Sr IT Auditor
Regeneron
- Location
- Hyderabad
- Work model
- On-Site
- Level
- Senior
- Posted
- 16h ago
Skills
About this role
Build our future together: At Regeneron, we use science and innovation to develop life-changing medicines for people with serious diseases. We are seeking a Senior IT Internal Audit Compliance & Technology Risk Specialist to join our Internal Audit team, supporting our SOX 404 compliance and IT audit programs in a hybrid work environment. In this role, you will contribute to the execution of IT compliance reviews, continuous auditing analytics, and operational audits while collaborating with accounting, technology, operational teams, and Internal Audit colleagues. This position offers the opportunity to contribute to a fast-growing, science-driven organization making a meaningful difference to patients worldwide. When & where: Hyderabad, India (Hybrid) Discover your role: Review IT processes and controls within scope of the company's SOX 404 program and assess control effectiveness. Develop and implement continuous auditing analytics to identify weaknesses in compliance-related exposures, operational processes, and internal controls. Partner with Internal Audit colleagues to develop risk-based audit programs and support departmental deliverables. Contribute to IT operational audits in accordance with Institute of Internal Auditors (IIA) standards, internal policies, and procedures. Implement assigned audit sections independently with minimal supervision while maintaining audit quality and compliance. Complete SOX 404 IT compliance reviews and testing of controls assigned by Internal Audit management. Provide internal control expertise to business functions and departments seeking guidance on governance and control practices. Find opportunities to enhance operational efficiencies and support the preparation of audit recommendations and reports for Senior Management and the Audit Committee. This role requires: Minimum 3 years of progressive experience in IT audit, information security, or technology risk. Experience auditing and evaluating IT infrastructure, cybersecurity risks and controls, and operating systems. Strong understanding of SOX, Committee of Sponsoring Organizations (COSO), Control Objectives for Information and Related Technologies (COBIT), National Institute of Standards and Technology (NIST), Good Practice (GxP), General Data Protection Regulation (GDPR), and related governance and regulatory frameworks. Knowledge of IT compliance programs, process reviews, testing of controls, and internal control frameworks. Experience using data analytics tools such as Dataiku, Alteryx, or similar technologies. Understanding of artificial intelligence concepts, associated risks including model governance, data quality, access, ethical use, and controls relevant to AI-enabled processes. Ability to interact autonomously with middle management and provide practical guidance on risk, governance, and control matters. Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), and/or Certified Information Systems Security Professional (CISSP) preferred. Pharmaceutical, life sciences, or other regulated industry experience preferred. Big Four or public accounting experience preferred. Does this sound like you? Apply now to take your first step towards living the Regeneron Way! We are committed to building a workplace with an inclusive culture. Regeneron is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion or belief (or lack thereof), sex, sexual orientation, gender identity or expression, gender reassignment, marital or civil partnership status, civil status, pregnancy or parental status, age, disability, nationality, citizenship status, ethnic or national origin, membership of the Traveler community, familial status, genetic information, military or veteran status, or any other characteristic protected under applicable law. Where required, we will provide reasonable accommodation to applicants with known