Senior Audit Manager - Information Security
About the Role
The Corporate Audit Services Senior Audit Manager (SAM) is primarily responsible for leading staff in the completion of audit engagements and managing the assigned Information Security audit portfolio. This role provides oversight of audit engagements to ensure they meet timelines, quality, and budgetary requirements. The SAM offers thought leadership and strategic direction on the coverage of information security risks at the Bank, develops audit plans, serves as co-risk owner, and coaches and develops team members.
Partners with Senior to Executive Leaders in their assigned Line of Business, Risk/Compliance/Audit (RCA) Consultants, RCA Managers, and other Senior RCA Managers to oversee the successful creation, implementation, and maintenance of an effective risk management framework. Accountable for projects and activities ensuring compliance with applicable federal, state, and local laws and regulations. Identifies gaps and drives solutions to minimize losses from inadequate internal processes, systems, or human errors. Actively identifies, responds to, or escalates risks as appropriate, influences policies and procedures to maximize profit potential and minimize regulatory exposure, and ensures effective partnership between the Line of Business and the Lines of Defense.
Manages a team of RCA Professionals with responsibility for staffing, performance management, prioritizing, guidance, and training.
Responsibilities
- Lead and oversee audit engagements to meet timelines, quality, and budgetary requirements.
- Provide thought leadership and strategic direction on information security risks.
- Develop and implement audit plans.
- Serve as co-risk owner and coach/develop team members.
- Partner with senior leaders to create, implement, and maintain an effective risk management framework.
- Ensure compliance with applicable federal, state, and local laws and regulations.
- Identify gaps and drive solutions to minimize losses from internal process failures.
- Actively identify, respond to, or escalate risks.
- Influence policies and procedures to maximize profit potential and minimize regulatory exposure.
- Manage a team of RCA professionals, including staffing, performance management, and training.
Requirements
- Undergraduate degree in a Technology, Cybersecurity, or Engineering-related field or equivalent combination of training and experience.
- Professional certification (e.g., CISSP, CISM, CISA, CIA, AWS Cloud Practitioner, Microsoft Azure Administrator, AI-related certification) or advanced degree (e.g., MS in Technology/Information Security, MBA) is a plus.
- Expert in project management and execution, including prioritizing tasks and balancing workload across multiple projects.
- Experience with Agile, Continuous Deployment, Continuous Delivery, DevSecOps, and Secure Software Development.
- API and Cloud Migration experience.
- Advanced data analytics, AI, and visualization acumen.
- Strong knowledge of IT Frameworks (e.g., COBIT, ITIL, NIST, FEDRAMP, PCI-DSS, CRI Cyber Risk Profile, AGILE, AWS Well Architected Framework) and experience implementing or leveraging these frameworks in audit and risk management practices.
- Technical knowledge of at least two of the following: API, secure cloud architecture, data encryption, deployment models, Zero Trust, network segmentation, authentication/authorization protocols, or cryptography. Hands-on experience in at least one of these areas.
- Bachelor's or advanced degree, or equivalent work experience. Typically more than 12 years of applicable experience.
Skills
- Critical thinking and intellectual curiosity.
- Strong written and verbal communication skills, with the ability to create clear, concise, and engaging messaging.
- Ability to work well under deadline pressure.
- Track record in developing team members.
- Considerable understanding of applicable laws, regulations, financial services, and regulatory trends impacting the assigned line of business.
- Thorough knowledge of the business line’s operations, products/services, systems, and associated risks/controls.
- Strong leadership and management skills for processes, projects, and people.
- Effective skills at managing stressful situations.
- Strong analytical, problem-solving, and negotiation skills.
- Proficient computer skills, especially Microsoft Office applications.
Location Requirements
This role requires working from a U.S. Bank location three (3) or more days per week.
Benefits
- Healthcare (medical, dental, vision).
- Basic term and optional term life insurance.
- Short-term and long-term disability.
- Pregnancy disability and parental leave.
- 401(k) and employer-funded retirement plan.
- Paid vacation (from two to five weeks depending on salary grade and tenure).
- Up to 11 paid holiday opportunities.
- Adoption assistance.
- Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law.
Pay
Pay Range: $143,905.00 - $169,300.00. The salary range reflects figures based on the primary location. The actual range for the role may differ based on the location of the role. In addition to salary, U.S. Bank offers a comprehensive benefits package, including incentive and recognition programs, equity stock purchase, 401(k) contribution, and pension (all benefits are subject to eligibility requirements).