About Us
Sophos is a global leader in advanced cybersecurity solutions designed to stop cyberattacks. In February 2025, the company acquired Secureworks, uniting two innovators that have reshaped the industry with AI‑driven technologies, services, and products. Today, Sophos is the world’s largest pure-play Managed Detection and Response (MDR) provider, supporting more than 28,000 organizations. Along with MDR and other services, Sophos offers a full range of top-tier endpoint, network, email, and cloud security solutions that work together seamlessly through the Sophos Central platform. Secureworks adds its cutting-edge Taegis XDR/MDR, identity threat detection and response, next-generation SIEM capabilities, managed risk, and extensive advisory services. Sophos delivers these offerings through reseller partners, MSPs, and MSSPs worldwide, protecting more than 600,000 organizations from phishing, ransomware, data breaches, and both common and state-sponsored cyber threats. All solutions are fueled by real-time and historical threat intelligence from Sophos X-Ops and the newly added Counter Threat Unit (CTU). The company is headquartered in Oxford, UK. More details are available at www.sophos.com.
Role Summary
We are looking for an experienced and meticulous Senior Internal Auditor. This position is responsible for assessing the strength of internal controls, risk management, and governance processes, while ensuring compliance with laws, regulations, and internal policies. The Senior Internal Auditor will help guide the Internal Audit function and will develop and execute a risk-based audit plan to evaluate key operations and internal controls, reporting findings and recommending improvements. The role also includes creating and carrying out comprehensive audit programs to meet ongoing testing needs related to contractual and regulatory compliance. The Senior Internal Auditor will advise senior leadership on best practices and support organizational improvements.
What You Will Do
• Plan, coordinate, and manage internal audits across departments, operations, and subsidiaries.
• Lead internal audit activities, including planning, reviewing documentation, analyzing data, preparing reports, and providing timely updates based on established Internal Audit methodologies.
• Help develop and carry out a risk-based audit plan aligned with strategic goals.
• Assess the effectiveness of internal controls and highlight improvement opportunities.
• Produce detailed audit reports outlining findings, risks, and actionable recommendations.
• Track and verify the implementation of audit recommendations.
• Lead ad hoc reviews of business processes, policies, and procedures, and offer advisory support to management.
• Ensure compliance with internal policies, regulations, and industry standards.
• Work with external auditors and regulatory bodies when required.
• Identify and conduct advisory projects aimed at improving operations and efficiency.
• Develop innovative solutions to address complex issues related to company strategy.
• Continuously enhance internal audit tools, methods, and practices.
What You Will Bring
• Bachelor’s degree in Accounting, Finance, Business Administration, or related field (required).
• CPA, CIA, or CISA certification (preferred or required, depending on organizational standards).
Experience:
• At least 6 years of internal audit experience.
• Background in internal auditing, risk management, compliance, or external audit.
• Understanding of financial, operational, and IT auditing principles.
Skills:
• Strong knowledge of internal control frameworks (such as COSO or SOX) and industry standards.
• Familiarity with internal audit best practices.
• Excellent analytical and problem‑solving abilities.
• High level of accuracy and attention to detail.
• Strong communication and interpersonal skills.
• Proficiency with audit tools and Microsoft Office Suite.
• Ability to balance multiple priorities and meet deadlines.
Preferred Attributes:
• Audit credentials such as CIA, CRMA, CISA, CFE, CPA, CQA, or ISO Lead Auditor (9001, 17020, 17021, 27001).
• Experience with data analytics.
• Understanding of enterprise risk management and compliance frameworks.
In the United States, the base salary for this position ranges from $125,000 to $208,000. Additional compensation includes bonus eligibility and a comprehensive benefits package. Actual pay will depend on factors such as skills, experience, training, education, certifications, location, and business needs.
Ready to Join Us?
At Sophos, we value the power of diverse perspectives in driving innovation. Research shows that candidates may hesitate to apply if they don’t meet every qualification. We challenge that idea. Your unique background may be exactly what our team needs. Don’t let a checklist stop you—apply.
What’s Great About Sophos?
• Remote‑first work model for most roles, with some positions requiring a hybrid approach. Candidates must have legal authorization to work in the location where the position is posted without employer sponsorship.
• A collaborative, creative environment with a strong sense of teamwork.
• Employee-led diversity and inclusion groups that foster community, education, and advocacy.
• Annual charitable initiatives, fundraising events, and volunteer opportunities.
• Global sustainability efforts aimed at reducing environmental impact.
• Worldwide fitness and trivia competitions to promote mental and physical wellness.
• Global wellbeing days for rest and recovery.
• Monthly wellbeing training and webinars to support employee health.
Our Commitment to You
We are proud of our inclusive culture and are dedicated to delivering equal opportunities for all. We believe that diversity combined with excellence makes Sophos stronger, and we welcome applicants who can enhance the diversity of our team. All applicants will be treated fairly and equally, regardless of gender, sex, gender identity, marital status, race, religion, color, age, veteran status, disability, pregnancy, maternity, or sexual orientation. If you need any adjustments during the hiring process, please let us know so we can support you.
Data Protection
If you decide to explore opportunities with us and share your resume or personal information, Sophos will retain this data for 12 months according to our Privacy Policy and may contact you about this or other appropriate roles. You may request deletion or updates to your information at any time using the steps outlined in the Privacy Policy. For details on our data protection practices, please refer to our Privacy Policy: Cybersecurity as a Service Delivered | Sophos.
To find out more about this job, please visit this link

