Write an IT Auditor Resume That Shows Control Testing Depth
An IT auditor resume example with SOX, ITGC and control testing keywords, plus a guide to writing findings and scope on paper.
Example IT Auditor summary
IT auditor with five years of ITGC and SOC 2 testing across banking and software clients. Leads access, change and operations testing for 14 in-scope applications, writes findings that management accepts without revision, and automated evidence pulls from Jira and Okta to cut four days of fieldwork per engagement. CISA certified and looking to move into an internal audit team with a technology focus.
Skills to list on a IT Auditor resume
- SOX ITGC testing
- SOC 2 Type II
- IT general controls
- User access reviews
- Change management control testing
- Risk and control matrices
- COBIT framework
- ISO 27001
- NIST Cybersecurity Framework
- Audit workpaper documentation
- Finding and remediation tracking
- Data analytics with Excel and SQL
- Third-party risk review
- Regulatory examination support
- Control walkthroughs
What actually gets this resume read
- Name the frameworks you tested against: SOX ITGC, SOC 2 trust services criteria, ISO 27001, NIST or PCI DSS.
- Give the scope of each engagement in applications, control counts and sample sizes, not just the client name.
- Show findings you wrote and whether management accepted them, because that is how audit quality is judged.
- Split control families out by name: access, change, operations and backup read very differently to a hiring manager.
- Put CISA prominently if you hold it, with the ISACA name, and note any progress toward it if you are studying.
- Add one bullet on data analytics or scripting, since audit teams now expect evidence work to be partly automated.