IT Audit Project Leader - Office of the Auditor General of Canada
- Classification
- AP-03
- Closes
- 2026-06-23
- Score
- 8/10 · Strong opportunity
- Eligibility
- internal
IT Audit Project Leader - Office of the Auditor General of Canada
Three things to notice before you apply
1. Professional value: a career-defining role with solid compensation
The salary range of $113,105 to $141,370 (AP-03 level) is competitive for senior audit professionals, especially given the scope of work at the Office of the Auditor General of Canada. This is not a routine compliance role. As an IT Audit Project Leader, you will be shaping audits that go directly to Parliament and influence public-sector accountability. The OAG is a separate employer under Schedule V of the Financial Administration Act, which means its classification and benefits structure is aligned with the federal public service but with some organizational independence. For someone who already holds the CPA and CISA designations, this role offers a clear career trajectoryâeither deepening technical authority in IT audit or moving into broader audit leadership within government. The fact that the OAG may use this process to build a pool for similar positions across different tenures (indeterminate, term, acting) adds flexibility if you're open to various entry points. That said, the real professional value here is the work itself: auditing the systems that underpin federal programs, and having your findings inform how public money is managed.
2. Work reality: hands-on audit leadership with significant accountability
This is not a desk-job where you review reports from a distance. The essential experience requirements make it clear you will be scoping, planning, executing, and reporting on general IT control audits, IT performance audits, service organization control audits, and risk assessments related to large IT projects. You will also supervise deliverables and assign tasks to team members. The posting mentions up to five days a week on-site presence in Ottawa, plus willingness to travel and work overtime as required. That means the work is collaborative, deadline-driven, and likely involves coordinating with multiple stakeholdersâboth within the OAG and across audited entities. For someone who enjoys being in the middle of complex systems and seeing how controls hold up under scrutiny, this will feel rewarding. For someone looking for a 9-to-5 routine with minimal pressure, the travel and overtime expectations are worth weighing carefully. The OAG also uses a competency model (technical expertise, strategic thinking, collaborative relationships, communication, project management, integrity, innovation) that will be assessed later, so you need to be comfortable with holistic evaluation beyond just ticking boxes.
3. Screening reality: the gate is narrow and credential-heavy
Let's be direct: to be considered for this role you must already hold both a CPA and a CISA designation, have a bachelor's degree, and demonstrate approximately four years of post-designation experience (or two years at AP-02 equivalent at OAG). On top of that, you need at least two years of external financial statement audit experience within the last five years, plus recent and significant experience in IT audit areas like ERP controls (SAP, Oracle, PeopleSoft, Microsoft Dynamics, or others), databases, and operating systems. The language requirement is Bilingual Imperative CBC/CBCâso you must function comfortably in both English and French in an audit context. And security clearance is Secret, which is a step above Reliability. For any external applicant, this is a serious filter. Preference is also given to veterans, OAG employees, and federal public servants before Canadian citizens and permanent residents. That means if there are internal candidates already at AP-02 with the right credentials, they may get first consideration. My read is that the OAG is using this posting to target a very specific profileâsomeone who is already a fully qualified audit professional with IT specialization and bilingual fluency. If that describes you, this is a strong opportunity. If you're missing even one essential, the application will not proceed.
What this IT Audit Project Leader actually does
The duties implied by the essential experience go beyond generic project management. You will lead audits that examine general IT controlsâthe policies, procedures, and technical safeguards that protect financial systems. This includes evaluating controls within enterprise resource planning (ERP) environments like SAP or Oracle, assessing operating system security, and reviewing databases. In addition, you will write analyses and findings and present recommendations. That means your output flows directly into audit reports that are tabled in Parliament. The role also involves supervising and assigning audit tasks to team members, so you need to balance technical depth with people management. The OAG's competency model emphasizes "personal and people development skills" and "productive and collaborative relationships," so the day-to-day likely involves mentoring junior auditors and liaising with stakeholders in audited departments.
