IT Auditor

Brief introduction - Role Summary/Purpose:

The Corporate Audit Department (CAD) is established by Colgate-Palmolive Company’s Audit Committee (“the Committee”) of the Board of Directors to assist the Committee and management in providing independent, objective assurance and advisory services designed to add value and improve Company’s operations. CAD’s primary mission is to enhance and protect the company’s value by providing risk-based and objective assurance, advice, and insight to enable enterprise-level effective risk identification and management. We collaborate closely with cross functional teams and leadership to achieve a robust control environment. The IT Auditor will play a key role in ensuring CAD delivers on its mission and successfully meets its objective.

The IT Auditor will play a key role in ensuring CAD delivers on its mission and efficiently meets its objective. We are seeking an experienced and forward-thinking IT Auditor to evaluate and strengthen our organization's enterprise technology risk, cybersecurity posture, SAP ERP security, cloud security and emerging technology controls. In this role, you will lead end-to-end audits covering IT General Controls (ITGCs), Operational Technology (OT/ICS) security, SAP security governance, and risk management surrounding Artificial Intelligence (AI) and Machine Learning (ML) deployments.

Responsibilities:

  • End-to-End Audit Execution: Plan, execute, and deliver risk-based audits covering ITGCs, cloud environments (AWS/Azure/GCP), application security controls, and third-party vendor risks.

  • SAP Security: Evaluate SAP authorization concepts, role design, custom T-codes, user access provisioning, Segregation of Duties (SoD) risks, and SAP GRC Access Control implementations.

  • Cybersecurity Compliance: Assess controls against major industry frameworks (e.g. NIST CSF, ISO/IEC 27001, SOC 2, CIS Controls).

  • ICS/OT Architecture Audits: Evaluate security controls across Industrial Control Systems (ICS), SCADA, PLCs, and manufacturing/operational environments.

  • OT/IT Security: Audit network segmentation, firewall configurations, Programmable Logic Controllers (PLC) security, remote access controls, vulnerability management and data flow protections between IT enterprise networks and OT operational zones (e.g. aligning with IEC 62443 and NIST SP 800-82).

  • AI/ML Governance & Risk Audits: Evaluate risk management frameworks for AI/ML deployments against framework standards (e.g. ISO/IEC 42001, NIST AI Risk Management Framework, EU AI Act compliance guidelines).

  • Stakeholder Reporting: Draft clear, high-impact audit reports and actionable recommendations for executive leadership and Audit Committee.

  • Remediation Tracking: Monitor and validate management remediation plans to ensure control gaps are effectively closed.

Required Qualifications:

  • Education: Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Industrial Automation, MIS, or a related technical field.

  • Experience: Minimum of 5 years of hands-on experience in IT/OT auditing, SOX Compliance and Cybersecurity auditing.

  • Domain Expertise:

    • Demonstrated experience auditing SAP Security frameworks (SoD analysis, SAP authorization mechanisms, T-code restrictions etc.).

    • Familiarity with Operational Technology (OT) / ICS security standards (e.g., IEC 62443, NIST SP 800-82).

    • Experience in auditing or assessing risks in AI/ML systems and automated decision-making platforms.

  • Certifications: At least one active core certification required:

    • Certified Information Systems Auditor (CISA)

    • Certified Information Security Manager (CISM)

    • Certified Information Systems Security Professional (CISSP)

    • Certified in Risk and Information Systems Control (CRISC)

Preferred Qualifications:

  • Audit Analytics & Automation: Hands-on experience using data analytics tools (e.g., Python, SQL, ACL, Power BI, Domo etc.) to build continuous audit testing scripts.

  • AI-Assisted Auditing: Experience leveraging Generative AI or automation tools to optimize audit workflows, evidence collection, and risk assessments.

  • Cross-Domain Knowledge: Ability to bridge technical communication gaps between IT teams, plant floor OT engineers and executive leadership.

  • Analytical Problem Solving: Skilled at evaluating complex technical environments.

  • Communication & Influence: Strong verbal and written communication skills to deliver objective audit findings and foster a risk-aware security culture across the Company.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available