Senior IT Audit Manager
Overview
The Senior Manager: IT Audit leads complex IT audit engagements, overseeing IT General Controls (ITGCs), application controls, and IT SOX compliance programs. This role demands deep technical expertise and strong risk and controls knowledge, coupled with the ability to engage senior stakeholders across the business.
Requirements
- CIA, CISA, or equivalent professional qualification
- 8-12+ years' experience in IT audit or technology risk
- Strong IT SOX experience (ICFR environment)
- Experience in ERP audits (SAP preferred)
- Deep understanding of ITGCs, logical access controls, change management, cybersecurity controls, and cloud risk
Responsibilities
- Lead and manage end-to-end IT audit engagements
- Oversee risk assessments and audit planning
- Review technical workpapers and ensure quality assurance
- Manage multiple engagements and teams simultaneously
- Lead IT SOX compliance programs (ITGCs, automated controls, interface controls)
- Assess design and operating effectiveness of controls
- Identify control gaps and drive remediation efforts
- Liaise with external auditors on IT SOX reliance
- Evaluate ERP environments and assess cybersecurity controls and IT governance frameworks
- Review cloud environments (Azure, AWS) and analyze system configurations, access management, and change controls
- Evaluate data analytics controls and automated control environments
- Advise clients/business on IT risk mitigation strategies
- Align IT controls to frameworks such as COBIT, ISO 27001, NIST
- Present audit findings to Executive Management and Audit Committees
- Build trusted relationships with CIOs, IT Directors, and Finance Leaders
- Mentor and develop managers and audit team
How to apply
Verify before you apply
SpanSam summarises opportunities for easier discovery. Always confirm the closing date, eligibility requirements and submission instructions on the original source before sending personal information or documents.
About this listing: SpanSam is an opportunity discovery service and is not the hiring employer unless explicitly stated. Application decisions and source-listing changes are controlled by the employer or institution.