Compensation
This employer didn't list pay. Model a likely range with the calculator.
Model this offer in the calculatorJob description
Notion is the collaborative AI workspace where teams and agents think together. We're building one place where your knowledge projects meetings and AI tools live side by side so work is faster clearer and less fragmented. Millions of individuals small teams and large companies run their work on Notion.
Notinos (our employees) are customer zero in bringing this future of work to life. We care about craft building things that last and the belief that great work is still fundamentally human. Our goal isn’t to ship the next feature. Each and every team of Notinos is working to set the standard for how humans work together in the AI era. From building a business’s system of record to making and managing AI agents to automating away the busy work we care deeply about giving our customers more time for their life’s work.
About the Role:We are seeking a strategic and technically fluent Lead IT Audit to join our Finance team reporting to the Head of Internal Audit. This is a broad high-impact role spanning both IT SOX compliance and operational IT audits. You will help establish and elevate our technology controls program end to end — owning the IT SOX lifecycle designing the IT general and application controls framework embedding AI and automation into how we test and monitor controls and delivering value-added operational IT and cybersecurity audits that strengthen how the company builds and runs its systems. You will partner with leaders across Engineering Security IT Finance and the business to ensure sound technology controls are built into how the company operates as we scale. This role is ideal for someone who thinks like a builder not just an auditor — someone who can translate complex control and security requirements into practical scalable processes in a fast-moving SaaS environment with modern cloud architecture and complex data flows.
This role can be based in either San Francisco or New York City. We work from our offices on Mondays Tuesdays and Thursdays (our Anchor Days) because we do our best thinking and building together in person. We’re looking for someone who’s excited to work alongside the team during those days.
What You'll Achieve:Own the full IT SOX lifecycle — scoping risk assessment documentation walkthroughs testing deficiency evaluation remediation and reporting — driving automation and efficiency across IT general controls (ITGCs) and IT application controls (ITACs)
Design operate and continuously improve technology controls spanning user access and segregation of duties change management SDLC and CI/CD pipelines interfaces data flows and system-generated reports
Design and execute value-added operational IT and cybersecurity audits — across cloud infrastructure security operations identity and access management data protection and privacy disaster recovery and resilience and vendor and third-party risk — while driving enterprise-level technology risk assessment that anticipates emerging risks before they materialize
Serve as a strategic advisor on cross-functional initiatives (product launches new systems architecture changes M&A) and as the primary point of contact for external auditors ensuring sound controls are built in from day one and audit evidence is complete clear and timely
Own IT control deficiencies from identification through sustained remediation while partnering with and educating system owners to build a culture of ownership and accountability
Champion the adoption of AI and modern tooling — from automated control testing and anomaly detection to continuous monitoring and AI-assisted documentation — to make the IT audit function smarter faster and more forward-looking
12+ years of progressive IT audit IT SOX or technology risk experience with a combination of Big 4 and high-growth technology company experience
Deep hands-on ownership of IT SOX/ITGC programs with a strong understanding of PCAOB standards SEC requirements and frameworks such as COSO COBIT NIST and ITIL
Demonstrated experience designing and leading operational IT audits end to end — including annual planning risk-based scoping fieldwork and reporting — across areas such as IT operations infrastructure resilience disaster recovery and business continuity capacity and availability management and IT vendor and third-party risk
Strong cybersecurity audit experience with working fluency in frameworks and regulations such as NIST CSF ISO 27001 SOC 2 GDPR and CCPA and the ability to translate them into practical testable controls
Software or SaaS industry experience is a must — particularly modern cloud-based technology stacks (AWS GCP Azure) software development lifecycles and complex data flows — paired with strong technical knowledge across cloud security configurations identity and access management change management DevOps and CI/CD pipelines and enterprise IT operations risks and controls
Process leadership — a track record of building functions designing new processes and policies and driving continuous improvement
Bachelor's degree in Information Systems Computer Science Accounting or a related field; CISA CISSP CISM CIA CPA or equivalent certification required
Strong stakeholder management and communication skills with the ability to translate complex technical and audit topics into clear language and influence partners across all levels of the organization
Notion is committed to providing highly competitive cash compensation equity and benefits. The compensation offered for this role will be based on multiple factors such as location the role’s scope and complexity and the candidate’s experience and expertise and may vary from the range provided below. For roles based in San Francisco the estimated base salary range for this role is $185000 - $220000 per year.
By clicking “Submit Application” I understand and agree that Notion and its affiliates and subsidiaries will collect and process my information in accordance with Notion’s Global Recruiting Privacy Policy.
#LI-Onsite
A Note on AIYou don’t need deep AI expertise for every role but we do expect every Notino to be intellectually curious drawn to tinkering and discovery and excited to use AI as a real collaborator in their work. For some roles AI fluency is a core requirement — when that’s the case we'll say so explicitly in the qualifications. People who thrive here don’t treat AI as a novelty. They use it to think better and make their work easier for others to build on.
Equal Opportunity & AccommodationsWe hire talented people from a wide range of backgrounds. If you’re excited about this role but don’t meet every bullet we still encourage you to apply. Notion is an equal opportunity employer and does not discriminate on the basis of any legally protected characteristic. Consistent with applicable law we will consider for employment qualified applicants with arrest and conviction records. Notion provides reasonable accommodations during the application process; if you need one please let your recruiter know.
Notion is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race color religion national origin age sex (including pregnancy childbirth or related medical conditions) marital status ancestry physical or mental disability genetic information veteran status gender identity or expression sexual orientation or other applicable legally protected characteristic. Notion considers qualified applicants with criminal histories consistent with applicable federal state and local law. Notion is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability please let your recruiter know.
Skills Required
- 12+ years progressive IT audit IT SOX or technology risk experience with Big 4 and high-growth tech exposure
- Deep hands-on ownership of IT SOX/ITGC programs and strong understanding of PCAOB and SEC requirements
- Familiarity with control frameworks such as COSO COBIT NIST and ITIL
- Experience designing and leading operational IT audits end-to-end (IT operations resilience DR/BC capacity vendor risk)
- Strong cybersecurity audit experience with NIST CSF ISO 27001 SOC 2 GDPR and CCPA
- Software/SaaS industry experience with modern cloud stacks (AWS GCP Azure) SDLC complex data flows cloud security configurations IAM change management and DevOps/CI/CD
- Process leadership experience building functions processes and policies and driving continuous improvement
- Bachelor's degree in Information Systems Computer Science Accounting or related field
- Certification required: CISA CISSP CISM CIA CPA or equivalent
- Strong stakeholder management and communication skills; ability to translate technical/audit topics for executives and partners
What the Team is Saying
.jpeg)


What We Do
Notion is a collaborative AI workspace. Teams use it to store knowledge run projects take meeting notes and build AI workflows — all in one place so AI always has the context it needs to be useful.We're building the layer where AI stops being a chat window and starts being part of how work gets done. Knowledge decisions and action in one connected system.
Why Work With Us
We're building the layer where AI stops being a chat window and starts being part of how work gets done. Notion is where AI becomes useful at work: real workflows real users real context. People here move from idea to shipped without asking permission. If you want your fingerprints on work that millions of people use this is the place.
Gallery
Notion Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
Employees work in-person at our offices on Mondays Tuesdays and Thursdays. The other two days are flexible.
Similar Jobs
Notion
Customer Experience Strategy & Operations Lead
Related roles





