Director - Technology Risk
EY · Secaucus, NJ · 4 days ago
On-siteInformation Technology$214k–$424k/yrFull-time
About the role
The role offers the opportunity to operate at a global executive level while further developing your leadership skills in an inclusive and diverse environment. You will be at the forefront helping EY manage the risks and challenges of a rapidly changing digital landscape, ensure compliance with evolving regulations, and identify opportunities for innovation and continuous improvement to deliver valuable outcomes.
Responsibilities
- Support the Chief Audit Executive build a technology risk capability that will enable internal audit to provide confidence and assurance that EY’s strategic technology and core platforms are protected and operating effectively.
- Lead the development of the technology-focused internal audit plan encompassing risk assessments and the strategic internal audit approach to emerging digital, cybersecurity, data, compliance and process risks.
- Monitor the technology environment, follow-up activities and future audit or advisory coverage.
- Lead internal audits and advisory engagements across IT risk management, cybersecurity, digital compliance (including ISO, PCI, Privacy and other leading security and technology frameworks and regulations), program risk, resilience, data governance and responsible AI.
- Assess key technology environments, applications, systems, interfaces, IT dependencies and IT general controls to support risk-based audit scoping and execution.
- Oversee end-to-end audit delivery, including scoping, planning, budgeting, resourcing, execution, reporting and completion of required documentation in accordance with GIA methodology.
- Promote innovation, data analytics, automation and leading practices to enhance audit effectiveness and insight generation.
- Cultivate trusted relationships with senior management, Audit Sponsors, stakeholders, second line functions and subject matter resources to support effective audit engagement, alignment on key risks and transparent communication of audit progress and outcomes, while maintaining GIA’s independence, objectivity and professional scepticism.
- Develop and strengthen GIA’s technology audit capabilities by supporting recruitment, managing and coaching team members and subject matter resources, fostering knowledge sharing, technical upskilling and an inclusive, high-performing team environment.
Qualifications
- A bachelor’s degree or equivalent qualification in a related field, with approximately 15+ years of relevant experience in technology risk, internal audit, public accounting, risk management or a large global organization.
- Certifications and / or accreditations in Information Security, Microsoft, SAP, AI or other relevant technologies.
- Experience in technology-enabled Integrated Risk Management (IRM) or Governance, Risk and Compliance (GRC) programs, Portfolio, Program and Project risk management consulting and/or assurance services, Regulatory Compliance (e.g. Privacy, SoCI Act, SoX, Spam Act), Resiliency – design, build, implementation of business and technology resilience programs, AI Governance, Responsible Use of AI (incl. Responsible AI strategy, AI Governance framework), Governance, Risk and Compliance, Internal Controls and Internal Audit (incl. Controls optimisation, SoX), Assurance – technology-focused internal audit (incl. IT General Controls, Cyber Security, and AI Governance).
Skills and Attributes
- Bring broad experience across IT governance, cybersecurity, digital compliance, ERP, resilience, data governance, responsible AI and technology-enabled transformation.
- Lead complex global projects and internal audits, building trust and engagement with senior stakeholders and deliver clear, risk-based insights that support effective governance, risk management and control improvement.
- Foster an inclusive, innovative and high-performing team environment by actively coaching, mentoring and developing team members.
- Deliver high-quality audit and advisory work within agreed timelines and budgets, while proactively managing risks, monitoring progress and keeping stakeholders informed of key outcomes and emerging matters.
- Communicate clearly and effectively, providing actionable insights and practical recommendations on control issues, risk implications and opportunities to address identified gaps.
- Stay current on business, technology and industry trends relevant to EY’s evolving risk landscape.