IT Auditor
IT auditors check an organisation's technology systems and the controls protecting them, so the business can trust its own data and show regulators and directors that it meets its obligations.

- Median salary*
- $109,200
4.4%vs last year, before tax
- People employed*
- 4,500
2.3%vs last year
- Projected growth*
- +12%
to 2035
- AI exposure*
- Moderate
- automation risk
- Average hours*
- 38/wk
−2h vs all jobs
- Shortage status*
- In shortage
national
IT auditors work in internal audit teams, at professional services firms and in government agencies, where technology runs everything from payroll to patient records to share trading. The job sits alongside financial audit but looks at the systems and controls that produce the numbers rather than at the numbers themselves, so it leans on risk and security knowledge as much as accounting. Banks, insurers, consultancies and large public sector bodies are the biggest employers.
How much do it auditors earn?
The median full-time salary for an it auditor is $109,200 per annum, before tax, up $23,100 since 2018.
Where you work moves pay more than anything else: internal audit in banking, insurance or a large consultancy pays above the middle of the range, while smaller not-for-profits and some public sector teams sit lower. A CISA certification is usually tied to a higher band, and contract or day-rate work on short engagements pays well but comes without paid leave or job security. Seniority within the audit function shapes the bands more than years spent in IT.
What does an it auditor do day to day?
The list below is what fills most weeks; the exact mix shifts with seniority and whatever stage the current work is at.
- Testing whether access controls actually work, by sampling user accounts or running a script across the whole population
- Reviewing how a new system will handle data, from the design stage through to go-live
- Checking a system against frameworks such as ISO 27001 or the Essential Eight and noting where it falls short
- Writing findings that explain the risk in plain language for managers and the audit committee
- Following up on last year's findings to see whether the fixes held
What skills do it auditors need?
Employers look for auditing and assurance, risk and internal controls, regulatory compliance, backed by ACL Analytics fluency and strong attention to detail.
Specialist skills
- Auditing and assurance
- Risk and internal controls
- Regulatory compliance
- Cyber security
- Data analysis
Software and tools
- ACL Analytics
- CaseWare IDEA
- Microsoft Excel
- Splunk
- Tableau
General skills
- Attention to detail
- Problem solving
- Written communication
Is the job growing?
About 4,500 people work as it auditors in Australia, and employment is projected to grow 12% over the decade to 2035. That's healthy, above-average growth, and the role should stay in solid demand.
How do you become an it auditor?
Here's the path most it auditors take, step by step.
- 1Start with a degree
A bachelor degree in accounting, information systems, computer science or a related field is the usual entry point, and about 52% of the people in the role hold one. Some universities offer a combined accounting and information systems degree, which covers both sides of the job.
- 2Get a first role that touches controls
Financial audit at an accounting firm, an internal audit graduate program, IT risk in a bank, or a systems support role with compliance duties all lead here. The point of the first job is to learn how evidence is gathered and how a finding is written up.
- 3Learn the frameworks on the job
ISO 27001, the Essential Eight, COBIT and APRA's technology standards are the reference points auditors work from. You learn them by applying them to real systems, not by reading them once.
- 4Add the CISA certification
The Certified Information Systems Auditor credential from ISACA is the standard qualification for the field and requires relevant work experience, so most people sit it a few years in. Auditors who came through accounting often hold a CA or CPA as well.
- 5Choose between in-house and advisory work
Internal audit teams offer steady hours and deep knowledge of one organisation, while consulting firms bring variety, travel and faster exposure to different industries. Moving between the two later is common and reasonably straightforward.
Ready to apply as an it auditor?
Whether you're working toward becoming an it auditor or already are one and want a hand with the next step (sharpening your resume for ATS screening, tightening your cover letter, or knowing what you'll actually be asked at interview), here are examples grounded in this specific role, not generic templates.
What jobs can an it auditor move to?
Moving into Chief Information Security Officer typically comes with the biggest pay rise, worth $91,000 a year more on average.
| Move to | Typical pay change | Overlap | Retraining |
|---|---|---|---|
| Chief Information Security Officer Audit and risk background supports leading security strategy, governance and compliance, with a short course to broaden executive leadership. | +$91,000 | 48% | short course |
| Cyber Security Analyst Understanding of technology controls and risk supports monitoring threats and incidents, and the audit approach carries across with little retraining. | +$18,800 | 79% | minimal |
| Penetration Tester Knowledge of system controls and vulnerabilities supports authorised security testing, with minimal retraining to build exploit techniques. | +$18,200 | 71% | minimal |
| Cyber Security GRC Specialist Controls, risk and compliance knowledge carries into security governance and regulatory advisory work, with a short course to bridge. | +$7,800 | 52% | short course |
| ISO Auditor Experience auditing technology controls and evidence transfers to certifying management systems against standards, needing a short course in quality frameworks. | −$35,400 | 63% | short course |
Moves are chosen from Jobs and Skills Australia's Data on Occupation Mobility, which follows income tax records between 2011-12 and 2020-21, together with entry requirements and skill overlap. A known move is one people were seen making in that data. Pay change compares median full-time pay for the two roles.
Who works as an it auditor?
The typical it auditor is 38 years old; 67% are men, 85% work full-time, and full-timers average 38 hours a week.
