IT Auditor

EastmanKingsport, TN
Onsite

About The Position

The Information Technology (IT) Auditor plays a key role on Eastman’s Internal Audit team, executing risk-based audits that evaluate the design and effectiveness of information technology controls across the enterprise. The IT Auditor leads or supports engagements spanning IT general controls, Sarbanes-Oxley (SOX) compliance, cybersecurity, and IT-dependent business processes. This role calls for someone who brings 3+ years of relevant experience, strong analytical thinking, and the ability to communicate clearly with both technical and non-technical stakeholders. The IT Auditor also contributes to department-wide process improvement, mentors team members, and helps advance Eastman’s use of AI, data analytics and automation within the audit function. The primary role of an Information Technology (IT) Auditor is to execute various audit engagements in a lead or support position. Audit execution involves scoping, planning, testing, identification of issues, and reporting. The IT Auditor may have a primary focus on IT business processes and/or Sarbanes-Oxley (SOX) areas. Even though the audit execution process has a defined framework, each audit and process owner are unique, so the ability to respond appropriately to varying situations and environments is important. The IT Auditor engages in various projects in support of Eastman’s Internal Audit process improvement and special requests.

Requirements

  • Bachelor’s degree in Information Systems, Accounting, Finance, Computer Science, or a related field.
  • 3+ years of progressive experience in IT audit, public accounting, internal audit, related risk/controls function or related IT experience.
  • Solid understanding of IT general controls, application controls, and SOX compliance requirements.
  • Working knowledge of the IIA International Standards for the Professional Practice of Internal Auditing.
  • Familiarity with one or more IT governance and control frameworks such as COBIT, NIST CSF, or ISO 27001.
  • Demonstrated ability to plan and execute audit engagements, manage time across multiple priorities, and meet deadlines with limited supervision.
  • Strong interpersonal skills with the ability to build and maintain effective working relationships across all levels of the organization.
  • Excellent written and verbal communication skills, including the ability to present complex technical issues to non-technical audiences clearly and concisely.
  • Proficiency with Microsoft Office applications and experience with data analytics or audit management software (e.g., ACL, IDEA, Power BI, Tableau, or similar tools).
  • Willingness to travel up to approximately 10–15%, primarily domestic.

Nice To Haves

  • Professional certification or active pursuit of certification such as CISA (Certified Information Systems Auditor), CIA (Certified Internal Auditor), CISSP, or CRISC.
  • Experience auditing cloud environments, cybersecurity programs, or operational technology (OT) systems.
  • Experience auditing ERP environments (SAP preferred), operating systems, databases, and network security controls.
  • Exposure to data analytics and continuous auditing techniques, including scripting or query languages such as SQL or Python.
  • Experience working within a manufacturing or chemical industry environment.

Responsibilities

  • Executing audits according to departmental guidelines, including Institute of Internal Auditors (IIA) standards, to assess the adequacy and effectiveness of internal controls, validate compliance with corporate procedures, and address potential risks.
  • Planning, scoping, and executing tasks required to complete audits as defined in lead or support auditor roles.
  • Conducting audit procedures such as leading interviews, requesting and analyzing evidence, and documenting test steps in detailed, well-supported work papers.
  • Evaluating the design and operating effectiveness of IT general controls (ITGCs), application controls, and key interfaces across platforms including ERP systems, operating systems, databases, and network infrastructure.
  • Assessing IT governance, risk management, and cybersecurity controls against established frameworks (e.g., COBIT, NIST, ISO 27001).
  • Identifying and evaluating audit issues and gaps using a risk-based approach.
  • Meeting with process management to discuss audit findings and gaining agreement on management action plans.
  • Partnering with audit clients to identify constructive, value-added solutions that address issues identified.
  • Coordinating business process audit testing with SOX testing to increase productivity and reduce duplication of effort.
  • Performing issue remediation follow-up and testing to validate that management action plans have been effectively implemented.
  • Performing process assessments and providing advisory services as requested by clients.
  • Developing relationships with primary contacts for focus areas.
  • Sharing process knowledge and key learnings with other audit team members.
  • Contributing toward departmental projects and initiatives.
  • Identifying opportunities to improve departmental processes and support corporate strategy.
  • Finding improvement opportunities where automation and data analytic tools could streamline procedures and enhance analysis of results.
  • Identifying and communicating IT audit findings to senior management.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service