Senior Information Technology Audit Manager in New Haven County

Energy Jobline
New Haven County, CT, United States
19 days ago
Apply on www.energyjobline.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$150,000.0 - $180,000.0
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Cloud Computing Security Control Objectives for Information and Related Technology (COBIT) Cyber Security Information Technology Audit IT General Controls (ITGC) Information Technology Data Analytics CIS Benchmarks Vulnerability Analysis

Job description

Are you looking for a high-visibility cyber risk position where you can be the subject matter expert in cybersecurity for a progressive internal audit department?, In this high-visibility role, you will evaluate the effectiveness of IT cybersecurity safeguards, and technology risk management processes, while helping the organization enhance its overall security posture and compliance framework. You’ll lead risk-focused audits, assess emerging technology risks, and provide practical recommendations that improve controls and strengthen operational resilience., n \n

  • Lead and execute IT audit and in depth cybersecurity control reviews \n

  • Perform risk assessments to identify technology and cybersecurity risks across business units \n

  • Become the SME for cybersecurity, including penetration testing, firewalls, networks, etc. \n

  • Evaluate the design and effectiveness of information security and IT controls \n

  • Conduct security reviews, vulnerability assessments, and penetration testing \n

  • Partner with IT, cybersecurity, and business leadership to identify risks and drive remediation \n

  • Prepare and present clear, actionable audit reports to senior management \n

  • Track and monitor audit findings and remediation plans to ensure timely resolution \n

Requirements

  • Bachelor’s degree in IT, Cybersecurity, Computer Science, Information Technology, Engineering, Accounting, or another related discipline. \n

  • Master’s degree is a plus \n

  • Certifications: CISA, CISSP, CISM, CRISC, CIA, CCSP, GIAC, CEH and/or Cloud Security \n

  • Approximately 8-15 years of progressive experience in cybersecurity, technology risk, cyber consulting, cyber assurance, or IT audit, with a significant focus on enterprise cybersecurity. \n

  • Experience within a Fortune 500, Big Four Cyber Risk practice, or leading cybersecurity consulting firm strongly . \n

  • Demonstrated experience leading complex cybersecurity audits and advisory engagements across large, global organizations. \n

  • Experience evaluating enterprise cybersecurity programs, cloud security, cyber resilience, operational resilience, and technology governance. \n

  • Working knowledge of IT General Controls (ITGCs) and SOX requirements, with the ability to coordinate effectively with audit leaders responsible for ITGC assurance. \n

  • Deep knowledge of cybersecurity frameworks including NIST CSF, NIST 800-53, ISO 27001, CIS Controls, COBIT, and applicable cybersecurity and privacy regulations. \n

  • Experience partnering with Chief Information Security Officers, technology executives, and business leadership on cybersecurity risk management and governance. \n

  • Strong executive presence with exceptional communication, presentation, stakeholder management, and report-writing skills. \n

  • Demonstrated ability to translate complex technical risks into clear business impacts and actionable recommendations. \n

  • Experience leveraging data analytics, automation, and continuous monitoring to enhance audit effectiveness. \n

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.energyjobline.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

1:32 min

Structuring platforms for new services and data analytics

Nevelina Aleksandrova · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

1:10 min

Introduction to Microsoft Fabric and data agents

Dr. Alexander Wachtel Dr. Alexander Wachtel +1 · World Congress 2025

Videos

See all

Related articles

See all