Manager, IT Auditor

Bain & Company

Dallas (TX)

Hybrid

USD 105,000 - 126,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Hybrid work model

Job summary

Bain & Company is seeking an IT Auditor Manager to lead IT audit engagements across technology risk areas, including cybersecurity, data governance, and AI risk. You will interact with senior leadership, foster collaboration across defense lines, and drive improvements in control effectiveness.

The role emphasizes risk-based assurance and continuous monitoring in a hybrid work model. The position requires strong IT audit expertise, COSO/COBIT/NIST framework knowledge, and experience coaching

Qualifications

  • Bachelor’s degree in IT, CS, AIS or related field; advanced degree preferred.
  • 6–9 years of IT audit, cybersecurity, or IT risk management experience; 2–3 years leading engagements.

Responsibilities

  • Lead IT audit engagements within the annual plan with risk-based procedures.
  • Assess governance and controls around AI/generative AI tools and data privacy.
  • Design audit programs, walkthroughs, sampling strategies, and test procedures.
  • Test IT general controls: access, change/config, operations, backups.
  • Test cybersecurity controls: patch management, monitoring, identity security, incident response.

Skills

IT risk knowledge
IA methodology
Data governance
AI risk
Stakeholder communication
Coaching/mentoring

Education

Bachelor’s degree in IT/CS/AIS
Advanced degree preferred

Tools

SQL
Power BI
ACL/Galvanize
Claude/ChatGPT

Job description

We are proud to be consistently recognized as one of the world’s best places to work, a champion of diversity and a model of social responsibility. Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.

WHERE YOU’LL FIT WITHIN THE TEAM

As a Manager, IT Auditor, you will hold a senior individual contributor role within the Internal Audit function, operating as part of the organization’s third line of defense. In this role, you will work closely with Global Internal Audit leadership, which reports directly into the Chief Risk Officer and the Board Risk Subcommittee. Your work will focus on providing independent assurance over the design and operating effectiveness of the organization’s technology processes and controls through risk-based audit engagements, delivering insights that help management strengthen technology processes, controls, and risk management practices.

Perform and lead assigned IT audit engagements across technology risk areas such as cybersecurity, cloud environments, AI and generative AI, third‑party risk, data governance, and IT operations. You will lead end‑to‑end audit engagements on a continuous or risk‑based cycle throughout the year, bringing strong IT audit knowledge and a risk‑based perspective to each engagement. The role carries no direct reports to start; you will coach team members on engagements, with the opportunity to take on formal supervisory responsibility as the function grows.

WHAT YOU’LL DO
Audit Planning & Execution
  • Lead assigned IT audit engagements within the approved annual audit plan, developing risk‑based audit procedures and testing approaches consistent with established audit methodology and risk priorities.
  • Assess the governance and controls around AI and generative AI tools (e.g., Claude, ChatGPT, Copilot), acceptable use, data privacy, model and vendor due diligence, human‑in‑the‑loop review, and output validation.
  • Design audit programs, end‑to‑end process walkthroughs, test procedures, and sampling strategies tailored to the risk profile of each engagement.
  • Test core IT general controls, covering logical access and periodic user access reviews, change and configuration management, IT operations and job scheduling, and backup and recovery.
  • Test cybersecurity controls, covering vulnerability and patch management, security monitoring and threat detection, identity and access security, and incident response readiness.
  • Audit data governance and oversight, including data ownership and stewardship, classification and retention, data quality controls, traceability and access rights, and the effectiveness of governance forums in exercising oversight over data use.
  • Identify process gaps and control design weaknesses and recommend sustainable, repeatable control improvements to process owners.
  • Review the software development lifecycle, including design approval, secure coding, testing and UAT, release management, segregation of duties, and post‑implementation review.
Governance & Stakeholder Engagement
  • Present audit findings, recommendations, and status updates to senior internal management.
  • Provide guidance to stakeholders on IT audit findings, control effectiveness, and identified technology risks.
  • Collaborate with the first and second lines of defense to understand and support alignment on established control objectives and risk tolerances.
  • Recommend improvements to key controls in collaboration with process and control owners, identify opportunities to reduce duplicative or low‑value controls and recommend appropriate improvements, and identify opportunities to improve continuous control monitoring and automated testing.
  • Coordinate with external certification bodies, assessors, and third‑parties in support of external certification and attestation programs (e.g., CMMC, ISO 27001, SOC 1/SOC 2), including readiness assessments, evidence requests, and findings follow‑up.
Reporting & Issue Management
  • Produce high‑quality internal audit reports with clear, risk‑rated findings and actionable recommendations.
  • Perform root‑cause analysis on control failures, distinguishing design gaps from execution breakdowns so remediation addresses the underlying process rather than the symptom.
  • Monitor remediation progress, assess management action plans, validate completion of agreed actions, and report status to relevant stakeholders.
  • Maintain audit documentation in accordance with IIA Standards and internal quality assurance requirements.
  • Coach and support team members during assigned audit engagements and provide feedback to promote consistent application of audit methodology.
  • Peer review workpapers and support consistent application of established audit methodology across assigned engagements.
  • Contribute to enhancements to IT audit tools, analytics, and audit practices, including appropriate use of AI‑enabled automation to support audit planning, testing, and reporting.
ABOUT YOU
Required Knowledge, Skills & Abilities
  • Deep understanding of IT risk, control frameworks, and audit methodology (IIA Standards, COSO, COBIT, NIST Cybersecurity Framework).
  • Strong knowledge of IT general controls and IT audit methodology, with working knowledge of cybersecurity, cloud risk, vendor management, and related technology risk areas sufficient to assess controls against established frameworks.
  • Practical experience auditing data governance and oversight frameworks, including data ownership, classification and retention, data quality, and data traceability.
  • Working knowledge of application development lifecycle and change management controls across waterfall, agile, and DevOps delivery models.
  • Familiarity with AI risk and governance frameworks (NIST AI RMF, ISO/IEC 42001, EU AI Act) as applied to enterprise AI deployments.
  • Experience supporting external certification and attestation engagements (e.g., CMMC, ISO 27001, SOC 1/SOC 2), including interfacing directly with certification bodies, assessors, or third‑parties.
  • Proficiency with analytics tools (SQL, Power BI, ACL/Galvanize) and AI assistants such as Claude or ChatGPT to support continuous auditing and automation.
  • Able to convey complex technical risk, in writing and verbally, to non‑technical audiences and manage stakeholders at all levels.
  • Able to coach colleagues and peer review workpapers, holding engagements to a consistent methodology and quality standard.
  • High degree of professional scepticism, integrity, and objectivity.
Experience & Qualifications
  • Bachelor’s degree in Information Technology, Computer Science, Accounting Information Systems, or a related field; advanced degree preferred.
  • 6-9 years of progressive experience in IT audit, cybersecurity, or IT risk management, including 2-3 years leading audit engagements end to end.
  • Prior experience in a Big 4, consulting firm, or regulated industry is a strong asset.
Certifications
  • CISA – Certified Information Systems Auditor
Additional Credentials Valued
  • CRISC – Certified in Risk & Information Systems Control
  • Cloud or cyber risk credentials (e.g., CCSP, Security+)
  • AI governance credentials (e.g., IAPP AIGP, ISO/IEC 42001 Lead Auditor)
US COMPENSATION INFORMATION

