I'm an IT auditor in Columbus, Ohio. I've been doing SOC 1 and SOC 2 examinations since 2023. Lately most of my own time outside work goes toward learning to build the controls I spend my days testing.

How I got here

I started college as a computer engineering major and had to drop it midway through the year.

I ended up finishing an accounting degree at Ohio State instead, and did two tax internships along the way. I was good enough at it, but I couldn't picture still loving it in twenty years.

When I graduated I had two offers on the table: financial audit at a Big 4, or IT audit at a newer firm. People wanted me to take the Big 4 offer. I took the other one instead, mostly because it was the one that put me closer to what I am truly interested in, technology.

I sat for the CPA later and passed in 2025. It meant a lot to me going through that process and earning the mark of the profession in accounting. To me, it signals trust, and that transfers to all parts of a business.

Why I started building things

A few years into examinations now, the part of the job that still bothers me is evidence collection.

So much of audit work is chasing down screenshots. I ask a control owner to prove some setting is what they say it is, they go find it, send it over, I tie it out, and then we do the exact same thing again next year. There is nothing inherently wrong with this. It's just a lot of effort to re-prove something the system already knows.

What gets me is none of that actually has to be rebuilt after the fact. If the infrastructure was built with security in mind in the first place, the proof is already sitting in the code and the version history. The evidence is seamlessly collected all throughout the audit period and is ready at a moment's notice.