Senior Manager, Cybersecurity & Technology Risk Audit
Listed on 2026-07-08
-
IT/Tech
Cybersecurity, IT Project Manager, IT Consultant, Information Security & Data Protection
Job Description:
Senior Manager, Cybersecurity & Technology Risk Audit
Department: Internal Audit
Reports To: Vice President, Internal Audit
OverviewAs a senior leader within the Internal Audit Department, the Senior Manager, Cybersecurity & Technology Risk Audit, is responsible for providing independent assurance and strategic advisory services over the Company's cybersecurity, technology risk, and digital transformation landscape.
This role serves as Internal Audit's subject matter expert for cybersecurity and technology risk, partnering closely with VP of IT, and other business leaders to evaluate cyber resilience, technology governance, and the effectiveness of enterprise security controls.
The Senior Manager leads complex cybersecurity audits, evaluates emerging technology risks, advises management on strategic technology initiatives, and helps strengthen the Company's overall cyber posture while maintaining the independence required of the Internal Audit function. While the role will have familiarity with IT General Controls (ITGCs), its primary focus is evaluating enterprise cybersecurity capabilities, technology risk management, operational resilience, and emerging technology risks.
Key Responsibilities Cybersecurity & Technology Risk Leadership- Lead the development and execution of the Company's cybersecurity and technology risk audit strategy as part of the annual risk-based Internal Audit Plan.
- Serve as the Internal Audit subject matter expert on cybersecurity, technology risk, and digital transformation.
- Partner with the Vice President of Internal Audit to identify emerging technology and cybersecurity risks and incorporate them into the annual audit plan.
- Continuously monitor the external cyber threat landscape, evolving regulatory requirements, and emerging technologies to ensure audit coverage remains aligned with enterprise risks.
- Coordinate cybersecurity audit activities with external specialists, co-sourced providers, and external auditors as appropriate.
Lead independent assessments of the design and operating effectiveness of controls across areas including:
- Cybersecurity Governance
- Security Operations (SOC)
- Identity & Access Management (IAM)
- Privileged Access Management (PAM)
- Cloud Security (AWS, Azure, GCP)
- Network and Infrastructure Security
- Vulnerability & Patch Management
- Data Protection & Encryption
- Third-Party & Supply Chain Cyber Risk
- Disaster Recovery & Business Continuity
- Operational Technology (OT/ICS), where applicable
- Artificial Intelligence (AI) Governance and Security
- Secure Software Development (Dev Sec Ops )
Evaluate cybersecurity programs against leading frameworks including NIST Cybersecurity Framework, NIST 800-53, ISO 27001, CIS Critical Security Controls, COBIT, and applicable privacy and cybersecurity regulations.
Advisory & Consulting- Serve as a trusted advisor to VP of IT, and other business leaders on cybersecurity governance, technology risk, and control effectiveness.
- Provide independent, risk-focused advisory services for major technology initiatives including cloud migrations, cybersecurity transformations, ERP implementations, AI initiatives, identity modernization, Zero Trust implementation, and digital transformation programs.
- Participate in steering committees, governance forums, and strategic technology initiatives as an independent advisor to identify risks early and recommend effective control design.
- Facilitate technology and cybersecurity risk assessments, cyber maturity assessments, tabletop exercises, and control design workshops.
- Benchmark the Company's cybersecurity capabilities against industry leading practices and peer organizations.
- Advise management on opportunities to improve cyber resilience through automation, continuous monitoring, data analytics, and emerging technologies while maintaining Internal Audit independence.
- Lead the annual enterprise cybersecurity and technology risk assessment.
- Develop technology risk matrices and control frameworks that support the annual audit plan.
- Identify and evaluate technology, cybersecurity, regulatory, operational, and emerging risks across all business units.
- Monitor evolving cyber threats, AI risks, regulatory developments, and geopolitical events that could impact the Company's risk profile.
- Develop risk-based audit scopes and work programs focused on cybersecurity, technology governance, operational resilience, and digital risks.
- Schedule audits and advisory engagements based on enterprise risk and business priorities.
- Lead the planning, scoping, and execution of cybersecurity audit and consulting engagements.
- Develop audit methodologies covering cloud security, artificial intelligence, cybersecurity, data privacy, digital transformation, and emerging technologies.
- Partner with VP of IT, and other business leadership to understand technology risks and strategic initiatives.
- Evaluate the effectiveness of enterprise cybersecurity governance, security operations, cloud environments,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).