A leading financial institution is seeking an experienced Senior Manager of Internal Audit to help drive the organization’s risk-based audit program, with a strong concentration on Information Technology, Cybersecurity, and Information Security. This individual will partner closely with senior audit leadership while serving as a trusted advisor on technology and emerging risks.
About the Role
In addition to technology-focused audits, the role will provide audit leadership across key areas of the business, including Commercial Banking, Risk Management, and Operations. The ideal candidate brings strong technical expertise, sound judgment, and the ability to communicate complex technology and control matters to executive leadership and the Audit Committee.
Responsibilities
- Lead end-to-end internal audits, risk assessments, and special reviews focused on IT, cybersecurity, information security, technology governance, cloud environments, data protection, third-party risk, and SDLC processes.
- Act as a senior technology and cyber risk advisor within Internal Audit, monitoring emerging threats and evaluating their potential impact on the organization.
- Manage audits across technology and business functions, incorporating relevant technology and IT-dependent controls into broader audit engagements.
- Expand the use of data analytics, automation, and AI-enabled audit techniques to improve audit coverage and effectiveness.
- Establish audit objectives, scope, and testing strategies based on enterprise risk assessments and applicable regulatory requirements.
- Evaluate control design and operating effectiveness, identify deficiencies, determine root causes, and develop practical recommendations for remediation.
- Review audit documentation and workpapers for quality, accuracy, consistency, and compliance with Internal Audit methodology.
- Draft and review audit reports that clearly articulate key risks, control weaknesses, and recommended actions for senior management and the Audit Committee.
- Track management responses and remediation efforts, ensuring identified technology and business risks are appropriately addressed.
- Collaborate with business leaders, regulators, external auditors, and co-sourced providers on technology, cybersecurity, and other specialized reviews.
- Contribute to enterprise risk assessments, SOX activities, regulatory examinations, and other risk and control initiatives involving technology or data.
- Provide leadership, mentorship, and technical direction to auditors and managers, supporting the development of a high-performing audit team.
- Maintain current knowledge of banking regulations, cybersecurity developments, and recognized frameworks, including FFIEC, NIST, COSO, and related industry standards.
- Support senior audit leadership with strategic initiatives, special projects, Board-level requests, and other high-priority assignments.
Qualifications
- Bachelor’s degree in Accounting, Finance, Information Systems, Computer Science, or a related discipline.
- 8+ years of progressive experience in internal audit, IT audit, information security, technology risk, or related risk management functions, preferably within banking or another highly regulated financial services environment.
- CISA, CIA, or CPA certification preferred.
- Additional education or credentials related to AI governance, data governance, AI ethics, or model risk management are a plus.
Required Skills
- Proven ability to lead complex technology, cybersecurity, and information security audits while managing and developing audit professionals.
- Strong understanding of IT general controls, cybersecurity, cloud technology, data governance, third-party risk, SDLC, and technology-enabled business processes.
- Experience evaluating controls surrounding AI/ML technologies, model development and deployment, data analytics, or emerging technology risks.
- Familiarity with analytics and automation tools such as SQL, Python, Tableau, Power BI, or R.
- Knowledge of banking regulatory requirements and technology risk expectations, including guidance from the OCC, FDIC, and FFIEC.
- Understanding of the COSO internal control framework and its application within technology-driven environments.
- Exceptional analytical, organizational, and project management capabilities.
- Strong written and verbal communication skills, including the ability to translate highly technical findings into clear business and risk implications for executives and Audit Committee members.
Preferred Skills
The successful candidate will combine technology and cybersecurity expertise with strong internal audit leadership skills. You should be comfortable operating independently, challenging processes constructively, managing complex engagements, and communicating effectively with stakeholders ranging from technical teams to executive leadership.