More Posts
When consultants moonlight as hitmen

Need likes. Like for puppy. Happy Halloween! 🎃

Who’s the best staff that you’ve worked with?
Additional Posts in Risk Assurance
M1 salaries in LA?
Thoughts on EY risk advisory?
New to Fishbowl?
unlock all discussions on Fishbowl.
The fact that IT audit is sold as "advisory" or "consulting" is baffling to me. It's control testing with tons of screenshots and pdfs lol. Don't see how anyone can do that for more than 2 years.
What are some good options to pivot to?
Coach
I mean at the end of the day you’re testing controls. The only difference is the criteria you’re using.
My experience in external audit was all about getting to the most basic, minimal level of “reasonable assurance” (or the least amount of questions fr the reviewers). Internal audit allows me to get somewhat more technical as there is time to dig into issues and process improvements.
How I long for a job where my client doesn’t see me as the enemy. :(
Same. I thought when I left public accounting I'd finally be accepted as part of "the team," but other departments still hate my role. The saving grace is commiserating over and hating on our external auditor 😏, but that only helps with the accounting dept. I'm at a very large F.I./broker dealer and most staff scoff at regulations of any kind, so I kind of expected this going in.
C'est la vie.
Can’t agree more with this shit
Has anybody pivoted to a Salesforce implementation role or have any experience shifting to something entirely new from IT Audit?
Yeah I’m coming up on one year. After another coupe of months I’m gonna get into cyber security. I can’t do this shit for much longer lol
Thats why it was time for me to cash out and jump to industry into Information Security. Finally got the opportunity to do cyber security work. I still help out with audits from a planning perspective, but it doesn’t reflect the work for the entire year.
I was shopping around the market at the 2 year mark and realized that the jobs in our field are quite competitive in terms of applicants (most employers wanted to hire people without the need to train them—-which is not possible frankly and explains why I saw certain job postings remaining open for 1yr+). In the end I stayed at the firm for another 2 years, while continuing to advocate/push to diversify my work experience and applying around in industry. The 2 year mark for you is a good starting point to look around what’s out there.
2 years in and going to industry to do IT security compliance in a month so i can jump properly into cybersecurity in maybe 2 years after getting relevant certifications, any advice
Actually, this is true for statutory audit, but you can find variety in Risk Assurance for channel 2 clients. I haven’t tested controls (screenshots, testing sheets, ...) for the past 3 years: I have a few testing engagement in my portfolio (SOX-like), which are all delivered by Senior Associates. Things get better: you get to work more with C-level (CEO, Internal Audit, CIO, ...).