Internal Audit - Manager (Remote)
Fico · San Diego, CA
📍 San Diego, CAvia workdayFirst listed here 2026-09-20
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Fico.
FICO (NYSE: FICO) is a leading global analytics software company, helping businesses in 100+ countries make better decisions. Join our world-class team today and fulfill your career potential!
The Opportunity
Join our top-notch risk and assurance team within a global, fast-growing and progressive data analytics and cutting-edge AI oriented software company. If you’re eager to feel empowered and apply your creativity and experience in a way that adds value and serves to mitigate business risks across the enterprise, this is the opportunity for you. This is a hands-on lead role. You will own the IT audit coverage for a defined portfolio of FICO’s financial applications, cloud platforms and security tooling — running engagements end to end, setting the testing approach, and raising the bar on how we use data, automation and AI to get assurance.
What You’ll Contribute
Lead IT audit engagements end to end with limited supervision — scoping and risk assessment, walkthroughs, design and operating effectiveness testing, issue development, and remediation validation.
Own the Sarbanes-Oxley Section 404 (SOX 404) IT general controls program for an assigned portfolio of in-scope financial applications and supporting infrastructure, spanning access to programs and data, change management, program development, and IT operations.
Test IT application controls, key reports, interfaces and system-generated data supporting financial reporting across our ERP and other in-scope financial applications.
Perform annual and ad-hoc segregation of duties (SoD) analysis. This is data-driven work: extracting role and entitlement data from source systems, normalizing and deduplicating it, applying and maintaining a conflict ruleset, identifying conflicting access combinations and privileged access exceptions, and working with process owners to validate, justify or remediate what surfaces. A standing goal for this role is to automate the extraction, normalization and comparison steps so the analysis becomes a repeatable, monitorable process rather than a once-a-year manual exercise.
Audit identity and access management across the enterprise — directory services, enterprise single sign-on, identity governance and access certification platforms, and privileged access and secrets management tooling (password vaults and safes) — covering joiner/mover/leaver provisioning, privileged access, and periodic user access reviews.
Evaluate change and release management controls across modern DevOps toolchains — Git-based source control, CI/CD pipelines, and IT service management platforms such as Jira and ServiceNow — including automated approvals and separation of duties between development and production.
Assess controls over cloud infrastructure and enterprise data platforms, covering configuration, encryption, logging and monitoring, and data pipeline integrity.
Perform cybersecurity and cloud security assessments across FICO’s SaaS product environments that hold sensitive client data.
Support third-party risk and service organization report reviews — evaluating SOC 1 and SOC 2 reports, transcribing and mapping complementary user entity controls (CUECs) to FICO controls, and assessing subservice organization coverage and bridge letters.
Contribute to emerging-risk coverage as FICO’s use of AI expands, including AI and model governance controls evaluated against frameworks such as the NIST AI Risk Management Framework and ISO/IEC 42001.
Apply data analytics and AI-assisted tooling to audit work — scripted population extraction, full-population testing where practical, and automated continuous monitoring — rather than defaulting to manual sampling.
Prepare clear, well-supported work papers; summarize findings and review them with the Chief Audit Executive and/or the Senior Manager, IT Risk & Assurance.
Act as the liaison between our external auditors and internal stakeholders across a wide variety of topics and projects. This means coordinating IT scoping and walkthroughs, owning evidence and PBC requests end to end, supporting reliance discussions on internal audit work, translating external auditor expectations into practical asks for system and process owners, and tracking open items through to closure so neither side is left waiting.
Partner with IT, Engineering, Security, Finance and business process owners so that population and sample requests are identified, communicated and retrieved efficiently.
Drive improvement of FICO’s internal control structure through practical control design and process enhancement recommendations.
Coach and review the work of junior auditors and co-sourced resources, and help maintain testing standards, templates and documentation quality across the team.
Proactively keep leadership informed of progress, control weaknesses and audit findings; meet established deadlines while maintaining confidentiality when dealing with sensitive information and situations.
What We’re Seeking
Bachelor’s degree in information technology, information systems, computer science, accounting or a related field; equivalent practical experience will be considered.
Approximately 3–5 years of progressive IT audit experience — public accounting, a national firm, or corporate internal audit at a technology, SaaS or financial services company. At least 3 years is recommended, including meaningful exposure to owning or leading ITGC and SOX 404 testing rather than executing someone else’s test steps.
Hands-on experience testing IT general and application controls over a major ERP — Oracle strongly preferred, SAP, NetSuite or comparable also valued — and over cloud-hosted business applications such as HCM, CRM, revenue and data warehouse platforms.
Real enthusiasm for using AI and automation to change how audit work gets done. Our team uses Claude daily and is actively building AI-assisted workflows: drafting and rolling forward testing narratives, mapping SOC report CUECs
More San Diego, CA jobs
San Diego, CA jobs · Browse all locations