Manager IT Audit
Listed on 2026-08-04
-
IT/Tech
Cybersecurity, IT Business Analyst, IT Consultant, Information Security & Data Protection
Job Description
The Manager, IT Audit is responsible for leading and coordinating the execution of technology-focused internal audit and Sarbanes Oxley (SOX) engagements. This role serves as the Internal Audit subject matter expert for information technology risk, IT General Controls (ITGCs), cybersecurity, system implementations, IT-dependent business processes, and technology governance.
This role will lead the planning, execution, and reporting of IT audits while evaluating the design and operating effectiveness of controls over critical systems, applications, infrastructure, and cybersecurity processes. Further, you will support the ongoing operation of the Internal Audit function through strategic collaboration (with Information Security, Finance and external audit teams, among others), ensuring complex risks are identified timely and continuous improvement remains at the forefront of the business.
This role is hands‑on and execution‑focused within the overall audit program, requiring strong attention to detail, sound judgment, and effective communication skills – in addition to a strong knowledge of ITGCs, ERP systems, and cybersecurity risk.
- Manage the planning, execution, and reporting of internal audit and SOX engagements inclusive of Information Technology General Controls (ITGCs), cybersecurity, identity and access management (IAM) and data governance, ensuring adherence to established methodologies and standards
- Manage IT SOX activities including annual risk assessment and scoping, ITGC testing, key reports, automated application control testing and segregation of duties, among others
- Evaluate cybersecurity governance, policies, and operating procedures – and partner with management in aligning the business against key frameworks such as ISO 27001 and NIST CSF
- Lead pre- and post-implementation reviews of ERP and technology projects, including evaluating system development lifecycle (SDLC) controls
- Identify control deficiencies, clearly document findings, and support remediation validation efforts
- Support internal and external audit requests and follow-up activities
- Assist in assessing cybersecurity, data privacy, and technology risks as part of integrated audits
- Participate in ERP and system‑related audits or implementation reviews as assigned
- Support reviews of system implementations, upgrades, and configuration changes, focusing on control design and operational effectiveness
- Execute audit engagements in alignment with approved audit plan, recommending practical process and control improvements based on audit results
- Solve complex departmental issues through coordination with multiple teams, business units, and departments to identify opportunities for continuous improvement
- Partner strategically with cross-functional stakeholders to facilitate audit processes, articulate audit findings, and support effective remediation efforts
- Manage the development and maintenance of audit work papers in accordance with professional standards, ensuring completeness and accuracy
- Stay current on internal audit standards, accounting guidance, and regulatory requirements
- 6+ years of progressive audit experience within IT Audit or Technology Risk (internal audit and/or public accounting)
- Knowledge of accounting principles, internal control frameworks, and audit methodology related to Information Technology General Controls (ITGCs)
- Professional certification such as CISA and/or CIA is essential (or demonstrated intent to pursue certification)
- Experience auditing ERP systems (SAP preferred) and related tools/applications
- Knowledge of cybersecurity and IT control frameworks, including ISO 27001 and NIST
- Experience assessing identity and access management (IAM), privileged access, cloud security, and third-party technology risk
- Strong capabilities in strategic planning, problem-solving, and cross-functional leadership within a team environment across all levels at Resideo
- Ability to manage multiple priorities and meet deadlines
- High integrity and professionalism when handling sensitive information
- Prior experience within a manufacturing or operational environment, or public…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).