IT Security, Risk, and Compliance Auditor

3 Months ago • 3 Years + • Cyber Security

Job Summary

Job Description

The IT Security, Risk, and Compliance Auditor at Coupa is crucial for assessing and enhancing the organization's security controls, managing risks, and ensuring compliance with various frameworks. The role involves conducting technical audits, implementing automated control testing, identifying gaps, and improving compliance processes to enhance operational efficiency and minimize risk. The candidate is expected to work across IT, security, and business units to evaluate security measures, improve control design, and meet industry standards.
Must have:
  • 3+ years in IT security auditing, risk assessments, or compliance
  • Strong knowledge of security frameworks (e.g., ISO 27001, SOC 2, PCI DSS)
  • Experience with GRC platforms and compliance automation tools
  • Bachelor’s degree in IT, Cybersecurity, or related field (or equivalent experience)
  • Strong verbal and written communication skills
Good to have:
  • CISA, CISSP, CRISC, CISM, ISO 27001 Lead Auditor certifications

Job Details

Coupa makes margins multiply through its community-generated AI and industry-leading total spend management platform for businesses large and small. Coupa AI is informed by trillions of dollars of direct and indirect spend data across a global network of 10M+ buyers and suppliers. We empower you with the ability to predict, prescribe, and automate smarter, more profitable business decisions to improve operating margins.

Why join Coupa?

🔹 Pioneering Technology: At Coupa, we're at the forefront of innovation, leveraging the latest technology to empower our customers with greater efficiency and visibility in their spend.
🔹 Collaborative Culture: We value collaboration and teamwork, and our culture is driven by transparency, openness, and a shared commitment to excellence.
🔹 Global Impact: Join a company where your work has a global, measurable impact on our clients, the business, and each other. 

Learn more on Life at Coupa blog and hear from our employees about their experiences working at Coupa. 

The Impact of an IT Security, Risk, and Compliance Auditor at Coupa:

The IT Security, Risk, and Compliance Auditor plays a critical role in evaluating, strengthening, and automating the organization’s security controls, risk posture, and compliance frameworks. This position is responsible for conducting technical security audits, implementing automated control testing, identifying gaps, and enhancing compliance processes to drive operational efficiency and risk reduction.

The ideal candidate has a technical background in security and compliance auditing with a strong understanding of control automation, evidence collection automation, and continuous compliance monitoring. They will work cross-functionally with IT, security, and business units to evaluate the effectiveness of security measures, improve control design, and ensure the organization meets regulatory and industry standards.

This role requires proficiency in security frameworks such as ISO 27001, SOC 2, PCI DSS, HIPAA, SWIFT, TISAX, C5, PIMS, NIST CSF, FedRAMP, and expertise in automation tools, GRC platforms, and evidence collection technologies.

What You'll Do:

    • Conduct Technical Audits & Risk Assessments: Perform in-depth security audits and risk-based assessments of infrastructure, applications, and cloud environments to evaluate compliance with standards like ISO 27001, SOC 2, PCI DSS, GDPR, and HIPAA.
    • Leverage Automation & Tools: Utilize automated control testing, evidence collection, and real-time compliance tracking via GRC platforms and security tools (e.g., SIEM, IAM, vulnerability management).
    • Evaluate & Improve Security Controls: Assess and validate security configurations, access management, encryption, and vulnerability management, providing risk-based recommendations and supporting mitigation efforts.
    • Reporting & Stakeholder Engagement: Produce detailed audit reports, dashboards, and presentations for technical and executive audiences, tracking remediation and ensuring audit follow-ups are completed.
    • Cross-Functional Collaboration & Advisory: Partner with IT, security, and business teams to integrate audit findings into strategy, advise on best practices, and support continuous improvement in control automation and compliance posture.

What You Will Bring to Coupa:

    • Education & Experience: Bachelor’s degree in IT, Cybersecurity, or related field (or equivalent experience) with 3+ years in IT security auditing, technical risk assessments, or compliance.
    • Technical & Framework Expertise: Strong knowledge of security frameworks (e.g., ISO 27001, SOC 2, PCI DSS, NIST CSF, HIPAA, FedRAMP) and understanding of IT systems, cloud security, encryption, and access management.
    • Tools & Automation: Experience with GRC platforms, compliance automation, control testing tools, evidence collection systems, and familiarity with audit/security tools (e.g., AuditBoard, Drata, Splunk, Qualys, AWS Security Hub).
    • Certifications (Preferred): CISA, CISSP, CRISC, CISM, ISO 27001 Lead Auditor, or equivalent credentials.
    • Communication & Analytical Skills: Strong verbal and written communication skills, with the ability to translate findings into actionable security recommendations and engage effectively with stakeholders.
#LI-REMOTE
#LI-PB

Coupa complies with relevant laws and regulations regarding equal opportunity and offers a welcoming and inclusive work environment. Decisions related to hiring, compensation, training, or evaluating performance are made fairly, and we provide equal employment opportunities to all qualified candidates and employees. 

Please be advised that inquiries or resumes from recruiters will not be accepted.

By submitting your application, you acknowledge that you have read Coupa’s Privacy Policy and understand that Coupa receives/collects your application, including your personal data, for the purposes of managing Coupa's ongoing recruitment and placement activities, including for employment purposes in the event of a successful application and for notification of future job opportunities if you did not succeed the first time. You will find more details about how your application is processed, the purposes of processing, and how long we retain your application in our Privacy Policy.

