Senior IT Audit Manager, Cybersecurity & Technology
Core
Lead technology audits and cyber security assessments for the Chief Technology and Transformation Office, focusing on Identity and Access Management (IAM), cloud systems, and emerging technologies like Generative AI.
Role type
Senior IC IT Audit Manager (Cybersecurity & IAM)
Builds
Independent assessments of IT infrastructure, applications, and security controls for the Chief Technology and Transformation Office.
Domain
Financial Services / Cybersecurity / Identity and Access Management
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
IAM architecture design and testing, vulnerability assessment, security testing of identity platforms, RBAC and provisioning control testing, cloud IAM validation (AWS/Azure/GCP), Zero Trust architecture knowledge, DevSecOps pipeline security, risk-based vulnerability assessment, stakeholder management, technical report writing
Preferred skills
CISA, CISSP, CEH, Red Team certification, experience with SailPoint and CyberArk, MFA bypass scenario testing, PAM weakness validation
Technologies
SailPoint, CyberArk, AWS, Azure, GCP, IAM tools, MFA, SSO, PAM, Generative AI, Large Language Models
Responsibilities
Execute internal audits including planning, fieldwork, and reporting for IT and cyber security; partner with stakeholders to identify identity-related vulnerabilities via grey box testing; assess IAM controls through abuse-case simulation and privilege escalation scenarios; conduct risk-based vulnerability assessments on identity attack vectors; drive adoption of Secure-by-Design principles across the SDLC; lead testing of advanced IAM capabilities like MFA bypass and SSO misconfigurations; collaborate on audit programs for emerging frontier technologies.
Seniority
Senior, hands-on IC