Senior Manager, IT Audit
Aon’s Internal Audit Department reports directly to the Audit Committee of Aon plc’s Board of Directors, serving as an independent assurance function that helps Aon manage risk and strengthen its global control environment.
About the role
This leadership position manages complex IT and integrated audit engagements, partnering with business and technology leadership to assess risk, strengthen controls, and support Aon’s digital transformation and innovation initiatives.
Responsibilities
- Lead and oversee complex IT assurance, advisory, integrated audit, special investigation, and risk assessment projects included in the annual audit plan.
- Develop and execute risk-based audit approaches covering technology, cybersecurity, cloud, data, application, and operational risks.
- Evaluate the design and operating effectiveness of IT controls and identify opportunities to strengthen the overall control environment.
- Review and approve audit workpapers to ensure audit objectives are satisfied and documentation meets Internal Audit standards.
- Prepare and present audit findings, risk assessments, recommendations, and executive-level reports to business and technology leadership.
- Communicate technical control issues in a meaningful business context and articulate risks, impacts, and practical solutions.
- Assist Internal Audit Directors and Senior Directors in developing risk-based audit plans responsive to strategic priorities and emerging risks.
- Monitor changes in technology, cybersecurity, AI, cloud computing, automation, privacy, and regulatory requirements to identify new risk areas.
- Participate in enterprise risk assessments and provide insight regarding technology and information security risks.
- Evaluate the adequacy of management’s remediation efforts and validate closure of technology-related audit findings.
- Build and maintain strong relationships with business, technology, cybersecurity, privacy, compliance, and risk management stakeholders.
- Serve as a trusted advisor while maintaining Internal Audit’s independence and objectivity.
- Collaborate with management to drive sustainable control improvements and risk reduction initiatives.
- Present audit results and risk themes to executive leadership and support Audit Committee reporting activities as required.
- Lead, mentor, and develop Internal Audit staff assigned to audit engagements.
- Supervise co-sourced audit resources and external professional service providers.
- Provide coaching, performance feedback, and knowledge transfer to enhance team capabilities.
- Support departmental initiatives, innovation efforts, methodology enhancements, and special projects.
Qualifications
- 8+ years of IT audit, information security, technology risk, internal audit, external audit, or comparable experience within:
- A large multinational organization,
- Financial services organization,
- Insurance industry organization, and/or
- Big Four or comparable professional services firm.
- Demonstrated experience leading complex IT and integrated audit engagements.
- Experience supervising audit teams and managing stakeholder relationships at multiple organizational levels.
Skills
- IT General Controls (ITGCs)
- Application controls
- IT governance and risk management
- Cybersecurity controls and assessments
- Identity and access management
- Infrastructure and network security reviews
- Cloud computing environments
- Technology resilience and disaster recovery
- Data governance and privacy controls
- Third-party technology risk management
- Regulatory and compliance requirements
- Cybersecurity frameworks and regulatory requirements, including:
- NIST Cybersecurity Framework
- COBIT
- ISO 27001
- SOX
- GDPR
- Auditing cloud platforms such as:
- Amazon Web Services (AWS)
- Microsoft Azure
- Google Cloud Platform (GCP)
- Containerized environments and modern technology architectures, including Docker and API-based integrations.
- Data analytics and visualization tools, including:
- Power BI
- Tableau
- SQL
- Python
- Intelligent automation and robotic process automation technologies such as Microsoft Power Automate.
- Artificial intelligence and machine learning governance concepts, including:
- Model governance
- AI risk management
- Bias detection and mitigation
- Explainability and transparency considerations
- Agile methodologies within audit planning and execution.
- Identifying practical, technology-enabled solutions that strengthen controls and improve business processes.
- Excellent verbal and written communication skills.
- Strong executive presence and presentation capabilities.
- Ability to translate complex technical concepts into business-relevant insights.
- Strong analytical, problem-solving, and critical-thinking skills.
- Exceptional organizational and project management capabilities.
- Ability to effectively influence and collaborate with stakeholders across all levels of the organization.
- Proven leadership skills with a collaborative, team-oriented, and results-driven approach.
- Curiosity, innovation mindset, and commitment to continuous improvement.
Education & Certifications
- Bachelor’s degree in Information Technology, Information Systems, Cybersecurity, Computer Science, Accounting, Finance, or a related discipline.
- Preferred Professional Certifications:
- Certified Information Systems Auditor (CISA)
- Certified in Risk and Information Systems Control (CRISC)
- Certified Internal Auditor (CIA)
- Certified Public Accountant (CPA)
- Certified Information Security Manager (CISM)
- Certified Information Systems Security Professional (CISSP)
- Other relevant audit, cybersecurity, cloud, or risk management certifications.
Pay
The salary range for this position (U.S. applicants) is $130,000 - $150,000 annually. The actual salary will vary based on education, experience, skills, and abilities, as well as internal equity and alignment with market data. The salary may also be adjusted based on geographic location. The salary range reflected is based on a primary work location of Chicago, Illinois.
Benefits
- Eligibility to participate in one of Aon’s annual incentive plans to receive an annual discretionary bonus in addition to base salary.
- 401(k) savings plan with employer contributions.
- Employee stock purchase plan.
- Consideration for long-term incentive awards at Aon’s discretion.
- Medical, dental, and vision insurance.
- Various types of leaves of absence.
- Paid time off, including 12 paid holidays throughout the calendar year, 15 days of paid vacation per year, and paid sick leave as provided under state and local paid sick leave laws.
- Short-term disability and optional long-term disability.
- Health savings account, health care, and dependent care reimbursement accounts.
- Employee and dependent life insurance and supplemental life and AD&D insurance.
- Optional personal insurance policies.
- Adoption assistance.
- Tuition assistance.
- Commuter benefits.
- Employee assistance program that includes free counseling sessions.