Compensation for this role includes base salary, annual discretionary performance bonus, 401(k) plan with an annual employer contribution based on years of service and Bain’s best in class benefits package (details listed below).

Some local governments in the United States require a good‑faith, reasonable salary range to be included in job postings for open roles. The estimated annualized compensation for this role is as follows:

  • In Georgia, the good‑faith, reasonable annualized full‑time salary range for this role is between $99,500 and $119,500.
  • In Massachusetts, the good‑faith, reasonable annualized full‑time salary range for this role is between $114,500 and $137,500.
  • In Texas, the good‑faith, reasonable annualized full‑time salary range for this role is between $104,500 and $125,500.

Placement within this range will vary based on several factors including, but not limited to experience, education, licensure/certifications, training and skill level.

  • Annual discretionary performance bonus
  • This role may also be eligible for other elements of discretionary compensation
  • 4.5% 401(k) company contribution, which increases after 3 years of service and is 100% vested upon start date

Bain & Company's comprehensive benefits and wellness program is designed to help employees achieve personal independence, protection and stability in the areas most important to you and your family.

  • Bain pays 100% individual employee premiums for medical, dental and vision programs, offering one of the most comprehensive medical plans for employees without impacting your paycheck
  • Generous paid time off, including parental leave, sick leave and paid holidays
  • Fully vested 401(k) company contribution
  • Paid Life and Long‑Term Disability insurance
WORKING MODEL / TRAVEL
  • This role follows a hybrid model, requiring in‑office presence at least one day per week.

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Manager, IT Auditor
Manager, IT Auditor

Bain & Company • Boston (MA)

Hybrid
USD 115,000 - 138,000
Discretionary bonus
401(k) company contribution
Paid time off
Manager, IT Auditor
Manager, IT Auditor

Bain & Company • Atlanta (GA)

Hybrid
USD 100,000 - 120,000
Medical and dental coverage
Generous paid time off
Fully vested 401(k)
+1
Expert Senior Manager, AI Engineering
Expert Senior Manager, AI Engineering

Bain & Company • Dallas (TX)

On-site
USD 258,000 - 294,000
Discretionary bonus
401(k) plan
Medical, dental, vision
+1
Expert Senior Manager, AI Engineering
Expert Senior Manager, AI Engineering

Bain & Company • Seattle (WA)

On-site
USD 258,000 - 294,000
Annual discretionary performance bonus
401(k) match
Benefits & wellness program
+4
Expert Senior Manager, AI Engineering
Expert Senior Manager, AI Engineering

Bain & Company • Houston (TX)

On-site
USD 258,000 - 294,000
401(k) plan
Excellent benefits
Fitness reimbursements
+1
Expert Senior Manager, AI Engineering
Expert Senior Manager, AI Engineering

Bain & Company • San Francisco (CA)

Hybrid
USD 260,000 - 320,000
Annual discretionary bonus
401(k) plan with employer contribution
Medical, dental and vision benefits
+1
Expert Senior Manager, AI Engineering
Expert Senior Manager, AI Engineering

Bain & Company • Chicago (IL)

Hybrid
USD 240,000 - 270,000
Annual discretionary bonus
401(k) with company contribution
Fully vested 401(k)
+5
Expert Senior Manager, AI Engineering
Expert Senior Manager, AI Engineering

Bain & Company • New York (NY)

On-site
USD 258,000 - 294,000
Annual discretionary performance bonus
401(k) company contribution
Health, dental, and vision benefits
+1
Expert Senior Manager, AI Engineering
Expert Senior Manager, AI Engineering

Bain & Company • Atlanta (GA)

On-site
USD 258,000 - 293,000
Expert Senior Manager, Engineering Excellence
Expert Senior Manager, Engineering Excellence

Bain & Company • Harrisburg, Atlanta (GA)

Hybrid
USD 258,000 - 294,000