About this role
At Ouster, we build sensors and tools for engineers, roboticists, and researchers, so they can make the world safer and more efficient. We've transformed LIDAR from an analog device with thousands of components to an elegant digital device powered by one chip-scale laser array and one CMOS sensor. The result is a full range of high-resolution LIDAR sensors that deliver superior imaging at a dramatically lower price. Our advanced sensor hardware and vision algorithms are used in autonomous cars, drones and many other applications. If you’re motivated by solving big problems, we’re hiring key roles across the company and need your help!
About the role
We are seeking a Senior IT Auditor to support the Company’s Internal Audit function and Sarbanes-Oxley (SOX) program. Reporting to the Internal Audit Manager – IT and Analytics (based in the US), you will have broad exposure to the operations of the Company and will interact with leaders across IT, Finance, HR, Operations, Legal, Sales, and Engineering, as well as our external auditors and advisors.
In this role, you will take a lead execution role in planning, organizing, and conducting SOX testing, risk assessments, and internal audit projects focused on IT systems, infrastructure, and analytics. Navigating increasingly complex environments, you will grow your personal brand, deepen your technical expertise, and apply critical thinking to break down complex risk concepts. This role presents an excellent, long-term path for career development, as Ouster Internal Audit is deeply committed to recruiting and developing great talent.
This person ideally possesses manufacturing or technology industry experience, with a focus on end-to-end SOX compliance in a multinational organization with US-based reporting requirements. The candidate must have strong technical knowledge of various IT auditing methodology, process flow mapping, design and documentation of controls, controls testing including testing of key reports and IPEs, evaluation of control deficiencies and remediation plans. Additionally, the candidate must have the ability to effectively manage relationships with partners (external auditors, outsourcing partners, control owners), demonstrate proficient project management skills, superior communication (written and oral) and organizational skills.
You will be joining a world-class Internal Audit team that tracks and seeks to understand the factors driving our growth and success. We help our entire organization achieve our operational and financial goals while embodying our company values. We ensure our objectives are feasible and work closely with all teams to ensure they have the resources they need to achieve our ambitious mission—enabling all teams to work together effortlessly.
This is a hybrid role requiring 2 to 3 days per week on-site at our Bangkok office. We strongly encourage candidates to live within a sustainable commuting distance, as relocation benefits are not offered for this position. Given our San Francisco headquarters (PST/PDT), you must also be prepared to periodically adjust your schedule to accommodate US business hours for critical meetings and peak season demands, ensuring seamless collaboration with US-based teams.
Key responsibilities:
● Plan, coordinate, and execute all phases of IT SOX compliance testing, leading fieldwork for IT general controls (ITGCs), system development life cycles (SDLCs), automated application controls, and key reports/IPE.
● Maintain and update all ICFR / SOX 404 documentation as required, including COSO framework mapping, process and control narratives/flowcharts, risk and controls matrices (RCMs), risk assessment, and systems scoping.
● Support the annual IT SOX scoping and risk assessment process in alignment with the overall ICFR and SOX program.
● Monitor changes to business processes and systems, applying independent judgement to evaluate the potential impact to the control environment and recommend necessary improvements.
● Assess vendor SOC reports to ensure adequate assurance over outsourced IT environments.
● Track deficiencies and remediation for IT controls and prepare SAD (Summary of Aggregated Deficiencies) analysis for assigned areas.
● Support the remediation of control deficiencies identified during SOX testing and collaborate with management to design effective remediation approaches and measures.
● Act as a key liaison with IT and Security for IT SOX assurance, while providing advisory services to IT and managing the relationship between IT and other departments.
● Collaborate with the external audit IT team on testing approaches and reliance strategies, PBCs, samples, and requests for assigned areas.
● Support internal audit projects related to IT systems and automation.
● Provide guidance and recommendations to senior management based on audit findings and industry best practices.
● Stay up-to-date with changes in regulatory requirements and provide guidance to the company on potential impacts.
● Foster a culture of compliance, integrity, and continuous improvement within the organization.
We acknowledge the confidence gap at Ouster. You do not need to meet all of these requirements to be the ideal candidate for this role. To thrive in this role, you have:
● Bachelor's degree in Management Information Systems (MIS), Computer Science, Accounting, Information Technology, or related field.
● At least 5 years of experience in IT auditing, IT controls, risk management, or compliance within a complex, multinational business environment (manufacturing or technology industry experience is a plus).
● Demonstrated experience working with US-listed multinational companies or US-parented companies, with exposure to SOX or similar internal controls compliance requirements.
● Professional fluency in both Thai and English (written and verbal) is required to interact with local teams and US-based management.
● Willingness and ability to periodically adjust work schedule to overlap with US Pacific Time (PST/PDT) to attend necessary meetings and manage busy season demands with US-based colleagues.
● Strong foundational knowledge of IT auditing methodologies, COSO, CoBIT, and ITIL frameworks, as well as Sarbanes-Oxley (SOX) and PCAOB requirements.
● Excellent communication and interpersonal skills, with the ability to communicate complex technical concepts to non-technical stakeholders.
● A solid grasp of IT systems, segregation of duties, and cybersecurity principles.
● Strong project management skills, with the ability to prioritize tasks, manage deadlines, and coordinate resources effectively.
● Ability to thrive in a fast-paced, dynamic environment and adapt to evolving business needs.
● Professional certification (CISA, CIA, CISSP, or CPA license) is preferred.