Senior Audit Manager
Listed on 2026-08-01
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Business Analyst, IT Project Manager
If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.
Senior Audit ManagerNew York, NY, US
Salary Range: $ To $ Annually
Purpose of Position:
The Senior Audit Manager supports the Deputy Chief Audit Officer (DCAO) in planning, supervising, and executing the Internal Audit plan, with a primary focus on Information Technology and Information Security risks. The role serves as a subject matter expert in technology and cyber risk while also providing audit coverage across other critical areas of Amalgamated Bank, including Commercial Banking, Risk Management, and Operations.
This position is responsible for leading complex, risk-based audits; assessing governance, risk management, and control effectiveness; and ensuring audit activities align with professional standards, regulatory expectations, and industry best practices.
Essential Job Functions:
- Lead and supervise internal audits and targeted reviews with a primary emphasis on Information Technology, Information Security, cybersecurity, technology governance, third-party risk management, data protection, and system development life cycle controls.
- Serve as the Internal Audit subject matter expert for IT and Information Security, includingidentifyingemerging technology and cyber risks relevant to the Bank.
- Plan and execute audits across multiple business lines, including IT, Commercial Banking, Risk Management, and Bank Operations, ensuring appropriate integration of technology risks into all audits.
- Integrate data analytics and AI audit methodologies into the overall audit framework.
- Develop audit scopes, perform risk assessments, oversee testing,validate issues, and ensure appropriate coverage of IT-dependent controls.
- Identifycontrol deficiencies, assess rootcausesandimpact, and recommend practical, risk-based remediation strategies.
- Review and approve audit work papers to ensure accuracy, completeness, and adherence to Internal Audit standards.
- Prepare, review, and edit audit reports to clearly communicate technology, information security, and business risks from a senior management and Audit Committee perspective.
- Evaluate management action plans andmonitorthe remediation of IT, information security, and business audit issues.
- Coordinate audit activities with internal stakeholders, regulators, and external or co-source auditors, particularly for targeted technology and cybersecurity reviews.
- Support enterprise risk assessment, SOX, and regulatory examination activities where technology or data risks are present.
- Provide coaching, technical guidance, and performance feedback to audit staff and managers.
- Stay current on regulatory guidance, industry standards, and emerging risks related to IT and information security, including FFIEC, NIST, and cybersecurity frameworks.
- Assist the DCAO with departmental initiatives, strategic projects, and regulatory or Board-level requests as assigned.
Knowledge, Skills and Experience Requirements :
- Bachelor’s degree in Accounting , Finance, Information Systems, Computer Science, or a related field.
- Minimum of 8–10 years of progressive internal audit, IT audit, information security, or risk management experience within a regulated financial services environment.
- Professional certification such as CISA strongly preferred; CIA or CPA a plus.
- Certification or training in AI ethics, data governance, or model risk management (e.g., MIT AI Ethics, NIST AI Risk Framework).
- Demonstrated experience leading complex IT and information security audits and supervising audit staff.
- Significant experience auditing or managing risks in data analytics, machine learning, or AI environments.
- Strong understanding of IT general controls, cybersecurity, cloud environments, data governance, third-party risk, and SDLC controls.
- Deep knowledge of AI/ML systems, model lifecycle, and related controls.
- Understanding of data analytics tools (e.g., Tableau, Python, SQL, Power BI, R) and audit automation.
- Working knowledge of banking regulations and technology-related regulatory expectations (e.g., FFIEC, OCC, FDIC guidance).
- Understanding of COSO internal control…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).