Head of IT Audit
About the Role
Lead complex Information Technology and Cybersecurity audits and other general system and application controls, IT processes, project management, and data integrity audit projects/initiatives utilizing information technology control frameworks, such as ITIL, COBIT, and FFIEC, or other relevant regulatory guidance (e.g., NYSDFS 500).
Responsibilities
- Effectively prepare a well-developed risk-based audit approach related to Information and Cybersecurity, Data Protection, Business Continuity Management, Physical Data Security, and other relevant information technology areas, ensuring alignment to current regulatory requirements (e.g., FFIEC, NYSDFS 500) and emerging risks.
- Proactively lead the development of the information technology Risk Assessment of the audit universe and the Audit Plan, incorporating IT audit standards and frameworks (e.g., ITIL, COBIT, FFIEC, ISO 17799, ISO/IEC 27002), data security and privacy regulations, and infrastructure technologies.
- Stay abreast of industry IT trends to identify potential issues, risks, and relevant best practices, laws, rules, and regulations impacting financial institutions, incorporating changes into the risk assessment process.
- Execute high-value IT audits, identify risks, assess mitigating controls, determine root causes, and make value-add recommendations to improve the control environment through well-developed audit reports.
- Leverage knowledge of systems and data to perform and document all reviews in a manner consistent with acceptable professional standards, including supporting audit procedures, findings, and results.
- Manage the audit issues follow-up process, review evidence of closure of findings, and determine that evidence of remediation is appropriate to effectively mitigate risks.
- Participate in department-wide initiatives, audit new product processes and systems, and perform other duties as assigned.
Requirements
- Approximately 15+ years of advanced professional auditing or comparable experience in a banking environment, providing exposure to progressive audit techniques, sophisticated information systems, network security, technology infrastructure, software development, project management, or related fields.
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field.
- In-depth knowledge of developing and implementing cybersecurity, privacy, and IT risk strategies in operational cybersecurity, privacy, and/or IT risk to assist management in continuous program improvement.
- Advanced understanding of information systems audit concepts, including security and control risks such as information security, logical and physical access security, change management, business recovery practices, and network technology.
- Expert knowledge of the IT-related regulatory environment and applicable banking regulations.
- Expert knowledge of control objectives for information and related technology, accepted auditing standards, and standards for the Professional Practice of Internal Auditing.
- Demonstrated ability to adapt quickly to changing demands and rapidly develop in-depth knowledge of new audit areas.
- Excellent verbal and written communication skills, with the ability to interact comfortably with all levels of management and Board-level committees.
- Ability to employ appropriate tools to enhance the audit process.
Qualifications
At least two of the following certifications (or equivalent) are strongly preferred:
- Certified Information System Auditor (CISA)
- Certified Information Systems Security Professional (CISSP)
- Certified in Risk and Information Systems Control (CRISC)
- Certified Information Privacy Professional (CIPP)
- Certified in the Governance of Enterprise IT (CGEIT)
- Certified Information Security Manager (CISM)
Pay
The expected annual salary for this position is between $200,000 and $250,000 at the start of employment. A salary offer is determined on an individualized basis, taking into consideration factors such as skills and experience.
Benefits
- Eligibility for an annual bonus
- Medical, pharmacy, dental, and vision plans
- Life and disability insurance
- Employee wellness program
- Retirement and savings plans with employer contributions
- Generous holiday and paid time off schedules
- Parental leave
- Tuition reimbursement
Schedule
Hybrid schedule.
Additional Information
The bank will make reasonable accommodations for employees with known mental or physical disabilities, pregnant individuals, victims of domestic violence or stalking, and employees with religious observance and practice obligations. Requests for accommodation should be directed to a supervisor or Human Resources.