Your Contributions (include, But Are Not Limited To)
- Lead and execute audit and advisory engagements end-to-end (ITGC, automated application controls, cybersecurity, cloud, AI and other technology areas), including scoping, testing, reporting, and remediation follow-up.
- Provide functional oversight to ensure high-quality, timely execution; set expectations, give feedback, and coach teams (internal, co-sourced, or hybrid); operate strategically and hands-on.
- Develop actionable audit/advisory observations and reports; analyze root causes and business impact; recommend right-sized remediation.
- Build relationships with technology/business leaders; translate technical risks into business terms for management and audit leadership.
- Monitor/validate remediation of audit action items; identify trends; escalate overdue/high-risk matters; support reporting to management/Audit Committee.
- Serve as a technology-risk functional expert; advise colleagues and integrate technology risks into broader audits; develop tools, practical guidance, and training.
- Advance adoption of data analytics, automated testing, continuous monitoring, and responsible AI-enabled audit methods.
- Provide technology-risk expertise for enterprise risk assessment and annual audit planning; evaluate tech strategy, cyber threats, regulatory expectations, incidents, and third-party dependencies.
- Anticipate/monitor emerging business, regulatory, technology, and risk trends and incorporate insights into planning.
Requirements
- Bachelorโs degree (Information Systems, CS, Cybersecurity, Accounting, Finance, Business, or related) + 8+ years progressive experience in IT/internal audit (technology risk/cybersecurity), public accounting, or consulting OR Masterโs degree + 6+ years.
- Public company audit environment required; biopharma/highly regulated industry strongly preferred; Big 4 and international experience plus.
- 3+ years leading complex engagements and coaching/mentoring teams (including direct reports/co-source partners).
- CISA or equivalent strongly preferred; CISSP, CISM, CRISC, CIA, CPA, and cloud/security credentials plus.
- Familiarity with internal audit standards and frameworks (COBIT, NIST, ISO 27001, COSO, privacy/regulatory requirements).
- Strong knowledge of technology risk domains (cybersecurity, cloud, IAM, ITGC, automated application controls, SDLC, resiliency/DR, data governance/privacy, third-party risk, AI governance, enterprise systems).
- Ability to independently lead complex cross-functional audits; exercise judgment; manage priorities/resources/schedules; drive continuous improvement.
- Advanced analytical and judgment skills; exceptional written/verbal communication and influencing.
- Experience with data analytics/visualization/automation/GRC or audit platforms; Power BI/SQL and AI-enabled audit solutions plus.
- Travel up to 20%.