The Team
You will join our Global Internal Audit team, partnering with technology, cybersecurity, privacy, compliance, and business stakeholders across the organization. The team provides independent assurance on technology risks and controls while supporting the company's transformation across cloud, cybersecurity, artificial intelligence, privacy, and digital innovation initiatives. We operate in a collaborative environment that values curiosity, continuous learning, and practical solutions to complex technology challenges As a Senior IT Auditor, you will independently execute risk-based IT audit engagements across SOX 404 IT General Controls (ITGCs), application controls, cybersecurity, cloud technologies, privacy, artificial intelligence (AI), Generative AI (GenAI), and technology governance domains.Working under the direction of the Lead IT Auditor, you will perform audit planning, risk assessments, control testing, reporting, and remediation validation activities while partnering with global stakeholders to strengthen governance, risk management, and compliance across the organization. Your Responsibilities- Execute risk-based IT audit engagements from planning through reporting and remediation validation.
- Perform SOX 404 IT General Controls (ITGC) testing covering access management, segregation of duties, change management, computer operations, and software development lifecycle (SDLC) controls.
- Conduct application control testing supporting financial and operational business processes.
- Evaluate the design and operating effectiveness of technology, cybersecurity, and privacy controls.
- Assess cybersecurity controls aligned with NIST Cybersecurity Framework (CSF), ISO 27001, CIS Controls, and COBIT.
- Review governance and controls related to identity and access management (IAM), privileged access management (PAM), cloud security, vulnerability management, incident response, and technology operations.
- Assess privacy and data governance controls related to data classification, retention, protection, and regulatory compliance.
- Evaluate governance, risk management, and control frameworks for AI, Generative AI, and emerging technologies, including alignment to Responsible AI principles and ISO 42001.
- Review SOC 1 and SOC 2 Type II reports and assess third-party technology and cloud service provider risks.
- Collaborate with internal stakeholders and external auditors to support compliance, audit coordination, and remediation activities.
- Prepare clear, concise, and actionable audit reports for management and senior leadership.
- Contribute to the continuous enhancement of audit methodologies, automation, analytics, and risk assessment practices.
Who are you?
You are an experienced IT audit professional who enjoys understanding complex technology environments and translating technical risks into practical business insights. You bring strong audit execution skills, sound professional judgment, and the ability to build productive relationships across global teams. To be successful in this role, you will have:
- A bachelor's degree in Information Systems, Information Technology, Computer Science, Cybersecurity, Accounting Information Systems, or a related field.
- 5+ years of IT audit experience within a Big Four or national public accounting firm or experience in Internal IT Audit, Technology Risk Management, Cybersecurity Assurance, Risk & Compliance, or related disciplines.
- Experience executing audit engagements through planning, fieldwork, reporting, and remediation follow-up activities.
- Strong knowledge of SOX 404 compliance, including IT General Controls (ITGCs), automated controls, and application controls testing.
- Experience auditing enterprise applications, cloud environments, technology operations, databases, and IT processes.
- Experience conducting cybersecurity risk assessments, technology governance reviews, compliance assessments, and privacy reviews.
- Professional certification such as CISA or CISSP.
- Knowledge of industry frameworks including NIST, ISO/IEC 27001, CIS Controls, COBIT, ISO 27701, and ISO 42001.
- Experience reviewing SOC 1 and SOC 2 Type II reports.
- Understanding of cloud security and governance controls within Microsoft Azure and AWS environments.
- Familiarity with DevOps practices, CI/CD pipelines, and modern software development methodologies.
- Understanding of AI governance, Generative AI risks, Responsible AI principles, and large language model technologies.
- Experience using data analytics techniques and audit management platforms such as AuditBoard or similar solutions.
HERE is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, age, gender identity, sexual orientation, marital status, parental status, religion, sex, national origin, disability, veteran status, and other legally protected characteristics.
Who are we?
HERE Technologies is a location data and technology platform company. We empower our customers to achieve better outcomes – from helping a city manage its infrastructure or a business optimize its assets to guiding drivers to their destination safely.
At HERE we take it upon ourselves to be the change we wish to see. We create solutions that fuel innovation, provide opportunity and foster inclusion to improve people’s lives. If you are inspired by an open world and driven to create positive change, join us. Learn more about us on our YouTube Channel.
Skills Required
- Bachelor’s degree in Information Systems, Information Technology, Computer Science, Cybersecurity, Accounting Information Systems, or a related field
- 5+ years of IT audit experience in Big Four or national public accounting, Internal IT Audit, Technology Risk Management, Cybersecurity Assurance, Risk and Compliance, or a related discipline
- Experience executing audit engagements through planning, fieldwork, reporting, and remediation follow-up
- Strong knowledge of SOX 404 compliance, IT General Controls, automated controls, and application controls testing
- Experience auditing enterprise applications, cloud environments, technology operations, databases, and IT processes
- Experience conducting cybersecurity risk assessments, technology governance reviews, compliance assessments, and privacy reviews
- Professional certification such as CISA or CISSP
- Knowledge of NIST, ISO/IEC 27001, CIS Controls, COBIT, ISO 27701, and ISO 42001
- Experience reviewing SOC 1 and SOC 2 Type II reports
- Understanding of cloud security and governance controls in Microsoft Azure and AWS environments
- Familiarity with DevOps practices, CI/CD pipelines, and modern software development methodologies
- Understanding of AI governance, Generative AI risks, Responsible AI principles, and large language model technologies
- Experience using data analytics techniques and audit management platforms such as AuditBoard or similar solutions
HERE Technologies Compensation & Benefits Highlights
-
Healthcare Strength — Health coverage is described as solid, with employer-verified medical, dental, vision, and mental-health/EAP resources. Public benefits materials consistently reference robust core coverage.
-
Leave & Time Off Breadth — Vacation/PTO is employer-verified, and programs like sabbatical and volunteer time off are highlighted in company-facing summaries. These options indicate a broad time-off offering.
-
Flexible Benefits — Work-from-home and hybrid arrangements are employer-verified, with many U.S. teams operating on a hybrid schedule. Flexibility features prominently in the total-rewards framing.
HERE Technologies Insights
What We Do
HERE Technologies is a location data and technology company that created the first digital map over 35 years ago. Today we are the world's leading location platform company with a global footprint across 52 countries. Although our strongest presence is in the automotive industry, we also work with leading companies across a wide range of industries, including transport and logistics, mobility, manufacturing and retail and the public sector.
Why Work With Us
At HERE, we're always excited about discovering people who share our passion for building innovative solutions that make the world easier to navigate. We believe our success is powered by our team's diversity, creativity and collaboration and we're always looking for opportunities to grow it further.
Gallery
HERE Technologies Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.

