IT Audit Lead

Fred Loya Insurance Agency

San Antonio (TX)

On-site

USD 120,000 - 160,000

Full time

25 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Loya Insurance is seeking an experienced IT Audit Lead to build and scale a technology audit and assurance capability. This role will provide independent, risk-based assurance over IT controls supporting financial reporting, cybersecurity, data privacy, regulatory compliance, and critical business operations.

The successful candidate will blend strong audit judgment with technical depth to engage with engineers, security leaders, data teams, and executives.

Qualifications

  • Bachelor’s degree or equivalent experience in a related field.
  • 8+ years of progressive experience in IT audit, technology risk, or cybersecurity assurance.
  • Experience leading complex technology audits from assessment to reporting and follow-up.
  • Strong knowledge of IT general controls and technology risk across IAM, PAM, change management, cloud, and third-party risk.
  • Ability to translate technical risk into business terms and actionable remediation.

Responsibilities

  • Develop and maintain a risk-based technology audit universe and annual assurance plan.
  • Lead technology audits from planning through testing, reporting, and remediation follow-up.
  • Assess IT general controls across identity management, privileged access, change management, and infrastructure.
  • Evaluate controls supporting SOX 404, GLBA, and NAIC cybersecurity expectations.
  • Communicate audit findings and risk implications to senior leadership.

Skills

Audit leadership
IT risk assessment
Communication skills
Problem solving
Independent judgment

Education

Bachelor's degree in information systems or related field
Equivalent relevant experience

Tools

SQL
Python
PowerShell
APIs
BI tools
GRC platforms

Job description

Loya Insurance is seeking a hands-on IT Audit Lead to build and lead a scalable technology audit and assurance capability. The role will provide independent, risk-based assurance over the technology controls that support financial reporting, cybersecurity, data privacy, regulatory compliance, and critical business operations.

The successful candidate will combine strong audit judgment with enough technical depth to work credibly with engineers, security leaders, data teams, and senior executives.

Key Responsibilities
  • Assist with the develop and maintain a risk-based technology audit universe and annual assurance plan aligned with enterprise risk and regulatory priorities.
  • Lead complex technology audits from planning and scoping through testing, reporting, and remediation follow-up.
  • Assess IT general controls and technology risks across identity and access management, privileged access, change management, infrastructure, cloud, applications, cybersecurity, resilience, and third parties.
  • Evaluate technology controls supporting a SOX 404 environment, Gramm-Leach-Bliley Act (GLBA), NAIC cybersecurity expectations, financial reporting, privacy, and critical operations.
  • Establish practical audit methodology, evidence standards, workpaper expectations, repeatable testing, issue validation, and risk reporting.
  • Translate technical observations into clear business risk, root cause, impact, accountable ownership, and actionable remediation recommendations.
  • Partner constructively with Technology, Cybersecurity, Compliance, Finance, Data, and AI teams while maintaining third-line independence.
  • Use data analytics, scripting, APIs, GRC tooling, or other automation to expand coverage and reduce dependence on manual sampling.
  • Provide concise reporting on technology risk themes, audit results, remediation progress, emerging threats, and significant initiatives to senior leadership.
Required Qualifications and Skills
  • Bachelor’s degree in information systems, computer science, accounting, finance, cybersecurity, business, or a related field; equivalent relevant experience may be considered in lieu of degree.
  • Eight or more years of progressive experience in IT audit, technology risk, cybersecurity assurance, technology controls, or a closely related discipline.
  • Demonstrated experience leading complex technology audits and managing work from risk assessment through final reporting and issue follow-up.
  • Strong working knowledge of IT general controls, including logical access, privileged access, change management, technology operations, backup and recovery, and third-party technology risk.
  • Ability to assess control design and operating effectiveness, evaluate evidence, identify root cause, and develop risk-based conclusions.
  • Strong written, verbal, workshop facilitation, and presentation skills, including the ability to explain technical risk in business terms.
  • Sound judgment, professional skepticism, independence, and the ability to operate effectively in a changing environment with limited existing structure.
Preferred Qualifications and Skills
  • Experience building or enhancing the maturity of an IT audit, technology assurance, or technology risk program.
  • Insurance or other regulated financial-services experience, including exposure to a SOX 404 environment, GLBA, NAIC cybersecurity requirements, or comparable regulatory frameworks.
  • Working knowledge of modern IT environments and related controls, including cloud infrastructure, network and endpoint security, identity and privileged access management (IAM/PAM), vulnerability management, system development and change management (SDLC/DevOps), APIs, and cybersecurity practices.
  • Experience assessing data governance, privacy, artificial intelligence, model risk, or automated decision systems.
  • Hands-on experience with audit analytics or automation using SQL, Python, PowerShell, APIs, BI tools, or GRC platforms.
  • Experience presenting to senior executives, or a board-level audience.
  • CISA strongly preferred. CISSP, CIA, CRISC, CPA, CCSK, or relevant cloud/security certifications are additional strengths; technical depth and judgment should take precedence over certification count.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior IT Audit Lead: Tech Risk & Assurance Leader
Senior IT Audit Lead: Tech Risk & Assurance Leader

Fred Loya Insurance Agency • San Antonio (TX)

On-site
USD 120,000 - 160,000
IT Audit Controls & SOX Senior Manager
IT Audit Controls & SOX Senior Manager

Madison-Davis, LLC • San Francisco (CA)

On-site
USD 150,000 - 210,000
Director Information Technology Audit (Cybersecurity, Cloud & AI)
Director Information Technology Audit (Cybersecurity, Cloud & AI)

TechMind RPO Pvt. Ltd. • Washington

Hybrid
USD 150,000 - 210,000
Senior IT Auditor
Senior IT Auditor

LHH • Houston (TX)

On-site
USD 110,000 - 150,000
Lead IT Auditor – $105-125K Plus Bonus
Lead IT Auditor – $105-125K Plus Bonus

ACCsurance, LLC • United States

On-site
USD 100,000 - 130,000
401k Match up to 6%
$9,000 in Student Loan Forgiveness
$12,000 in Home-buyers Assistance
+2
Senior Information Technology Auditor
Senior Information Technology Auditor

Leeds Professional Resources • Miami (FL)

On-site
USD 95,000 - 130,000
IT Controls & SOX Manager
IT Controls & SOX Manager

Madison-Davis, LLC • San Francisco (CA)

Hybrid
USD 120,000 - 180,000
IT Auditor
IT Auditor

Oliver James Group • Des Moines (IA)

Hybrid
USD 90,000 - 120,000
Relocation assistance
IT Auditor
IT Auditor

Oliver James Associates Ltd. • Des Moines (IA)

On-site
USD 85,000 - 110,000
Relocation assistance
IT Audit Manager – $115-135K Plus 15-20% Bonus
IT Audit Manager – $115-135K Plus 15-20% Bonus

ACCsurance, LLC • United States

On-site
USD 80,000 - 120,000
Outstanding benefits package
Work/life balance
Discounted ESOP program
+1