- 38
- Median age
- 33%
- Female share
- 85%
- Full-time
- −2h
- vs all-jobs avg
What's it like being an it auditor?
The work runs to an audit cycle: planning and risk assessment first, fieldwork through the middle, then reporting and follow-up. Testing, reading and writing fill most of the week, broken up by interviews and workshops with the teams who run the systems. Full-time weeks average 38 hours, though the weeks before an audit committee meeting run longer.
What people like
- You see the whole organisation. An audit takes you through trading platforms, payroll, cloud services and the teams that run them, which is hard to get from a single technical role.
- Findings usually lead to fixes. When you report a gap in access controls or patch management, there is a plan and a deadline attached, and you check back the following year to see whether it held.
- The subject matter keeps moving. Cloud migration, new privacy rules and ransomware all land on the audit plan within a year or two of arriving, so the reading never stops.
- The qualification travels. CISA is recognised internationally, and audit and risk skills carry across banking, government and consulting without starting over.
What people find hard
- You deliver news people don't want. Control owners can be defensive when a finding names their team, and the report goes to people more senior than they are.
- Evidence gathering drags. Waiting on screenshots, change records or a system owner's calendar can eat days out of a fieldwork window.
- Reporting deadlines cluster. Audit committee papers fall due on fixed dates, so the final weeks of an audit are long whatever the fieldwork turned up.
- You audit systems you don't run. You may be testing a platform you have never administered, so the early part of an audit is spent learning how it is supposed to behave.
Based on our synthesis of professional-body surveys and public accounts of the role, not first-person verified reviews.
Which industries employ it auditors?
Financial and Insurance Services employs the largest share of it auditors, followed by Professional, Scientific and Technical Services.
Top employing industries
- 1Financial and Insurance Services
- 2Professional, Scientific and Technical Services
- 3Public Administration and Safety
- 4Information Media and Telecommunications
- 5Health Care and Social Assistance
Ranked by employment share; the source doesn't publish an exact percentage per industry.
| Bachelor degree | 52% | |
|---|---|---|
| Postgraduate | 26% | |
| Diploma / Advanced Diploma | 13% | |
| Other | 9% |
Will AI replace it auditors?
IT auditing sits in the middle: the testing and evidence gathering that fill most of the week are increasingly automated, while the judgement about what to test and how to report it stays with the auditor. Analytics tools already let an auditor check a whole population instead of a sample, and drafting tools can turn notes into a first version of the working papers. What keeps the exposure moderate is that a finding has to be defensible to an audit committee and sometimes to a regulator, which needs someone who understands both the system and the standard.
Share of typical working time by exposure level
- Control testing across a full data setAnalytics tools can test every entry in an access log or ledger, so the auditor's time goes into designing the test and chasing the exceptions it throws up.30%high
- Interviewing system owners and chasing evidenceGetting a straight answer about who approved a change or where data actually sits depends on reading the room and knowing which question to ask next.25%low
- Judging which risks matter and reporting to the audit committeeTools can rank anomalies, but weighing a control gap against the business it affects and explaining that to a board needs context the auditor holds.25%moderate
- Writing working papers and draft findingsDrafting tools produce a usable opening version, though the auditor still has to confirm the wording matches the evidence.20%high
Moves least exposed to AI
These career moves from it auditor work are rated low for AI exposure:
- Penetration Tester
High skill overlap (71%), little retraining to get there, and a low automation-risk profile.
Common questions about becoming an it auditor
Straight answers to the questions people ask most.
How much do IT auditors earn?
$109,200 per year before tax is the median for full-time IT auditors, which means half earn more and half earn less. Banking, insurance and the large consultancies pay above that, and a CISA certification usually puts you in a higher band.
How do you become an IT auditor?
Most people start with a degree in accounting, information systems or a related field, then take a first job in financial audit, internal audit or IT risk. From there you learn the frameworks on real systems and sit the CISA exam once you have the required work experience.
Are IT auditors in demand?
IT auditors are currently in shortage nationally. Employment is projected to grow 12% over the decade to 2035, so the role is a reasonable bet if you already have audit or security experience behind you.
Will AI replace IT auditors?
AI is changing how the testing gets done more than it is removing the role. Analytics tools can now check every transaction in a data set instead of a sample and produce a first draft of the working papers, but deciding what risk matters and defending a finding to an audit committee still needs a person. The work is shifting towards designing the tests and interpreting what they turn up.
What can IT auditors move into?
The controls and risk knowledge you build carries into cyber security analysis or governance, risk and compliance work, and neither needs much retraining. Penetration testing suits auditors who want the technical side, paying $18,200 more. Over time, the audit and risk background supports security leadership such as a chief information security officer role.
What is the difference between an IT auditor and a financial auditor?
Financial auditors test the transactions and balances behind the financial statements, while IT auditors test the systems that produce them and the controls around access, change and data. The two work together on most large audits, so a systems finding often explains a number the financial team is querying.
Related roles
- Cyber Security GRC Specialist
- Cyber Security Analyst
- Penetration Tester
- ISO Auditor
- Chief Information Security Officer
- Cyber Security Analyst
Not sure this is you? Take the career quiz and get a ranked shortlist of roles that fit how you like to work.