Because the posting mentions service organization control audits and assessments of large IT projects, you may also evaluate third-party service providers or major system implementations across government. This is not narrow compliance workâit evolves with the technology landscape. The OAG also signals that emerging technology (AI, robotic process automation, cloud computing) is an asset qualification, which suggests the audit methodologies are adapting to new risks. If you have experience in those areas, you can differentiate yourself.
The screening puzzle: credentials, experience, and language
The essential criteria are unusually specific. Many Government of Canada jobs ask for broad "experience in auditing" without designations. Here, you cannot substitute a degree plus years of experience for the CPA and CISA. Those are hard requirements. The experience thresholds are also narrow: "approximately four years post-designation experience" and "at least two years of external financial statement audit experience gained within the last five years." That last piece is criticalâif your external audit experience is older than five years, or if it's internal audit only, you may not meet the bar. The OAG also requires recent and significant experience in IT controls across specific ERP systems, databases, and operating systems. They define "recent and significant" as approximately two years of continuous duties within the past five years. So your application needs to clearly show not just that you've done IT audit, but that you've done it consistently and recently.
Language assessment (CBC/CBC) will be applied later, but you should be ready for a rigorous evaluation. The OAG is a separate employer and may have its own testing standards. If you are not fully bilingual, this is not the role to "grow into" the language. You need to have it already.
The security clearance process for Secret can take months, but the closing date is June 2026, so there is time. Do not assume this is an immediate hireâit may be used to build a pool for future vacancies.
Why the asset qualifications matter more than they appear
The asset qualifications listed are not afterthoughtsâthey are likely used for top-down selection. The OAG reserves the right to retain "a specific number of candidates who best meet the essential qualifications," and may also use asset qualifications at any stage. That means if there are dozens of applicants who meet the essentials, those with additional certifications (CISM, CRISC, CISSP) or experience in large IT project audits, cyber security, or emerging technology will float to the top. If you hold any of those, make sure to highlight them prominently. If you don't, you can still be considered, but the competition may be steeper.
The knowledge of industry frameworks (COBIT, IIA, NIST, ITIL, TBS policies) is also an asset. In your application, you can briefly reference which frameworks you have applied in past audits. The OAG may assess this later, but having it on your résumé early helps you get past the initial screen.
One more thing: the posting mentions "experience using emerging technology, such as artificial intelligence, in the conduct of external financial audits." If you have used data analytics tools or automated audit procedures, describe that concretely. Even if you don't have CISM, this kind of forward-looking experience can make your application stand out.
Should you apply? Next steps and honest warnings
This role is worth serious effort if you meet the essential criteria. The salary, the nature of the work, and the prestige of the OAG make it a strong opportunity. However, there are real risks for external applicants. Preference for internal candidates, deployment priority, and the possibility of random or top-down selection mean your application might not even reach the assessment stage if enough internal candidates are available. That is not a reason to skip itâapply if you fit, but do not treat it as a guaranteed shot.
The closing date is June 23, 2026, so there is no urgency. You have time to prepare a strong application. Focus on your résumé and a text answer that directly maps to each essential experience requirement. Use the same language from the posting: "scoping, planning, executing, reporting of general IT control audits," "managing and supervising project deliverables," "writing analyses and findings." Be explicit about the ERP systems and operating systems you have audited.
Also note the text question: "Travaillez-vous actuellement au Bureau du vérificateur général du Canada ou y avez-vous déjà travaillé?" is asked in French. That is a signal that bilingualism is taken seriously from the first step.
If you are missing one essential, do not apply. This is not a role where you can "learn on the job." Missing an essential criterion is a real riskâyour application will be screened out.
Practical next move: Review your experience against the essentials. If you have the CPA, CISA, recent external financial statement audit experience, and bilingualism, start drafting your rĂ©sumĂ© and addressing the competency model (especially technical subject matter expertise and strategic thinking). FedJobReady can help you align your narrative with the OAG's expectations, particularly around recent and significant experience and the seven competency areas. The paid help is worth using here because the evidence burden is highâone vague bullet point could sink you. Apply cleanly, with precision, and then move on to other opportunities. If you don't meet the bar, do not waste your whole weekend on this. There will be other federal audit roles that are more accessible.