Senior Manager Technology & Cybersecurity Audit
Indexed description
Senior Manager, Cybersecurity & Technology Audit
Overview
The Senior Manager, Cybersecurity & Technology Audit provides senior leadership within Internal Audit, delivering independent assurance and advisory services across the organization’s cybersecurity, technology risk, and digital transformation landscape.
The role serves as Internal Audit’s subject matter expert for cybersecurity and technology risk, partnering with the VP of IT and senior business leaders to assess cyber resilience, technology governance, security controls, and emerging technology risks.
The Senior Manager leads complex cybersecurity and technology audits, advises on strategic technology initiatives, and helps strengthen the organization’s overall cyber and technology risk posture while maintaining Internal Audit independence.
Key Responsibilities
Cybersecurity & Technology Risk
- Lead the cybersecurity and technology risk component of the annual, risk-based Internal Audit plan
- Serve as Internal Audit’s subject matter expert for cybersecurity, technology risk, and emerging technologies
- Identify and assess evolving cyber, technology, regulatory, operational, and emerging risks
- Monitor the external threat landscape, regulatory developments, and technology trends to maintain relevant audit coverage
- Coordinate specialist, co-sourced, and external audit support as required.
Cybersecurity Assurance
- Lead independent assessments of cybersecurity governance, control effectiveness, and resilience across areas includiing:
- Security governance and operations
- Identity and privileged access management
- Cloud, network, infrastructure, and endpoint security
- Vulnerability management and threat detection
- Incident response and ransomware preparedness
- Data protection and encryption
- Third-party and supply chain cyber risk
- Disaster recovery and business continuity
- AI governance and security
- Secure software development and DevSecOps
- Operational Technology (OT/ICS), where applicable
- Evaluate cybersecurity programs against leading frameworks such as NIST CSF, NIST 800-53, ISO 27001, CIS Controls, COBIT, and applicable regulations.
Advisory & Strategic Support
- Provide independent, risk-focused advice to the VP of IT and senior business leaders.
- Support major technology initiatives including cloud transformation, ERP implementations, AI programs, identity modernization, Zero Trust, and digital transformation.
- Participate in technology governance forums and strategic initiatives to identify risks and control considerations early.
- Conduct cybersecurity risk assessments, maturity reviews, tabletop exercises, and control design assessments.
- Benchmark cybersecurity capabilities against industry practices and identify opportunities to improve resilience through automation, analytics, and continuous monitoring.
Audit Execution & Reporting
- Develop audit scopes, methodologies, and work programs for cybersecurity and technology risk engagements.
- Lead planning, fieldwork, and execution of complex audits and advisory reviews.
- Assess cybersecurity governance, cloud security, security architecture, identity management, third-party risk, and technology resilience.
- Perform targeted ITGC reviews where appropriate, coordinating with the leader responsible for ITGC and SOX assurance.
- Evaluate preparedness for cyber incidents, including incident response, vulnerability management, disaster recovery, and business continuity.
- Prepare executive-level reports outlining key risks, control gaps, business impact, root causes, and practical recommendations.
- Monitor remediation and escalate significant unresolved risks to senior management, the VP of Internal Audit, and Audit Committee as appropriate.
Leadership & Continuous Improvement
- Drive the use of data analytics, automation, continuous auditing, and AI-enabled techniques within Internal Audit.
- Maintain current knowledge of cybersecurity threats, regulatory requirements, and technology developments.
- Enhance cybersecurity audit methodologies and technology risk assessment capabilities.
- Mentor Internal Audit professionals and serve as the department’s technical resource for cybersecurity and technology risk.
Qualifications
Education & Certifications
- Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, IT, Engineering, Accounting, or a related discipline.
- Master’s degree preferred.
- At least one relevant certification required, such as CISA, CISSP, CISM, CRISC or CIA.
- Additional certifications such as CCSP, GIAC, CEH, Security+, or relevant cloud security credentials preferred.
Experience & Skills
- 8–12+ years of progressive experience in cybersecurity, technology risk, cyber assurance, consulting, or IT audit, with significant enterprise cybersecurity experience.
- Experience in a large, complex organization, Fortune 500 company, Big Four cyber risk practice, or leading cybersecurity consultancy preferred.
- Demonstrated experience leading complex cybersecurity audits and advisory engagements.
- Strong knowledge of cybersecurity governance, cloud security, cyber resilience, operational resilience, and technology risk management.
- Working knowledge of ITGC and SOX requirements.
- Strong understanding of NIST, ISO 27001, CIS Controls, COBIT, and relevant cybersecurity and privacy regulations.
- Experience working with CISOs, technology executives, and senior business leaders.
- Excellent executive communication, presentation, stakeholder management, and report-writing skills.
- Ability to translate complex technical risks into clear business impacts and actionable recommendations.
- Experience using data analytics, automation, or continuous monitoring to improve audit effectiveness.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search