> Markdown version of [/jobs/ext/2028895-it-audit-manager](https://www.wearedevelopers.com/jobs/ext/2028895-it-audit-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Audit Manager - **Company:** KBR Inc - **Location:** Houston, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Information Systems, Monitoring of Systems, Identity and Access Management, Information Technology Audit, IT Management, Information Technology Operations, Information Systems Security Architecture Professional, Systems Development Life Cycle, Release Management, Software Engineering, Cloud Platform System, IT General Controls (ITGC), Information Technology, Data Analytics - **Published:** August 11, 2026 - **Apply:** https://kbr.wd5.myworkdayjobs.com/KBR_Careers/job/Houston-Texas/IT-Audit-Manager_R2127914 ## About the Role The ideal candidate brings strong experience managing IT SOX programs within complex global organizations, demonstrated expertise in IT control frameworks and risk assessment methodologies, and a proven ability to lead and develop audit teams while driving high-quality, risk-based audit execution., * Bachelor's degree in Information Systems, Information Technology, Computer Science, Accounting, Finance, Audit, or a related field. * Minimum of 10 years of progressive experience in IT audit, IT risk management, IT controls, IT compliance, or related disciplines. * Minimum of 4 years of experience leading and managing IT SOX compliance programs and audit teams. * Experience conducting and overseeing SOX 404 testing within large, complex, and global organizations. * Demonstrated experience leading cross-functional initiatives involving IT, Internal Controls, Finance, and external audit stakeholders. * Experience managing distributed, onshore, and offshore resources in a testing or audit environment. Technical & Leadership Skills * Deep knowledge of IT General Controls (ITGCs), including access management, change management, IT operations, and system development controls. * Strong expertise in SOX 404 compliance requirements, control testing methodologies, and internal control frameworks. * Experience evaluating and testing application controls, automated controls, interface controls, and system-generated reports. * Strong understanding of Software Development Lifecycle (SDLC) processes and associated control requirements. * Proven ability to assess control design and operating effectiveness, identify risks, and evaluate control deficiencies. * Strong analytical, problem-solving, and risk assessment skills. * Ability to manage multiple priorities, projects, and deadlines in a fast-paced environment. * Effective leadership, coaching, and team development capabilities. * Excellent verbal and written communication skills with the ability to present complex technical and compliance matters to diverse audiences. * Strong stakeholder management and relationship-building skills across business and technology functions., * Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), or equivalent professional certification. * Prior experience within a publicly traded organization with mature SOX compliance requirements. * Experience supporting external audit reliance strategies and coordinating with external auditors. * Knowledge of leading control frameworks and governance standards, including COBIT, NIST, and related IT risk frameworks. * Experience supporting digital transformation, ERP implementations, cloud environments, or large-scale technology change initiatives. * Advanced experience with data analytics, audit automation, or continuous controls monitoring tools. ## Description * Manage the annual IT SOX compliance program, including planning, execution, monitoring, and reporting activities across IT control domains. * Develop and maintain risk-based testing strategies and audit plans covering IT General Controls (ITGCs), application controls, automated controls, interface controls, and SDLC controls. * Oversee walkthroughs, control assessments, and testing activities to evaluate the design and operating effectiveness of key IT controls. * Lead and review testing of ITGCs, including access management, change management, IT operations, and system development controls. * Direct testing and evaluation of SDLC controls, including development approvals, testing evidence, release management, and production migration processes. * Oversee testing of key automated controls, application controls, system interfaces, and management reports used in financial reporting processes. * Manage and mentor onshore and offshore IT audit and SOX testing teams, ensuring consistency, quality, and adherence to established audit methodologies. * Review workpapers, testing documentation, and audit evidence to ensure accuracy, completeness, and compliance with professional standards. * Partner with IT management, Internal Controls, business process owners, and external auditors to coordinate testing activities, address control issues, and facilitate audit reliance. * Evaluate identified control deficiencies, assess potential SOX impact and severity, and provide recommendations for corrective actions. * Monitor remediation activities, validate the effectiveness of corrective actions, and track resolution through completion. * Prepare and present status reports, executive dashboards, testing summaries, and risk updates to management and key stakeholders. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [PySpark - Combining Machine Learning & Big Data](https://www.wearedevelopers.com/videos/44-pyspark-combining-machine-learning-big-data) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Engineering/Manager Pendulum: Generating compound interest on your career](https://www.wearedevelopers.com/videos/100348-engineering-manager-pendulum-generating-compound-interest-on-your-career) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [How should you format your IT resume?](https://www.wearedevelopers.com/magazine/68-how-should-you-format-your-it-resume) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools)