> Markdown version of [/jobs/ext/3608990-it-audit-manager](https://www.wearedevelopers.com/jobs/ext/3608990-it-audit-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Audit Manager - **Company:** Veritas - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $160,000.0 - $190,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Data Analysis, Cyber Security, Information Systems, Data Governance, R (Programming Language), Information Technology Audit, Python (Programming Language), Machine Learning, Systems Development Life Cycle, Power BI, SQL Databases, Tableau (Software), Cloud Platform System, IT General Controls (ITGC), Information Technology, Data Analytics, Machine Learning Operations - **Published:** October 7, 2026 - **Apply:** https://www.thejobnetwork.com/job/be9c9729-3120-47f2-82f6-a3b9e82e5a64/senior-it-audit-manager ## About the Role * Bachelor's degree in Accounting, Finance, Information Systems, Computer Science, ora related field. \n * Minimum of 8-10 years of progressive internal audit, IT audit, information security, or risk management experience within a regulated financial services environment. \n * Professional certification such as CISA strongly preferred; CIA or CPA a plus. \n * Certification or training in AI ethics, data governance, or model risk management (e.g., MIT AI Ethics, NIST AI Risk Framework). \n * Demonstrated experience leading complex IT and information security audits and supervising audit staff. \n * Significant experience auditing or managing risks in data analytics, machine learning, or AI environments. \n * Strong understanding of IT general controls, cybersecurity, cloud environments, data governance, third-party risk, and SDLC controls. \n * Deep knowledge of AI/ML systems, model lifecycle, and related controls. \n * Understanding of data analytics tools (e.g., Tableau, Python, SQL, Power BI, R) and audit automation., * Working knowledge of banking regulations and technology-related regulatory expectations (e.g., FFIEC, OCC, FDIC guidance). ## Description * Serves as a subject matter expert in technology and cyber risk while also providing audit coverage across other critical areas including Commercial Banking, Risk Management, and Operations. \n * Responsible for leading complex, risk-based audits; assessing governance, risk management, and control effectiveness; and ensuring audit activities align with professional standards, regulatory expectations, and industry best practices. \n * Lead and supervise internal audits and targeted reviews with a primary emphasis on Information Technology, Information Security, cybersecurity, technology governance, third-party risk management, data protection, and system development life cycle controls. \n * Serve as the Internal Audit subject matter expert for IT and Information Security, including identifying emerging technology and cyber risks relevant to the Bank. \n * Plan and execute audits across multiple business lines, including IT, Commercial Banking, Risk Management, and Bank Operations, ensuring appropriate integration of technology risks into all audits. \n * Integrate data analytics and AI audit methodologies into the overall audit framework. \n * Develop audit scopes, perform risk assessments, oversee testing, validate issues, and ensure appropriate coverage of IT-dependent controls. \n * Identify control deficiencies, assess root causes and impact, and recommend practical, risk-based remediation strategies. \n * Review and approve audit workpapers to ensure accuracy, completeness, and adherence to Internal Audit standards. \n * Prepare, review, and edit audit reports to clearly communicate technology, information security, and business risks from a senior management and Audit Committee perspective. \n * Evaluate management action plans and monitor the remediation of IT, information security, and business audit issues. \n * Coordinate audit activities with internal stakeholders, regulators, and external or co-source auditors, particularly for targeted technology and cybersecurity reviews. \n * Support enterprise risk assessment, SOX, and regulatory examination activities where technology or data risks are present. \n * Provide coaching, technical guidance, and performance feedback to audit staff and managers. \n * Stay current on regulatory guidance, industry standards, and emerging risks related to IT and information security, including FFIEC, NIST, and cybersecurity frameworks. \n * Assist the DCAO with departmental initiatives, strategic projects, and regulatory or Board-level requests as assigned. \n