Director - Digital Technology Audit
About Us
As the largest private-sector power producer in the world and the nation's largest producer of clean and reliable energy, Constellation is focused on lighting the way to a brilliant tomorrow for all. With a portfolio including 55 gigawatts of capacity from nuclear, natural gas, geothermal, hydro, wind, and solar facilities—enough to power the equivalent of 27 million homes—we lead in clean energy production. Our culture is powered by passion and purpose, fostering a workplace where employees grow, thrive, and contribute to healthier communities and a cleaner planet.
About the Role
The Director, IT Internal Audit provides strategic risk leadership for the Company's technology and cybersecurity assurance program. This role serves as a key risk advisor on technology risk, cyber resilience, data governance, and digital transformation, developing and executing a risk-based IT audit strategy, overseeing SOX IT assurance activities, and advancing data-driven audit capabilities.
Responsibilities
- Own the end-to-end IT, cybersecurity, and digital audit strategy and portfolio, ensuring comprehensive coverage of enterprise technology, cyber, data, and IT-enabled business risks.
- Develop and maintain a dynamic, risk-based audit plan informed by emerging threats, strategic initiatives, regulatory developments, and enterprise risk assessments.
- Lead enterprise-wide IT audit and advisory engagements, establishing scope, objectives, and methodologies using a risk-based approach aligned to business strategy and emerging risks.
- Oversee assurance activities related to IT General Controls (ITGCs), application controls, cybersecurity, identity and access management, cloud technologies, data governance, resilience, and IT-enabled business processes.
- Drive initiatives to optimize technology controls and reduce the total cost of risk management.
- Serve as the functional owner for Internal Audit's digital and analytics strategy, establishing a roadmap to increase automation, continuous monitoring, and data-driven assurance.
- Evaluate and implement audit technologies, advanced analytics, artificial intelligence use cases, and data-enabled risk assessment capabilities.
- Champion innovative approaches to risk identification and audit delivery through strategic use of technology and data.
- Act as a strategic advisor to the CIO, CISO, Digital leadership, and senior stakeholders on technology risk, cyber resilience, governance, and control effectiveness.
- Translate complex technology and cybersecurity risks into concise, actionable insights for Executive Management and the Audit Committee.
- Build strong partnerships across Internal Audit, Enterprise Risk Management, Compliance, Security, and external assurance providers.
- Develop, coach, and lead a high-performing team of IT audit, cybersecurity, and analytics professionals, fostering innovation and continuous improvement.
Leadership & Behavioral Expectations
- Transformational Audit Leadership: Drives a forward-looking audit agenda balancing core assurance with transformation, technology, and emerging risk coverage.
- Digital Leadership: Demonstrates a digital-first mindset and promotes innovative, data-driven approaches to assurance and risk management.
- Business Acumen and Strategic Orientation: Understands the business and balances core assurance responsibilities with modernization initiatives that improve effectiveness and stakeholder value.
- Change Leadership and Stakeholder Alignment: Builds trust across business leaders and risk partners while promoting consistency and continuous improvement during change.
- Executive Presence: Establishes credibility and influence with executive leadership and Audit Committee members through sound judgment and trusted advisory relationships.
Requirements
- Bachelor’s degree in Information Systems, Computer Science, Engineering, Accounting, Finance, Business Administration, or a related field.
- 12+ years of progressive professional experience, including significant leadership responsibility within IT internal audit, technology risk management, cybersecurity, assurance, or a comparable control-focused environment.
- Demonstrated experience leading a team of risk-based IT auditors or major technology risk programs across infrastructure, cybersecurity, cloud technologies, data management, identity and access management, disaster recovery, and IT-enabled business processes.
- Significant experience evaluating and testing IT General Controls (ITGCs), automated controls, and technology controls supporting SOX compliance.
- Demonstrated success developing and implementing digital transformation initiatives, audit analytics programs, automation solutions, or technology-enabled assurance capabilities.
- Deep understanding of cybersecurity frameworks, technology risk management practices, and emerging technology risks, including cloud, cyber resilience, third-party risk, and data governance.
- Proven ability to influence executive stakeholders and communicate complex technology and cyber risks in a clear, business-oriented manner.
- Experience leading and developing teams, including managers and/or geographically dispersed teams.
Preferred Qualifications
- Advanced degree.
- Professional certification (e.g., CISA, CISSP, CIA, CPA, CRISC, CISM, PMP).
- Experience leading technology risk assurance programs within a Fortune 500, energy, utility, or other highly regulated industry.
- Experience developing and leveraging data analytics, automation, AI-enabled tools, or continuous auditing techniques within Internal Audit.
- Familiarity with NIST Cybersecurity Framework, COBIT, ISO 27001, NERC CIP, and other relevant technology risk and cybersecurity frameworks.
Benefits
- Competitive compensation, including a bonus program and 401(k) with company match.
- Employee stock purchase program.
- Comprehensive medical, dental, and vision benefits, including robust wellbeing programs.
- Disability and life insurance benefits.
- Paid time off for vacation, holidays, and sick days.
- Additional benefits supporting employees and their families.
Pay
Expected salary range of $195,300 to $217,000, varying based on experience, along with a comprehensive benefits package.