Manager, IT Auditor
Listed on 2026-09-25
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Business Analyst
WHAT MAKES US A GREAT PLACE TO WORK
We are proud to be consistently recognized as one of the world’s best places to work, a champion of diversity and a model of social responsibility. Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment.
We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.
As a Manager, IT Auditor, you will hold a senior individual contributor role within the Internal Audit function, operating as part of the organization’s third line of defense. In this role, you will work closely with Global Internal Audit leadership, which reports directly into the Chief Risk Officer and the Board Risk Subcommittee. Your work will focus on providing independent assurance over the design and operating effectiveness of the organization’s technology processes and controls through risk-based audit engagements, delivering insights that help management strengthen technology processes, controls, and risk management practices.
Perform and lead assigned IT audit engagements across technology risk areas such as cybersecurity, cloud environments, AI and generative AI, third-party risk, data governance, and IT operations. You will lead end-to-end audit engagements on a continuous or risk-based cycle throughout the year, bringing strong IT audit knowledge and a risk-based perspective to each engagement. The role carries no direct reports to start;
you will coach team members on engagements, with the opportunity to take on formal supervisory responsibility as the function grows.
Audit Planning & Execution
- Lead assigned IT audit engagements within the approved annual audit plan, developing risk-based audit procedures and testing approaches consistent with established audit methodology and risk priorities.
- Assess the governance and controls around AI and generative AI tools (e.g., Claude, ChatGPT, Copilot), acceptable use, data privacy, model and vendor due diligence, human-in-the-loop review, and output validation.
- Design audit programs, end-to-end process walkthroughs, test procedures, and sampling strategies tailored to the risk profile of each engagement.
- Test core IT general controls, covering logical access and periodic user access reviews, change and configuration management, IT operations and job scheduling, and backup and recovery.
- Test cybersecurity controls, covering vulnerability and patch management, security monitoring and threat detection, identity and access security, and incident response readiness.
- Audit data governance and oversight, including data ownership and stewardship, classification and retention, data quality controls, traceability and access rights, and the effectiveness of governance forums in exercising oversight over data use.
- Identify process gaps and control design weaknesses and recommend sustainable, repeatable control improvements to process owners.
- Review the software development lifecycle, including design approval, secure coding, testing and UAT, release management, segregation of duties, and post-implementation review.
- Present audit findings, recommendations, and status updates to senior internal management.
- Provide guidance to stakeholders on IT audit findings, control effectiveness, and identified technology risks.
- Collaborate with the first and second lines of defense to understand and support alignment on established control objectives and risk tolerances.
- Recommend improvements to key…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).