Posted in

Senior IT Audit Manager – Cybersecurity and Risk Oversight

Senior IT Audit Manager – Cybersecurity and Risk Oversight

CompanyLazard
LocationNew York, NY, USA
Salary$150000 – $175000
TypeFull-Time
DegreesBachelor’s
Experience LevelSenior, Expert or higher

Requirements

  • 10+ years experience in IT audits, risk assessments, and compliance with frameworks like COBIT, ISO 27001, and regulatory standards (e.g., SOX, NIST, SWIFT CSP)
  • Hands-on experience with IT systems (applications, databases, networks) and expertise in cybersecurity, disaster recovery, and business continuity planning
  • Experience leveraging AI, automation, and data analytics in audit processes, coupled with excellent interpersonal and reporting skills to collaborate with stakeholders and senior management
  • Bachelor’s in IT, Computer Science, or related field
  • Preferred certifications include CISA, CISM, or CISSP
  • Strong ability to evaluate risks, identify control gaps, and provide actionable, cost-effective recommendations

Responsibilities

  • Develop and implement risk-based IT audit frameworks aligned with organizational objectives, regulatory requirements, and industry best practices to strengthen IT governance
  • Conduct detailed audits of IT systems (applications, databases, networks, and change management processes) to uncover vulnerabilities, evaluate controls, and recommend cost-effective solutions
  • Evaluate business continuity, disaster recovery capabilities, and adherence to cybersecurity standards (e.g., NIST, SOX, SWIFT CSP) to ensure operational resilience and regulatory compliance
  • Build partnerships with auditees and communicate effectively with senior management, delivering audit reports and recommendations that drive informed decision-making
  • Integrate advanced technologies like AI, automation, and data analytics into audit processes to improve efficiency, detect risks, and optimize resource allocation for impactful findings

Preferred Qualifications

  • Preferred certifications include CISA, CISM, or CISSP