Similar Jobs

Lilt - Staff Full Stack Engineer

Lilt

Boston, Massachusetts, United States (Hybrid)
1 Month ago
Hashlist - Product Manager

Hashlist

Pune, Maharashtra, India (Hybrid)
9 Months ago
Playtika - FP&A Specialist

Playtika

Israel (On-Site)
4 Months ago
Luxoft - Lead Python & C++ Engineer

Luxoft

Chennai, Tamil Nadu, India (On-Site)
8 Months ago
Wargaming - Lead Level Artist

Wargaming

Belgrade, Serbia (Hybrid)
2 Months ago
Vercel - Staff Security Operations Engineer

Vercel

San Francisco, California, United States (Hybrid)
3 Months ago
LeoVegas - Senior Information Security GRC Analyst

LeoVegas

Sliema, Malta (On-Site)
1 Month ago
Veeam Software - Cloud Application Security Engineer (Middle/Senior)

Veeam Software

Prague, Czechia (On-Site)
1 Month ago
Applike - IT Security Manager (f/m/d)

Applike

Hamburg, Hamburg, Germany (Hybrid)
7 Months ago
Survay Monkey - Information Security Engineer III

Survay Monkey

Amsterdam, North Holland, Netherlands (Hybrid)
3 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Balbix - Staff DevOps Engineer

Balbix

Gurugram, India (On-Site)
5 Months ago
Tesla - Automotive Technician (Kfz-Mechatroniker/Automechaniker)

Tesla

Weinstadt, Baden-Württemberg, Germany (On-Site)
6 Months ago
imerza - Senior Architectural 3D Artist

imerza

Sarasota, Florida, United States (On-Site)
3 Months ago
Lionbridge Games - Software Testing Associate

Lionbridge Games

Masovian Voivodeship, Poland (On-Site)
4 Months ago
playground - Senior VFX Artist

playground

Royal Leamington Spa, England, United Kingdom (Hybrid)
3 Months ago
NielsenIQ - Analyst - Retail

NielsenIQ

Langley, British Columbia, Canada (Hybrid)
1 Month ago
cyara - Support Engineer

cyara

United States (Remote)
5 Months ago
Rippling - Global Immigration Specialist

Rippling

San Francisco, California, United States (On-Site)
1 Month ago
Jellyfish - Senior Paid Social Manager

Jellyfish

Johannesburg, Gauteng, South Africa (Hybrid)
3 Months ago
sphere entertainment - Assistant Editor

sphere entertainment

Burbank, California, United States (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Jobs in Reno, Nevada, United States

Carbon Health - Per Diem Medical Assistant

Carbon Health

La Quinta, California, United States (On-Site)
1 Month ago
160over90 - Account Executive, Partnerships

160over90

Chicago, Illinois, United States (On-Site)
1 Month ago
Apple - Product Manager, Card Payments and Authentication

Apple

Cupertino, California, United States (On-Site)
2 Months ago
Uniswap Labs - Senior Frontend Engineer

Uniswap Labs

New York, United States (Hybrid)
1 Month ago
Next Level Business Services - SAP WM (Full Time)

Next Level Business Services

Naples, Florida, United States (On-Site)
10 Months ago
CAE - Project Engineer

CAE

Binghamton, New York, United States (On-Site)
2 Months ago
Marvell - Principal Optical Engineer

Marvell

Santa Clara, California, United States (On-Site)
2 Months ago
FalconX - Senior Trading Systems Front End Engineer

FalconX

New York, New York, United States (On-Site)
2 Months ago
Qualcomm - NPI Program Analyst, Staff

Qualcomm

San Diego, California, United States (On-Site)
2 Months ago
NBC Universal - Mgr, Content Accounting - TV Networks

NBC Universal

Englewood Cliffs, New Jersey, United States (Hybrid)
3 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Decagon - Senior Security Engineer, Detection & Response

Decagon

San Francisco, California, United States (On-Site)
1 Month ago
bytedance - Application Security Engineer - Global Monetization

bytedance

Singapore (On-Site)
4 Months ago
Polygon Labs - Senior Security Engineer (Rust)

Polygon Labs

(Remote)
4 Months ago
Lilt - Staff DevOps Engineer (Security Clearance Required)

Lilt

Washington, District Of Columbia, United States (Hybrid)
5 Months ago
Survay Monkey - Software Engineer II - Security Engineering

Survay Monkey

Ottawa, Ontario, Canada (Hybrid)
1 Month ago
Varonis  - Junior Security Analyst

Varonis

Morrisville, North Carolina, United States (On-Site)
3 Months ago
Zazz - Cybersecurity Analyst

Zazz

(Remote)
6 Months ago
Rocket studio - Senior/Expert Security Specialist (IT)

Rocket studio

Warsaw, Masovian Voivodeship, Poland (Hybrid)
3 Months ago
Jane Street - Cybersecurity Governance and Risk Specialist

Jane Street

London, England, United Kingdom (On-Site)
3 Months ago
Tesla - Security Systems Engineer

Tesla

Brandenburg, Germany (On-Site)
6 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Pune, Maharashtra, India (Hybrid)

Pune, Maharashtra, India (Remote)

Bogota, Colombia (Hybrid)

Pune, Maharashtra, India (Hybrid)

Hyderabad, Telangana, India (On-Site)

Pune, Maharashtra, India (On-Site)

Bogota, Colombia (Hybrid)

Pune, Maharashtra, India (Hybrid)

Pune, Maharashtra, India (On-Site)

View All Jobs

Get notified when new jobs are added by Coupa

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug