Director - Digital Technology Audit
Constellation · Chicago, IL · 3 wk ago
HybridInformation Technology$195k–$217k/yrFull-time
Primary Purpose Of Position
The Director, IT Internal Audit provides strategic risk leadership for the Company's technology and cybersecurity assurance program and serves as a key risk advisor on technology risk, cyber resilience, data governance, and digital transformation. This role is responsible for developing and executing a risk-based IT audit strategy, overseeing SOX IT assurance activities, advancing data-driven audit capabilities, and providing Management and the Chief Audit Executive with clear, decision-useful insights regarding emerging technology and cyber risks.
Primary Duties And Accountabilities
- Lead IT, Cyber and Digital Risk-Based Audit Program
- Own the end-to-end IT, cybersecurity and digital audit strategy and portfolio, ensuring comprehensive coverage of the enterprise's most significant technology, cyber, data, and IT-enabled business risks.
- Develop and maintain a dynamic, risk-based audit plan informed by emerging threats, strategic initiatives, regulatory developments, technology transformation activities, and enterprise risk assessments.
- Develop and lead enterprise wide IT audit and advisory engagements, establishing scope, objectives, and methodologies using a risk based approach aligned to business strategy, technology initiatives, and emerging IT and cybersecurity risks.
- Oversee assurance activities related to IT General Controls (ITGCs), application controls, cybersecurity, identity and access management, cloud technologies, data governance, resilience, and IT-enabled business processes.
- Drive initiatives to optimize technology controls and reduce total cost of risk management.
- Drive Internal Audit's Digital Strategy
- Serve as the functional owner for Internal Audit's digital and analytics strategy, establishing a roadmap to increase automation, continuous monitoring, data-driven assurance, and scalable audit execution.
- Evaluate and implement audit technologies, advanced analytics, artificial intelligence use cases, and data-enabled risk assessment capabilities that enhance audit effectiveness and efficiency.
- Champion innovative approaches to risk identification and audit delivery through the strategic use of technology and data.
- Executive Technology Risk Advisor
- Serve as a strategic advisor to the CIO, CISO, Digital leadership, and other senior stakeholders on technology risk, cyber resilience, governance, and control effectiveness.
- Translate complex technology and cybersecurity risks into concise and actionable insights for Executive Management and the Audit Committee.
- Build strong partnerships across Internal Audit, Enterprise Risk Management, Compliance, Security, and external assurance providers to ensure coordinated risk coverage.
- Audit Team Leader
- Develop, coach, and lead a high-performing team of IT audit, cybersecurity, and analytics professionals while fostering innovation, technical excellence, and continuous improvement across the Internal Audit function.
Leadership & Behavioral Expectations
- Transformational Audit Leadership: Drives a forward-looking audit agenda that balances core assurance with transformation, technology, and emerging risk coverage.
- Digital Leadership: Demonstrates a digital-first mindset and promotes innovative, data-driven approaches to assurance and risk management.
- Business Acumen and Strategic Orientation: Understands the business, balances delivery of core assurance responsibilities with modernization and transformation initiatives that improve audit and business process effectiveness, efficiency, and stakeholder value.
- Change Leadership and Stakeholder Alignment: Builds trust across business leaders, risk partners, and external assurance providers while promoting consistency, accountability, and continuous improvement during change.
- Executive Presence: Establishes credibility and influence with executive leadership, technology management, and Audit Committee members through sound judgment and trusted advisory relationships.
Minimum Qualifications
- Bachelor's degree in Information Systems, Computer Science, Engineering, Accounting Finance, Business Administration, or a related field.
- 12+ years of progressive professional experience, including significant leadership responsibility within IT internal audit, technology risk management, cybersecurity, assurance, or a comparable control focused environment.
- Demonstrated experience leading a team of risk-based IT auditors, risk assessments or major technology risk program across infrastructure, cybersecurity, cloud technologies, data management, identity and access management, disaster recovery, and IT-enabled business processes.
- Significant experience evaluating and testing IT General Controls (ITGCs), automated controls, and technology controls supporting SOX compliance.
- Demonstrated success developing and implementing digital transformation initiatives, audit analytics programs, automation solutions, or technology-enabled assurance capabilities.
- Deep understanding of cybersecurity frameworks, technology risk management practices, and emerging technology risks, including cloud, cyber resilience, third-party risk, and data governance.
- Proven ability to influence executive stakeholders and communicate complex technology and cyber risks in a clear, business-oriented manner.
- Experience leading and developing teams, including managers and/or geographically dispersed teams.
Preferred Qualifications
- Advanced degree.
- Professional certification (e.g., CISA, CISSP, CIA, CPA, CRISC, CISM, PMP).
- Experience leading technology risk assurance programs within a Fortune 500, energy, utility, or other highly regulated industry.
- Experience developing and leveraging data analytics, automation, AI-enabled tools, or continuous auditing techniques within Internal Audit.
- Familiarity with NIST Cybersecurity Framework, COBIT, ISO 27001, NERC CIP, and other relevant technology risk and cybersecurity frameworks.
Pay
Expected salary range of $195,300 to $217,000, varies based on experience, along with comprehensive benefits package that includes bonus and 401(k).
Benefits
- Bonus program
- 401(k) with company match
- Employee stock purchase program
- Comprehensive medical, dental and vision benefits, including robust wellbeing programs
- Disability and life insurance benefits
- Paid time off for vacation, holidays, and sick days