Technology Audit - Lead
Core
Lead technology audits to assess the design and effectiveness of IT controls across infrastructure, applications, cybersecurity, and cloud environments, providing assurance on the organization's IT audit and risk posture.
Role type
Senior IC technology audit lead
Builds
Audit reports, remediation tracking, and advisory support on control implications for IT projects
Domain
Financial services / IT Governance, Risk, and Compliance (GRC)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
IT audit planning and execution, NIST 800-53/800-171 assessment, SOC 1/SOC 2 evaluation, COBIT 2019 implementation, access management control testing, change management control testing, data protection control testing, business continuity control testing, regulatory requirement analysis
Preferred skills
Automated audit tools usage, data analytics for auditing, GRC platform management, SOX compliance knowledge, GDPR compliance knowledge, ISO 27001 implementation, DevOps methodology knowledge, ITIL framework knowledge, Agile methodology knowledge
Technologies
AWS, Azure, NIST 800-53, NIST 800-171, SOC 1, SOC 2, ISO 27001, COBIT 2019
Responsibilities
Plan, execute, and report on technology audits covering infrastructure, applications, cybersecurity, and cloud environments; Assess IT control frameworks including NIST, SOC 1/SOC 2, ISO 27001, and COBIT; Evaluate the design and operating effectiveness of controls over access management, change management, data protection, and business continuity; Collaborate with cross-functional teams including IT, cybersecurity, risk management, and compliance; Develop audit procedures and programs that align with industry standards and internal risk assessments; Prepare detailed audit reports and communicate findings and recommendations to management and stakeholders; Track remediation of audit issues and validate closure of management actions; Provide advisory support on control implications of emerging technologies and IT projects; Develop a strong understanding on regulatory requirements and industry best practices related to IT governance, risk, and compliance; Execute delegated tasks as deemed appropriate by the Group CISO and other empowered Group Cyber leadership authorities; Support the Group Cyber Strategy end-to-end, driving alignment of all activities, decisions, and deliverables with strategic objectives and business outcomes.
Seniority
Senior, hands-on IC