Cyber Security Assessment Manager
About the role
At Crowe Consulting, consultants are expected to build both technical and transferable skills, think critically, and use technology—including emerging AI capabilities—to solve real business problems. In this role, you will continuously learn, collaborate across teams, and explore how tools can improve efficiency, insights, and client outcomes.
As a Financial Services Cybersecurity Internal Audit Manager, you will work directly with client stakeholders to understand their cybersecurity internal audit needs, plan and execute engagements, and deliver high-quality findings and recommendations that enhance the client's security posture and compliance efforts.
In management at Crowe, you play a pivotal role in leading teams, guiding project execution, and deepening client relationships. You will contribute to account planning, identify opportunities to add value, and ensure high-quality delivery. As responsibilities expand, you take on broader account ownership, balancing project leadership with growing involvement in client strategy and solution development.
Responsibilities
- Plan and execute internal audits across cybersecurity and IT infrastructure domains, including:
- Security Operations Centers (SOC)
- Data Services and Data Governance
- Third Party Risk Management (TPRM)
- Cyber Resilience and Incident Response
- Infrastructure risk control frameworks, including second line of defense (2LOD) review
- Infrastructure-level Incident and Problem Management
- Integrated Cyber Auditing alongside business and operational auditors
- Assess design and operational effectiveness of technical cybersecurity controls against regulatory expectations and industry frameworks (e.g., NIST CSF, COBIT, ISO 27001).
- Prepare thorough audit documentation, reports, and deliverables independently and on schedule.
- Communicate audit procedures, findings, and recommendations directly to client stakeholders, including both technical and non-technical audiences.
- Maintain audit quality and responsiveness throughout the engagement lifecycle, ensuring client satisfaction and confidence.
Requirements
- Minimum of 5 years of total professional experience.
- At least 3 years of hands-on experience performing internal audits, specifically in cybersecurity, IT general controls, or infrastructure risk within a financial services or consulting environment.
- Strong working knowledge of cybersecurity operations, controls, and governance practices.
- Demonstrated ability to independently complete audits from planning through reporting, with minimal oversight.
- Excellent written and verbal communication skills, especially in documenting observations and explaining results to clients.
- Bachelor’s degree.
- One or more relevant professional certifications: CISSP, CISA, or equivalent.
Preferred Qualifications
- Experience working with or auditing financial services regulations and guidelines (e.g., OCC, FDIC, FFIEC, NYDFS).
- Prior experience at a public accounting or advisory firm delivering internal audit services to banking, insurance, or fintech clients.
We expect the candidate to uphold Crowe’s values of Care, Trust, Courage, and Stewardship.
Pay
A reasonable estimate of the current range is $104,500.00 - $213,800.00 per year.
Benefits
At Crowe, we offer employees a comprehensive total rewards package, including:
- Exceptional people experience with a focus on well-being and career growth.
- Consistent career coaching and guidance from a dedicated Career Coach.
- An inclusive culture that values diversity and provides equitable access to opportunities.