Skip to content
careertips

Home IT & Software

IT Auditor

IT auditors check an organisation's technology systems and the controls protecting them, so the business can trust its own data and show regulators and directors that it meets its obligations.

Illustration of a person working as an it auditor
Median salary*
$109,200

4.4%vs last year, before tax

People employed*
4,500

2.3%vs last year

Projected growth*
+12%

to 2035

AI exposure*
Moderate
automation risk
Average hours*
38/wk

−2h vs all jobs

Shortage status*
In shortage

national

IT auditors work in internal audit teams, at professional services firms and in government agencies, where technology runs everything from payroll to patient records to share trading. The job sits alongside financial audit but looks at the systems and controls that produce the numbers rather than at the numbers themselves, so it leans on risk and security knowledge as much as accounting. Banks, insurers, consultancies and large public sector bodies are the biggest employers.

How much do it auditors earn?

The median full-time salary for an it auditor is $109,200 per annum, before tax, up $23,100 since 2018.

Where you work moves pay more than anything else: internal audit in banking, insurance or a large consultancy pays above the middle of the range, while smaller not-for-profits and some public sector teams sit lower. A CISA certification is usually tied to a higher band, and contract or day-rate work on short engagements pays well but comes without paid leave or job security. Seniority within the audit function shapes the bands more than years spent in IT.

Median annual salary, 2018–2028
Salaries rose $23,100 a year to 2024; the dashed line shows a projection to 2028 based on the real ABS Wage Price Index growth rate, not a role-specific forecast.
Full it auditor salary breakdown →

What does an it auditor do day to day?

The list below is what fills most weeks; the exact mix shifts with seniority and whatever stage the current work is at.

  • Testing whether access controls actually work, by sampling user accounts or running a script across the whole population
  • Reviewing how a new system will handle data, from the design stage through to go-live
  • Checking a system against frameworks such as ISO 27001 or the Essential Eight and noting where it falls short
  • Writing findings that explain the risk in plain language for managers and the audit committee
  • Following up on last year's findings to see whether the fixes held

What skills do it auditors need?

Employers look for auditing and assurance, risk and internal controls, regulatory compliance, backed by ACL Analytics fluency and strong attention to detail.

Specialist skills

  • Auditing and assurance
  • Risk and internal controls
  • Regulatory compliance
  • Cyber security
  • Data analysis

Software and tools

  • ACL Analytics
  • CaseWare IDEA
  • Microsoft Excel
  • Splunk
  • Tableau

General skills

  • Attention to detail
  • Problem solving
  • Written communication

Is the job growing?

About 4,500 people work as it auditors in Australia, and employment is projected to grow 12% over the decade to 2035. That's healthy, above-average growth, and the role should stay in solid demand.

Employment, 2015–2024, projected to 2035
Employment grew 400 to 2024; the dashed line shows the official projection to 2035.

How do you become an it auditor?

Here's the path most it auditors take, step by step.

  1. 1
    Start with a degree

    A bachelor degree in accounting, information systems, computer science or a related field is the usual entry point, and about 52% of the people in the role hold one. Some universities offer a combined accounting and information systems degree, which covers both sides of the job.

  2. 2
    Get a first role that touches controls

    Financial audit at an accounting firm, an internal audit graduate program, IT risk in a bank, or a systems support role with compliance duties all lead here. The point of the first job is to learn how evidence is gathered and how a finding is written up.

  3. 3
    Learn the frameworks on the job

    ISO 27001, the Essential Eight, COBIT and APRA's technology standards are the reference points auditors work from. You learn them by applying them to real systems, not by reading them once.

  4. 4
    Add the CISA certification

    The Certified Information Systems Auditor credential from ISACA is the standard qualification for the field and requires relevant work experience, so most people sit it a few years in. Auditors who came through accounting often hold a CA or CPA as well.

  5. 5
    Choose between in-house and advisory work

    Internal audit teams offer steady hours and deep knowledge of one organisation, while consulting firms bring variety, travel and faster exposure to different industries. Moving between the two later is common and reasonably straightforward.

Ready to apply as an it auditor?

Whether you're working toward becoming an it auditor or already are one and want a hand with the next step (sharpening your resume for ATS screening, tightening your cover letter, or knowing what you'll actually be asked at interview), here are examples grounded in this specific role, not generic templates.

What jobs can an it auditor move to?

Moving into Chief Information Security Officer typically comes with the biggest pay rise, worth $91,000 a year more on average.

Move toTypical pay changeOverlapRetraining
Chief Information Security Officer

Audit and risk background supports leading security strategy, governance and compliance, with a short course to broaden executive leadership.

+$91,000
48%short course
Cyber Security Analyst

Understanding of technology controls and risk supports monitoring threats and incidents, and the audit approach carries across with little retraining.

+$18,800
79%minimal
Penetration Tester

Knowledge of system controls and vulnerabilities supports authorised security testing, with minimal retraining to build exploit techniques.

+$18,200
71%minimal
Cyber Security GRC Specialist

Controls, risk and compliance knowledge carries into security governance and regulatory advisory work, with a short course to bridge.

+$7,800
52%short course
ISO Auditor

Experience auditing technology controls and evidence transfers to certifying management systems against standards, needing a short course in quality frameworks.

$35,400
63%short course

Moves are chosen from Jobs and Skills Australia's Data on Occupation Mobility, which follows income tax records between 2011-12 and 2020-21, together with entry requirements and skill overlap. A known move is one people were seen making in that data. Pay change compares median full-time pay for the two roles.

Who works as an it auditor?

