Position Title - Senior IT Audit Manager
Location – New York City, New York (Hybrid 3 days in office – Midtown Manhattan)
Summary
The Senior IT Audit Manager is a newly opened opportunity due to organic company growth within a 100-year-old publicly traded financial services banking institution. Based out of the company’s midtown Manhattan office, this hybrid flexible role will report directly to the Deputy Chief Audit Officer and provide critical support in planning, supervising, and executing the Internal IT Audit plan, with a primary focus on Information Technology and Information Security risks. The Senior IT Audit Manager will offer a base salary in the $160,000 to $190,000 range based on experience, a 10-15% annual bonus, and a comprehensive benefits package. Ideal candidates will have 8 or more years of professional experience including related IT Audit experience in public accounting or a combination of public accounting and internal IT Audit experience with exposure to financial services organizations. This is an unique opportunity for candidates currently in public accounting interested in transitioning into a highly respected and growing NYC based organization.
Job Description
- Serves as a subject matter expert in technology and cyber risk while also providing audit coverage across other critical areas including Commercial Banking, Risk Management, and Operations.
- Responsible for leading complex, risk-based audits; assessing governance, risk management, and control effectiveness; and ensuring audit activities align with professional standards, regulatory expectations, and industry best practices.
- Lead and supervise internal audits and targeted reviews with a primary emphasis on Information Technology, Information Security, cybersecurity, technology governance, third-party risk management, data protection, and system development life cycle controls.
- Serve as the Internal Audit subject matter expert for IT and Information Security, including identifying emerging technology and cyber risks relevant to the Bank.
- Plan and execute audits across multiple business lines, including IT, Commercial Banking, Risk Management, and Bank Operations, ensuring appropriate integration of technology risks into all audits.
- Integrate data analytics and AI audit methodologies into the overall audit framework.
- Develop audit scopes, perform risk assessments, oversee testing, validate issues, and ensure appropriate coverage of IT-dependent controls.
- Identify control deficiencies, assess root causes and impact, and recommend practical, risk-based remediation strategies.
- Review and approve audit workpapers to ensure accuracy, completeness, and adherence to Internal Audit standards.
- Prepare, review, and edit audit reports to clearly communicate technology, information security, and business risks from a senior management and Audit Committee perspective.
- Evaluate management action plans and monitor the remediation of IT, information security, and business audit issues.
- Coordinate audit activities with internal stakeholders, regulators, and external or co-source auditors, particularly for targeted technology and cybersecurity reviews.
- Support enterprise risk assessment, SOX, and regulatory examination activities where technology or data risks are present.
- Provide coaching, technical guidance, and performance feedback to audit staff and managers.
- Stay current on regulatory guidance, industry standards, and emerging risks related to IT and information security, including FFIEC, NIST, and cybersecurity frameworks.
- Assist the DCAO with departmental initiatives, strategic projects, and regulatory or Board-level requests as assigned.
Position Requirements
- Bachelor’s degree in Accounting, Finance, Information Systems, Computer Science, ora related field.
- Minimum of 8–10 years of progressive internal audit, IT audit, information security, or risk management experience within a regulated financial services environment.
- Professional certification such as CISA strongly preferred; CIA or CPA a plus.
- Certification or training in AI ethics, data governance, or model risk management (e.g., MIT AI Ethics, NIST AI Risk Framework).
- Demonstrated experience leading complex IT and information security audits and supervising audit staff.
- Significant experience auditing or managing risks in data analytics, machine learning, or AI environments.
- Strong understanding of IT general controls, cybersecurity, cloud environments, data governance, third-party risk, and SDLC controls.
- Deep knowledge of AI/ML systems, model lifecycle, and related controls.
- Understanding of data analytics tools (e.g., Tableau, Python, SQL, Power BI, R) and audit automation.
- Working knowledge of banking regulations and technology-related regulatory expectations (e.g., FFIEC, OCC, FDIC guidance).
- Understanding of COSO internal control framework and its application to technology-enabled processes.