> Markdown version of [/jobs/ext/3041001-it-audit-manager](https://www.wearedevelopers.com/jobs/ext/3041001-it-audit-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Audit Manager - **Company:** Invesco - **Location:** Houston, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Word, Microsoft Excel, Microsoft Windows, Artificial Intelligence, Amazon Web Services, Data Analysis, Microsoft Azure, Unix, Software as a Service, Cloud Computing Security, Configuration Management, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Systems, Data Validation, Linux, Monitoring of Systems, Identity and Access Management, Information Technology Audit, Python (Programming Language), Microsoft Office, Microsoft SQL Server, Oracle Databases, Open Web Application Security, Microsoft PowerPoint, Power BI, Cloud Services, Software Engineering, Tableau (Software), Software Vulnerability Management, Web Applications, Data Logging, Google Cloud, Cloud Platform System, IT General Controls (ITGC), Snowflake, Software Security, Model Validation, Cyber Threat Analysis, Firewalls (Computer Science), Information Technology, Data Analytics, Software Coding, Devsecops, Alteryx, Programming Languages - **Published:** September 23, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a87b41a28c9e80c8 ## About the Role * Minimum 5-7 years of experience in technology audit, consulting, or information security roles. * Bachelor's degree in Information Systems, Computer Science, Engineering, or Finance preferred. Other business or technology related degrees considered depending upon relevant experience. * MBA, Master's degree in Information Systems, Analytics, Computer Science, Engineering, or Finance a plus. * Professional auditing, security, or technology designation (e.g., CISSP, CCSP, AWS Cloud Practitioner, CFA, etc.) or to have substantially completed the requirements for such a designation while actively pursuing the completion of such designation preferred. * Experience within the asset management or securities industries a plus, with knowledge of investment products (equities, fixed income, alternatives), portfolio management, trading and investment operations and finance. * Experience auditing enterprise and web applications, cybersecurity practices, privacy, application security, API security, secure software development practices, vulnerability management, and infrastructure platforms such as UNIX, Linux, Windows, SQL Server, and Oracle databases. * Knowledge of and experience auditing networking and firewalls a plus. * Experience with concepts and auditing of cloud-based platforms (AWS, Microsoft Azure, Google Cloud, Snowflake), services, and applications, including cloud security, configuration management, encryption, logging and monitoring, identity controls, and third-party/SaaS governance. * Experience designing and conducting data analysis to support audit objectives, including use of data analytics, automation, and AI-enabled techniques to identify risks, trends, anomalies, and control exceptions. * Experience designing and building continuous auditing or monitoring tools and techniques a plus, including automated control testing, exception reporting, dashboarding, and continuous risk monitoring. * Excellent written and verbal communication skills. * Critical thinking and problem-solving ability; effectively identify risks and unexpected patterns in complex situations, investigate issues, analyze root cause, and determine the appropriate course of action. * Excellent knowledge of leading practices around IT controls, such as the COBIT, NIST, ISO27000, OWASP, and AI governance/control frameworks. * Strong knowledge of current technology and cybersecurity trends, including artificial intelligence governance, model risk, cloud security, application and API security, identity and access management, data protection, DevSecOps, third-party technology risk, and operational resilience. * Proficient with analytics software such as Tableau, Power BI, Alteryx, ACL, IDEA, etc. a plus. * Proficiency in code development, specifically programming languages such as R and Python a plus, including the ability to support audit automation, data validation, analytics scripting, and AI-assisted audit procedures. * Proficient with Microsoft Office (MS Word, Excel, PowerPoint, Access etc.). ## Description The Invesco Internal Audit function provides independent assurance, advisory, and investigative services for the organization. While partnering closely with business leaders, the department focuses on the most critical risks and issues facing the organization and delivers strategic, innovative, and data-driven results. The department strives to be valued business advisors that provide meaningful solutions and insights, not just information and recommendations. Our team continuously seeks opportunities to improve our methodology by leveraging technology, data, agile principles, and creative solutions to maximize value to the organization. Your Role As an IT Audit Manager, you will have exciting opportunities to not only enhance your knowledge and familiarity with new technologies and cybersecurity practices across the global organization, but also Invesco products and business processes through integrated reviews covering areas such as Investments, Trading, Distribution, Compliance, and Finance. You will be responsible for: * Analyzing risk in areas of assigned audit responsibility and preparing proposed internal audit plans based on the results. * Scheduling and coordinating the planning for specific audit and advisory engagements. * Collaborating with leadership and colleagues to deliver innovative approaches that meet the objectives of both audit and advisory engagements. * Preparing audit testing strategies and approaches that meet the objectives of assigned engagements, with a focus on internal control design and testing, including for unstructured, risk-based, or complex audits. * Performing audit testing and analysis and supervising the performance of work by any assigned staff or contractors, including reviewing workpapers, documenting control weaknesses or inefficiencies and managing the completion of the engagement within the given timeframe. * Exercising individual judgment and initiative in selecting emphasis for coverage within an engagement and determining and locating sources of information. * Independently evaluating issues based on impact and importance. * Preparing results and conducting entry/exit meetings to obtain management concurrence and responses. * Performing follow-up on previously identified findings and management's action plans. * Preparing reports targeted to senior management and corporate directors. * Assessing emerging technology and cybersecurity risks, including artificial intelligence, cloud services, application and API security, data protection, third-party technology risk, and operational resilience, as part of audit planning and engagement execution. * Collaborating closely with the Data Analytics team to design, develop, and apply data analytics, automation, and AI-enabled techniques to support risk assessment, audit testing, continuous monitoring, and reporting. * Assisting in training and development of junior team members by providing on the job coaching and delivering constructive and motivating feedback., The above information on this description has been designed to indicate the general nature and level of work performed by employees within this role. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job. The job holder may be required to perform other duties as deemed appropriate by their manager from time to time. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [The Time Paradox: Building Timezone-Safe Python/Django Applications](https://www.wearedevelopers.com/videos/1915-the-time-paradox-building-timezone-safe-python-django-applications) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Top Must-Visit Developer Conferences in the US in 2026](https://www.wearedevelopers.com/magazine/679-top-must-visit-developer-conferences-in-the-us-in-2026) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)