Related Posts
AWS cloud application architect. Had an on-site interview with AWS a few days ago and just got an email saying they want to talk to me about next steps. The role is cloud application architect but I want to ask them about the senior cloud application architect role. I have all the relevant experience for that role and feel like I’d be a better fit for that senior role. How should I approach this conversation? Is this even possible? Amazon
Hi Amazonians, I'm looking for a switch to a PBC, especially Amazon. Could you guys please refer me for SDE-1 position in India location?
Skills: NodeJS, Angular, Django, MongoDB, MySQL, AWS, Distributed Systems etc.
YOE: 2.5 years
Location: India (preferred cities: Delhi NCR, Bangalore, Hyderabad)
Amazon Amazon India
More Posts
Partners be like

Additional Posts in Consulting
8AM Sunday Scaries 😬
offer from the client. thoughts?
New to Fishbowl?
unlock all discussions on Fishbowl.






Avoid IT audit unless you are getting it just for the clearance
Thankfully I was able to pivot from IT audit to TAS. Not going back to IT
Can you take screenshots
I want to see exactly what they do 😂 lol
Depends on what role - if entry level: know the differences between Soc1s, soc2s, SOX audits, know a general understanding of different tech layers - app level, OS, network, etc. also do some reading on general IT controls and application IT controls, automated, manual, etc. (if entry level that would look good to give an overview).
Senior level - talk about past experience in IT audit, what type of audits, S1/S2/Sox. What was your role, did you lead walk throughs - if so, for what type of controls. How big of teams did you lead, how did you improve audit quality, have you worked on any proposals, did you utilize offshore resources, usage of bots to automate testing, understanding of soc reports, did you write any narratives in reports, etc
For entry level as well - talk about the life cycle of an audit, pre planning - if any changes need to be done from prior year (any weaknesses in control testing that should be improved on, budget planning, planning of walk throughs - finding appropriate control owners to lead the walk throughs), then you conduct interim walk throughs - which are meetings to understand each IT control in place, this is round 1 of testing early in the audit timeline, you gather support for about 60% of testing samples, then within the last like 90 days (I forget what the timeline is bc I’ve been out of IT audit for 2 years), you conduct roll forward walk throughs, which is you confirm if there have been any changes to the controls or not (if not - you select the remaining tesitng samples you need)- if there have been changes, you document the changes and gather the samples you need. Then review process where you’re higher ups review and you address any updates that need to be made, and then for SOX you’re good, for SOC 1 report, you write the report and any changes and updates, and then you issue the report