including findings, root cause analysis, and actionable, in a timely manner for internal and external audiences..
- Complete assigned responsibilities following audit standards.
- Partner with internal and external audit teams to ensure a timely and efficient testing approach and issue resolution.
- Monitor and validate the implementation of management action plans and ensure sustainable remediation of control issues.
- Support new system implementations and ensure compliance with existing policies
- Conduct risk assessments, including the identification of controls and testing attributes.
- Contribute to the development and evolution of the IT audit program, including risk assessment methodology, audit universe updates, and use of data analytics.
- Act as a key liaison to internal and external auditors, examiners, and other assurance functions to ensure coordinated risk coverage and alignment.
- Excellent time management and organizational skills, with the ability to support multiple projects, work both independently and collaboratively within the team and effectively prioritize and manage a large volume of work
EDUCATIONAL REQUIREMENT & QUALIFICATION:
- Bachelor’s degree with 5-8 years of experience in IT audit, internal audit, cybersecurity, financial services, or a related business function
- 3+ years of direct experience in IT Audit for a SaaS company or equivalent IT audit experience at a top-tier firm (Big 4, RSM, Protiviti, etc.)
- 2+ years of experience leading end-to-end engagements and/or leadership experience within the information technology or security fields.
- Certifications combined with hands on experience in AWS/Azure cloud infrastructure and security.
- Certifications combined with hands on experience in Cybersecurity Auditing against popular frameworks such as NIST CSF.
- Demonstrated knowledge of internal controls, business risks and audit techniques in a large SaaS organization
- Demonstrated knowledge of SOC1 and SOC2 requirements
- Knowledge of data analytics tools such as ACL, Power BI, or Tableau and proficiency in Microsoft Excel, Word, Outlook, used for issue identification and trend monitoring.
- Experience with AuditBoard or other audit engagement support tools
- Maintains other designations including Certified Management Accountant (CMA), Certified Fraud Examiner (CFE), Certified Information Security Systems Professional (CISSP), Certified Financial Services Auditor (CFSA), or other relevant business designation.
- Strong knowledge of internal audit methodologies, including experience leading audit projects in accordance with the Institute of Internal Auditors (IIA) Global Standards.
- Superior interpersonal, written, and verbal communication skills, with the ability to create thorough documentation and interface effectively with individuals at various levels.
- Ability to remain organized, pay strict attention to detail, and meet critical deadlines within a high volume, fast-paced environment.
This position requires fluent written and oral communication in English.
Health & Wellness
Hybrid Work Opportunities
Flexible Time Off
Career Development & Mentoring Programs
Health & Wellness Benefits, including competitive health insurance offerings and generous paid parental leave for eligible new parents
Community Volunteering & Company Philanthropy Programs
Employee Peer Recognition Programs – “You Earned it”
Click here to find out more about the benefits we offer.
Our Culture & Commitment:
We’re proud to foster a supportive, inclusive environment where career growth, collaboration, and wellness are prioritized. And our benefits go beyond healthcare—offering resources for physical, mental, and professional well-being. Click here to find out more about the benefits we offer. Q2 employees are encouraged to give back through volunteer work and nonprofit support through our Spark Program (see more). We believe in making an impact—in the industry and in the community.
We are an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, or veteran status.