The Managing Director will provide strategic leadership and enterprise-wide oversight of audit coverage across Cybersecurity and Core Technology, setting direction for audit strategy, testing priorities, and integrated risk coverage. The role partners with business, technology, control, and audit stakeholders while leading the directors accountable for portfolio execution.
Location
Chicago, IL (onsite)
Compensation
USD 200,000 - 260,000 per year
Key Responsibilities
- Define and execute a risk-based, integrated audit strategy across Cybersecurity and Core Technology, including current and emerging risk reviews.
- Lead ongoing risk assessment activities and develop audit coverage approaches to deliver independent assurance over cybersecurity and core technology risks, control effectiveness, and risk management practices.
- Strengthen audit capabilities through workforce planning, technical specialization, succession management, methodology enhancements, and targeted capability development across cyber, cloud, infrastructure, engineering, and technology operations risk domains.
- Maintain integrated, risk-based audit coverage spanning cybersecurity, engineering, technology operations, service management, platform support, cloud, infrastructure, software delivery, operational resilience, and third-party ecosystems, with emphasis on systemic risks, enterprise-wide control dependencies, and emerging technology risks.
- Serve as the senior audit relationship lead for technology executives, including CISOs, engineering, infrastructure, and operations leadership, while sustaining strategic partnerships with regulators, control functions, and other key stakeholders.
- Lead audit support for regulatory examinations, horizontal reviews, regulatory commitments, and remediation activities related to cybersecurity and core technology, ensuring audit insights and risk perspectives are communicated effectively.
- Ensure audit quality, consistency, and timeliness using standardized methodologies, reusable testing approaches, and continuous improvement practices, including proactive engagement and continuous monitoring for end-to-end risk visibility and timely reprioritization.
- Drive adoption of analytics, continuous assurance, and AI-enabled auditing for forward-looking risk insights, including AI-enabled threats and advanced cyber risks.
- Deliver thematic insights and root-cause analysis across technology domains, providing enterprise-wide risk perspectives.
- Promote and support the Bank’s risk culture by ensuring employees understand their accountabilities for risk-taking activities, encouraging open communication and effective challenge, and demonstrating tone from the top.
Required Qualifications
- 15+ years of experience in Internal Audit, Technology Audit, Cybersecurity, or Risk Management within large financial institutions.
- Senior leadership experience overseeing complex technology domains, including cybersecurity, infrastructure, cloud, engineering, technology operations, and operational resilience.
- Deep expertise in cybersecurity, technology infrastructure, engineering practices, service management, operational resilience, and technology risk management, with demonstrated ability to lead integrated audit programs across multiple risk domains.
- Strong experience engaging regulators and executive stakeholders, including CIO, CISO, and regulators.
- Demonstrated track record of driving audit transformation, including analytics, automation, and continuous auditing.
- Experience leading geographically dispersed teams, building and scaling high-performing teams, and delivering capability uplift in specialized domains.
- Strong understanding of technology risk management and emerging risks, including artificial intelligence, AI-enabled threats, quantum computing implications, technology transformation, evolving regulatory expectations, and advanced supply chain dependencies.
- One or more professional certifications in information systems audit, cybersecurity, or technology risk management required (for example, CISA or CISSP).
Preferred Certifications
- Additional certifications in cloud platform/security, cybersecurity, network security, service management, or resilience (for example, CISM, CCSP, CCSK, GIAC, ITIL).
Relevant Technologies
- Analytics
- Continuous assurance
- AI-enabled auditing
- Artificial intelligence
- Quantum computing
- CISA, CISSP
- CISM, CCSP, CCSK
- GIAC
- ITIL
People & Culture Leadership
- Models simplicity and productivity enhancements for optimization across groups, supporting continuous improvement on key measures.
- Activates a winning culture aligned to Purpose by aligning culture to strategy and enabling exceptional execution.
- Fosters an inclusive environment by eliminating barriers to inclusion.
- Develops leaders, plans for succession, and fosters a high-performance culture.
- Drives top talent acquisition and retention while developing organizational capabilities for competitive advantage.
- Leads and mentors a team with diverse risk and business experience, skills, and orientation.
- Leads, promotes, and reinforces the Bank’s Ambition; personally role models One Bank leadership; drives sustainable improvements in customer loyalty and business growth; adheres to and supports enterprise customer experience and brand standards.