Business Assurance and Compliance Auditor
What you'll need to apply
What this employer's standard application typically asks
Company-specific questions
- Have you previously worked at Apple?
About this role
Employer-provided description, formatted for easier reading.
The Business Assurance and Compliance group is looking for a motivated IT audit or Information Security professional to join our team. You'll identify risk across new and evolving processes and technologies spanning SOX, PCI, privacy, security, and emerging AI governance and design control responses proportionate to that risk.
You'll work in a range of capacities, from closing individual control gaps to helping shape the broader standards the organization uses to manage compliance risk, collaborating closely with subject matter experts and business partners along the way.
The Business Assurance and Compliance group partners across Apple's technology and business organizations to assess and test IT and security controls against key compliance frameworks (SOX, PCI, privacy, SOC 1/2, NIST CSF, and others), and to identify risk introduced by new technologies including AI and machine learning systems.
You'll lead or contribute to process and systems walkthroughs, test controls across ERP and cloud environments, and stay attuned to emerging regulatory and technology trends, translating them into practical control requirements. The role blends independent and team-based work across concurrent projects sourced from compliance stakeholders, business and finance teams.
3–5 years of relevant experience in IT audit, information security, or compliance gained through public accounting/consulting(Big 4), industry, internal audit, or equivalent experience.
Bachelor’s degree in Information Systems, Business, Accounting, Engineering, Computer Science or relevant field required.
Prior experience at a Big 4 or large regional public accounting firm is strongly preferred. Experience with compliance and risk frameworks, such as PCI DSS 4. 0, SOX, global privacy regulations (GDPR,PIPL and emerging AI/data laws), SOC 1/2, NIST CSF 2.
0. Controls experience across systems development lifecycle, access management, computer operations, networking, and security. Experience assessing security compliance controls such as identity and access management, vulnerability management, incident response, and data protection.
Growing awareness of AI governance and model risk including how organizations assess and control risk introduced by AI/ML systems and GenAI tooling. Ability to understand and test cloud IT controls across modern, often multi-cloud environments Experience interpreting and applying regulatory requirements, with the ability to translate expectations into practical, well-designed controls that meet current and future needs.
Experience with Chinese and European regulatory and security requirements. Familiarity with both the technical stack (database to network to cloud) and core business processes (Order to Cash, Purchase to Payables, Hire to Retire, and others), bringing a valuable cross-organizational perspective.
Comfortable working independently and within a team, managing concurrent work from a variety of compliance or business sources with limited supervision. Experience leading, or contributing to, process and systems walkthroughs as part of a risk or control gap assessment. Strong project management and organizational skills.
Clear, confident communicator and equally effective in group presentations and one-on-one conversations.