IT Audit Principal

epicorsoftware· EPIC Epicor Software
Apply Now ↗
📍 US, Austin Las CimasFull time
Full timeOnsiteEPIC Epicor Software

About this role

As an IT Audit Principal, you will lead and execute complex internal IT audits across a variety of technology environments, including cloud and on-premises infrastructure, with a focus on Cybersecurity, IT General Controls (ITGCs), and Application Controls. You will assess control design and operating effectiveness, evaluate technology and security risks, identify control gaps and root causes, and provide practical recommendations that strengthen the organization overall control environment.

In this role, you will serve as an independent and objective advisor, partnering with leaders across IT, Security, Finance, HR, and external audit teams. You will apply deep subject matter expertise through hands-on control evaluations, support major transformation initiatives, and advise leadership on effective ways to manage risk. We are seeking applicants with strong technical knowledge, sound judgment, and the ability to turn complex findings into clear actions that support a strong and sustainable control environment.

What you'll be doing

  • Lead internal IT audit engagements from planning through reporting, including risk assessment, control evaluation, stakeholder communication, and remediation monitoring.
  • Conduct cybersecurity audits using a comprehensive, risk-based approach to assess the design and effectiveness governance, risk management, and control processes established across key areas such as identity and access management, security monitoring, privileged access, vulnerability management, incident response, and other relevant cybersecurity domains.
  • Lead evaluations of cybersecurity programs and controls against established frameworks and standards such as NIST and ISO 27001, in alignment with the Internal Audit plan and business risk priorities.
  • Conduct ITGC SOX audits to assess the design and operating effectiveness of controls across key areas such as access management, change management, IT operations, interfaces, backups, and disaster recovery.
  • Evaluate System Development Life Cycle (SDLC) controls for major implementations, upgrades, and transformation, including project governance, requirements and design, user acceptance testing (UAT), data conversion, access and security, deployment readiness, and post implementation.
  • Provide thought leadership in the continuous development and execution of the risk based internal audit plan, supporting enterprise risk assessments, audit
  • prioritization, scoping, and coordination across IT, SOX, and operational audit actives.
  • Partner with GRC, security, and technology teams to evaluate risks across cloud, infrastructure, and application environments and assess whether key controls are appropriately designed and operating effectively.
  • Act as a liaison to external auditors for ITGC and cybersecurity-related audits, ensuring alignment and timely communication of findings.
  • Lead and perform root cause analysis and provide recommendations for control deficiencies, including those related to cybersecurity incidents and/or control gaps.
  • Develop, review, and maintain IT control documentation, including process flows, narratives, and control matrices, and ensuring alignment with both SOX and cybersecurity requirements.
  • Enable continuous improvement initiatives across IT Audit and cybersecurity programs, including automation and deployment of new technologies.
  • Support executive leadership with special project advisory that inform strategic initiatives, risk assessments, and special transformational projects as needed.
  • Build and leverage AI solutions and workflows to enable capacity or unlock capability for an Internal Audit function.

What you'll likely bring

  • 8+ years of progressive experience in IT audit, IT compliance, SOX, and/or cybersecurity risk management (public accounting and/or industry). Big 4 is a plus.

  • Specialized experience in the Software industry.

  • Bachelor’s degree in Information Systems, Cybersecurity, Accounting, Finance, or related field.

  • Relevant certifications such as CISA, CISSP, CISM, CRISC, CIA, or CPA (or equivalent).

What can set you apart

  • Deep experience performing cybersecurity audits.
  • Strong knowledge of ITGC domains (Access Management, Change Management, Interfaces, Backups, Disaster Recovery), SDLC, and their intersection with cybersecurity controls.
  • Deep experience auditing systems such as SalesForce, Workday, Kinetic, Microsoft Azure (Entra ID), Active Directory, and different types of cloud environments (IaaS, PaaS, and SaaS).
  • Strong understanding of SOX requirements (e.g. 302, 404), principles-based internal control-integrated framework (COSO), IT Frameworks (e.g., COBIT) and cybersecurity control frameworks (e.g., NIST CSF, ISO 27001, CIS Critical Security Controls).
  • Experience leveraging automation and tools such as Workiva’s Wdesk and AI tools (ChatGPT, Copilot, Claude, etc.).
  • Excellent communication and stakeholder management skills, with the ability to influence at all levels of the organization.

#LI-CM1

#HYBRID

About Epicor 

At Epicor, we’re truly a team. Join 5,000 talented professionals in creating a world of better business through data, AI, and cognitive ERP. We help businesses stay future-ready by connecting people, processes, and technology. From software engineers who command the latest AI technology to business development reps who help us seize new opportunities, the work we do matters. Together, Epicor employees are creating a more resilient global supply chain. 

We’re Proactive, Proud, Partners.  


Whatever your career journey, we’ll help you find the right path. Through our training courses, mentorship, and continuous support, you’ll get everything you need to thrive. At Epicor, your success is our success. And that success really matters, because we’re the essential partners for the world’s most essential businesses—the hardworking companies who make, move, and sell the things the world needs.

Competitive Pay & Benefits 

  • Health and Wellness: Comprehensive health and wellness benefits designed to support your overall well-being. 

  • Internal Mobility: Opportunities for mentorship, continuing education, and focused career goal setting, with 25% of positions filled internally. 

  • Career Development: Free LinkedIn Learning licenses for everyone, along with our Mentoring Program to boost your personal development. 

  • Education Support: Geographically specific programs to balance the cost of education with the benefits of continued learning and personal development. 

  • Inclusive Workplace: Collaborate with a diverse team in an inclusive, global workplace that fosters innovation and celebrates partnership. 

  • Work-Life Balance: Policies built on mutual trust and support, encouraging time off to rest, recharge, and reconnect. 

  • Global Mobility: Comprehensive support for international relocations and permanent residency processes.  

Equal Opportunities and Accommodations Statement 

Epicor is committed to creating a workplace and global community where inclusion is valued; where you bring the whole and real you—that’s who we’re interested in. If you have interest in this or any role- but your experience doesn’t match every qualification of the job description, that’s okay- consider applying regardless.  

We are an equal-opportunity employer.  

Recruiter:

Christi McCall

Frequently Asked Questions

Is the salary disclosed for the IT Audit Principal position at epicorsoftware?
The salary for this IT Audit Principal role at epicorsoftware is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the IT Audit Principal position at epicorsoftware located?
This IT Audit Principal role at epicorsoftware is based in US, Austin Las Cimas. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the IT Audit Principal role at epicorsoftware full-time or part-time?
This is listed as a Full time position. It is posted as a IT Audit Principal role in the EPIC Epicor Software department at epicorsoftware.
Which team or department does the IT Audit Principal at epicorsoftware belong to?
This IT Audit Principal position is part of the EPIC Epicor Software department at epicorsoftware. See the full job description for more information about the team structure and responsibilities.
How do I apply for the IT Audit Principal position at epicorsoftware?
Click the "Apply Now" button on this page. You will be redirected to epicorsoftware's official application portal hosted on workday where you can submit your application directly.
When was the IT Audit Principal job at epicorsoftware posted?
This IT Audit Principal position at epicorsoftware was posted on Aug 4, 2026. Apply as soon as possible — early applications are often reviewed first.
IT Audit Principal
epicorsoftware
Apply for this role ↗

You'll be redirected to epicorsoftware's official application page on Workday.