The typical it auditor is 38 years old; 67% are men, 85% work full-time, and full-timers average 38 hours a week.

38
Median age
33%
Female share
85%
Full-time
−2h
vs all-jobs avg

What's it like being an it auditor?

The work runs to an audit cycle: planning and risk assessment first, fieldwork through the middle, then reporting and follow-up. Testing, reading and writing fill most of the week, broken up by interviews and workshops with the teams who run the systems. Full-time weeks average 38 hours, though the weeks before an audit committee meeting run longer.

What people like

  • You see the whole organisation. An audit takes you through trading platforms, payroll, cloud services and the teams that run them, which is hard to get from a single technical role.
  • Findings usually lead to fixes. When you report a gap in access controls or patch management, there is a plan and a deadline attached, and you check back the following year to see whether it held.
  • The subject matter keeps moving. Cloud migration, new privacy rules and ransomware all land on the audit plan within a year or two of arriving, so the reading never stops.
  • The qualification travels. CISA is recognised internationally, and audit and risk skills carry across banking, government and consulting without starting over.

What people find hard

  • You deliver news people don't want. Control owners can be defensive when a finding names their team, and the report goes to people more senior than they are.
  • Evidence gathering drags. Waiting on screenshots, change records or a system owner's calendar can eat days out of a fieldwork window.
  • Reporting deadlines cluster. Audit committee papers fall due on fixed dates, so the final weeks of an audit are long whatever the fieldwork turned up.
  • You audit systems you don't run. You may be testing a platform you have never administered, so the early part of an audit is spent learning how it is supposed to behave.

Based on our synthesis of professional-body surveys and public accounts of the role, not first-person verified reviews.

Which industries employ it auditors?

Financial and Insurance Services employs the largest share of it auditors, followed by Professional, Scientific and Technical Services.

Top employing industries

  1. 1Financial and Insurance Services
  2. 2Professional, Scientific and Technical Services
  3. 3Public Administration and Safety
  4. 4Information Media and Telecommunications
  5. 5Health Care and Social Assistance

Ranked by employment share; the source doesn't publish an exact percentage per industry.

Highest qualification held
Bachelor degree
52%
Postgraduate
26%
Diploma / Advanced Diploma
13%
Other
9%

Will AI replace it auditors?

IT auditing sits in the middle: the testing and evidence gathering that fill most of the week are increasingly automated, while the judgement about what to test and how to report it stays with the auditor. Analytics tools already let an auditor check a whole population instead of a sample, and drafting tools can turn notes into a first version of the working papers. What keeps the exposure moderate is that a finding has to be defensible to an audit committee and sometimes to a regulator, which needs someone who understands both the system and the standard.

high · 50%
moderate · 25%
low · 25%

Share of typical working time by exposure level

  • Control testing across a full data set
    Analytics tools can test every entry in an access log or ledger, so the auditor's time goes into designing the test and chasing the exceptions it throws up.
    30%
    high
  • Interviewing system owners and chasing evidence
    Getting a straight answer about who approved a change or where data actually sits depends on reading the room and knowing which question to ask next.
    25%
    low
  • Judging which risks matter and reporting to the audit committee
    Tools can rank anomalies, but weighing a control gap against the business it affects and explaining that to a board needs context the auditor holds.
    25%
    moderate
  • Writing working papers and draft findings
    Drafting tools produce a usable opening version, though the auditor still has to confirm the wording matches the evidence.
    20%
    high

Moves least exposed to AI

These career moves from it auditor work are rated low for AI exposure:

  • Penetration Tester

    High skill overlap (71%), little retraining to get there, and a low automation-risk profile.

Common questions about becoming an it auditor

Straight answers to the questions people ask most.

How much do IT auditors earn?

$109,200 per year before tax is the median for full-time IT auditors, which means half earn more and half earn less. Banking, insurance and the large consultancies pay above that, and a CISA certification usually puts you in a higher band.

How do you become an IT auditor?

Most people start with a degree in accounting, information systems or a related field, then take a first job in financial audit, internal audit or IT risk. From there you learn the frameworks on real systems and sit the CISA exam once you have the required work experience.

Are IT auditors in demand?

IT auditors are currently in shortage nationally. Employment is projected to grow 12% over the decade to 2035, so the role is a reasonable bet if you already have audit or security experience behind you.

Will AI replace IT auditors?

AI is changing how the testing gets done more than it is removing the role. Analytics tools can now check every transaction in a data set instead of a sample and produce a first draft of the working papers, but deciding what risk matters and defending a finding to an audit committee still needs a person. The work is shifting towards designing the tests and interpreting what they turn up.

What can IT auditors move into?

The controls and risk knowledge you build carries into cyber security analysis or governance, risk and compliance work, and neither needs much retraining. Penetration testing suits auditors who want the technical side, paying $18,200 more. Over time, the audit and risk background supports security leadership such as a chief information security officer role.

What is the difference between an IT auditor and a financial auditor?

Financial auditors test the transactions and balances behind the financial statements, while IT auditors test the systems that produce them and the controls around access, change and data. The two work together on most large audits, so a systems finding often explains a number the financial team is querying.

Related roles

Not sure this is you? Take the career quiz and get a ranked shortlist of roles that fit how you like to work.

careertips is an independent, data-first guide to Australian careers, built to help you understand what a role actually pays and where it can take you, not to sell you something.

Where available, figures are sourced from Jobs and Skills Australia and the Australian Bureau of Statistics (CC BY 4.0). Figures marked * are our own analysis. How we source and label our data. Last updated 2026-09-01.