Role in brief
Notion is looking for a Lead, IT Audit and Technology Risk to manage IT SOX compliance and conduct operational IT audits. This role involves ensuring technology controls and cybersecurity in a SaaS environment. Candidates with extensive IT audit experience, including Big 4 and high-growth tech companies, who can drive automation and advise on strategic initiatives, should apply.
About the role
This role focuses on leading the entire IT SOX lifecycle, from risk assessment and documentation to testing and reporting. The successful candidate will be responsible for designing, operating, and enhancing technology controls related to user access, change management, and CI/CD pipelines. A key aspect is driving efficiency and automation within IT general controls and application controls.
The position also involves designing and executing operational IT and cybersecurity audits across various domains, including cloud infrastructure, security operations, and data protection. The lead will conduct enterprise-level technology risk assessments to proactively identify emerging risks. This role requires a strategic mindset to advise on cross-functional initiatives and act as the main contact for external auditors.
Success in this role means owning IT control deficiencies from identification through remediation, partnering with system owners to foster a culture of accountability. The lead will champion the adoption of AI and modern tools for automated control testing, continuous monitoring, and AI-assisted documentation, aiming to make the IT audit function more efficient and forward-looking.
The estimated base salary range for this role, if based in San Francisco, is between $185,000 and $220,000 per year.
Skills that matter here
- IT audit: This role requires extensive experience in IT audit, including leading operational audits and managing the full IT SOX lifecycle.
- IT SOX: The candidate will own the entire IT SOX program, from scoping to reporting, ensuring compliance with PCAOB standards and SEC requirements.
- cloud security: The role involves auditing cloud security configurations and understanding modern cloud-based technology stacks like AWS, GCP, and Azure.
- cybersecurity: The lead will design and execute cybersecurity audits, translating frameworks like NIST CSF and ISO 27001 into practical controls.
- AWS: Experience with AWS is necessary for understanding and auditing cloud security configurations and modern technology stacks.
- DevOps: The role requires knowledge of DevOps and CI/CD pipelines to design and improve technology controls and audit software development lifecycles.
Who this role suits
- A candidate with a background in both Big 4 and high-growth technology companies.
- Someone who can translate complex technical and audit topics into clear language for various stakeholders.
- An individual who excels at building functions, designing new processes, and driving continuous improvement.
- A person who can proactively identify emerging technology risks and advise on strategic initiatives.
From the employer
What You'll Achieve:
- Own the full IT SOX lifecycle — scoping, risk assessment, documentation, walkthroughs, testing, deficiency evaluation, remediation, and reporting — driving automation and efficiency across IT general controls (ITGCs) and IT application controls (ITACs)
- Design, operate, and continuously improve technology controls spanning user access and segregation of duties, change management, SDLC and CI/CD pipelines, interfaces, data flows, and system-generated reports
- Design and execute value-added operational IT and cybersecurity audits — across cloud infrastructure, security operations, identity and access management, data protection and privacy, disaster recovery and resilience, and vendor and third-party risk — while driving enterprise-level technology risk assessment that anticipates emerging risks before they materialize
- Serve as a strategic advisor on cross-functional initiatives (product launches, new systems, architecture changes, M&A) and as the primary point of contact for external auditors, ensuring sound controls are built in from day one and audit evidence is complete, clear, and timely
- Own IT control deficiencies from identification through sustained remediation while partnering with and educating system owners to build a culture of ownership and accountability
- Champion the adoption of AI and modern tooling — from automated control testing and anomaly detection to continuous monitoring and AI-assisted documentation — to make the IT audit function smarter, faster, and more forward-looking
Skills You'll Need to Bring:
- 12+ years of progressive IT audit, IT SOX, or technology risk experience, with a combination of Big 4 and high-growth technology company experience
- Deep, hands-on ownership of IT SOX/ITGC programs, with a strong understanding of PCAOB standards, SEC requirements, and frameworks such as COSO, COBIT, NIST, and ITIL
- Demonstrated experience designing and leading operational IT audits end to end — including annual planning, risk-based scoping, fieldwork, and reporting — across areas such as IT operations, infrastructure resilience, disaster recovery and business continuity, capacity and availability management, and IT vendor and third-party risk
- Strong cybersecurity audit experience with working fluency in frameworks and regulations such as NIST CSF, ISO 27001, SOC 2, GDPR, and CCPA, and the ability to translate them into practical, testable controls
- Software or SaaS industry experience is a must — particularly modern cloud-based technology stacks (AWS, GCP, Azure), software development lifecycles, and complex data flows — paired with strong technical knowledge across cloud security configurations, identity and access management, change management, DevOps and CI/CD pipelines, and enterprise IT operations risks and controls
- Process leadership — a track record of building functions, designing new processes and policies, and driving continuous improvement
- Bachelor's degree in Information Systems, Computer Science, Accounting, or a related field; CISA, CISSP, CISM, CIA, CPA, or equivalent certification required
- Strong stakeholder management and communication skills, with the ability to translate complex technical and audit topics into clear language and influence partners across all levels of the organization
What the Company Offers:
- Notion is committed to providing highly competitive cash compensation, equity, and benefits.
- The compensation offered for this role will be based on multiple factors such as location, the role’s scope and complexity, and the candidate’s experience and expertise, and may vary from the range provided below.
- For roles based in San Francisco, the estimated base salary range for this role is $185,000 - $220,000 per year.
Questions about this role
What is the seniority level for this position?
This is a Lead-level position.
What is the remote work policy for this role?
This role is fully remote, but the salary range provided is specifically for roles based in San Francisco.
What certifications are required for this role?
A CISA, CISSP, CISM, CIA, CPA, or equivalent certification is required.