IT Auditor

Job Requisition ID:  57150

Founded in 1920, Eastman is a global specialty materials company that produces a broad range of products found in items people use every day. With the purpose of enhancing the quality of life in a material way, Eastman works with customers to deliver innovative products and solutions while maintaining a commitment to safety and sustainability. The company’s innovation-driven growth model takes advantage of world-class technology platforms, deep customer engagement, and differentiated application development to grow its leading positions in attractive end markets such as transportation, building and construction, and consumables. As a globally inclusive company, Eastman employs approximately 13,000 people around the world and serves customers in more than 100 countries. The company had 2025 revenue of approximately $8.8 billion and is headquartered in Kingsport, Tennessee, USA. For more information, visit www.eastman.com.

 

Responsibilities

 

The Information Technology (IT) Auditor plays a key role on Eastman’s Internal Audit team, executing risk-based audits that evaluate the design and effectiveness of information technology controls across the enterprise. The IT Auditor leads or supports engagements spanning IT general controls, application controls, Sarbanes-Oxley (SOX) compliance, cybersecurity, and IT-dependent business processes. This role calls for someone who brings 3+ years of relevant experience, strong analytical thinking, and the ability to communicate clearly with both technical and non-technical stakeholders. The IT Auditor also contributes to department-wide process improvement, mentors team members, and helps advance Eastman’s use of AI, data analytics and automation within the audit function.


The primary role of an Information Technology (IT) Auditor is to execute various audit engagements in a lead or support position. Audit execution involves scoping, planning, testing, identification of issues, and reporting. The IT Auditor may have a primary focus on IT business processes and/or Sarbanes-Oxley (SOX) areas. Even though the audit execution process has a defined framework, each audit and process owner are unique, so the ability to respond appropriately to varying situations and environments is important. The IT Auditor engages in various projects in support of Eastman’s Internal Audit process improvement and special requests.


•    Executing audits according to departmental guidelines, including Institute of Internal Auditors (IIA) standards, to assess the adequacy and effectiveness of internal controls, validate compliance with corporate procedures, and address potential risks.
•    Planning, scoping, and executing tasks required to complete audits as defined in lead or support auditor roles.
•    Conducting audit procedures such as leading interviews, requesting and analyzing evidence, and documenting test steps in detailed, well-supported work papers.
•    Evaluating the design and operating effectiveness of IT general controls (ITGCs), application controls, and key interfaces across platforms including ERP systems, operating systems, databases, and network infrastructure.
•    Assessing IT governance, risk management, and cybersecurity controls against established frameworks (e.g., COBIT, NIST, ISO 27001).
•    Identifying and evaluating audit issues and gaps using a risk-based approach.
•    Meeting with process management to discuss audit findings and gaining agreement on management action plans.
•    Partnering with audit clients to identify constructive, value-added solutions that address issues identified.
•    Coordinating business process audit testing with SOX testing to increase productivity and reduce duplication of effort.
•    Performing issue remediation follow-up and testing to validate that management action plans have been effectively implemented.
•    Performing process assessments and providing advisory services as requested by clients.
•    Developing relationships with primary contacts for focus areas 
•    Sharing process knowledge and key learnings with other audit team members
•    Contributing toward departmental projects and initiatives.
•    Identifying opportunities to improve departmental processes and support corporate strategy.
•    Finding improvement opportunities where automation and data analytic tools could streamline procedures and enhance analysis of results.
•    Identifying and communicating IT audit findings to senior management.

Qualifications

 

Required


•    Bachelor’s degree in Information Systems, Accounting, Finance, Computer Science, or a related field.
•    3+ years of progressive experience in IT audit, public accounting, internal audit, related risk/controls function or related IT experience.
•    Solid understanding of IT general controls, application controls, and SOX compliance requirements.
•    Working knowledge of the IIA International Standards for the Professional Practice of Internal Auditing.
•    Familiarity with one or more IT governance and control frameworks such as COBIT, NIST CSF, or ISO 27001.
•    Demonstrated ability to plan and execute audit engagements, manage time across multiple priorities, and meet deadlines with limited supervision.
•    Strong interpersonal skills with the ability to build and maintain effective working relationships across all levels of the organization.
•    Excellent written and verbal communication skills, including the ability to present complex technical issues to non-technical audiences clearly and concisely.
•    Proficiency with Microsoft Office applications and experience with data analytics or audit management software (e.g., ACL, IDEA, Power BI, Tableau, or similar tools).
•    Willingness to travel up to approximately 10–15%, primarily domestic.

 

Preferred


•    Professional certification or active pursuit of certification such as CISA (Certified Information Systems Auditor), CIA (Certified Internal Auditor), CISSP, or CRISC.
•    Experience auditing cloud environments, cybersecurity programs, or operational technology (OT) systems.

•    Experience auditing ERP environments (SAP preferred), operating systems, databases, and network security controls.
•    Exposure to data analytics and continuous auditing techniques, including scripting or query languages such as SQL or Python.
•    Experience working within a manufacturing or chemical industry environment.

NOTE:

Eastman will not accept applicants for this offered position who require visa sponsorship, including those whose status is F-1 visa OPT who subsequently would require ongoing visa sponsorship.

Eastman Chemical Company is an equal opportunity employer.  All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, national origin, disability, pregnancy, veteran status or any other protected classes as designated by law.

 

Eastman is committed to creating a highly engaged workforce, where everyone can contribute to their fullest potential each day.


Nearest Major Market: Asheville
Nearest Secondary Market: Knoxville

Job Segment: Internal Audit, Testing, Network Security, Cloud, Computer Science, Finance, Technology, Security