SENIOR MANAGER, IT INTERNAL AUDIT
SharkNinja France · Needham, MA · Yesterday
Information TechnologyFull-time
Responsibilities
- Facilitate the ERM program: build the smoke detectors
- Engineer the technical side of risk sensing: continuous monitoring, anomaly detection, and analytics that surface emerging risk signals across systems and data
- Own the technology, cybersecurity, data privacy, and third-party dimensions of the enterprise risk assessment, including for connected and IoT products
- Feed what the data shows into the risk-based plan, so IA's effort reflects where risk actually lives, not where it lived last year
- Execute risk-based business reviews: advisory and assurance
- Lead technology-focused business reviews driven by the risk assessment, including cyber, data privacy, system implementations, and third-party technology
- Embed data analytics across the function's reviews, testing full populations, not samples
- Run every engagement through our why/what/how lens and the three-lines qualifier: partner with IT and InfoSec as allies, coordinate without duplicating, and engage exactly where IA adds unique value
- Help define how SharkNinja audits AI: shape the governance and assurance approach for AI-enabled processes and tools
- Lead pre- and post-implementation reviews for major system deployments and enhancements
- Assess ICFR (SOX): own the technology control environment assessment
- Lead the ITGC dimension of IA's assessment of the effectiveness of internal control over financial reporting
- Tackle high-priority gaps including privileged and service account access, segregation of duties, and access governance
- Assess automated controls, key reports, and IPE assurance, ensuring the system-driven controls and data the assessment relies on are actually reliable
- Coordinate across the three lines and with external audit so reliance is maximized and duplication eliminated
- Deliver rapid insights
- Be the technical trusted resource: fast, risk-based answers on technology, security, and AI initiatives
Requirements
- 8+ years of progressive IT audit, IT risk, or technology risk advisory experience; Big 4 / national firm foundation plus in-house experience strongly preferred
- Strong command of risk-based auditing: technology risk assessment, planning driven by risk, and reporting that connects technical findings to business impact
- Deep ITGC and SOX 404 expertise across ERP environments, with Oracle Cloud/EBS experience strongly preferred and Coupa or other procure-to-pay platforms a plus, including experience coordinating across the three lines and positioning work for external auditor reliance
- Strong command of access management and segregation of duties concepts, including privileged and service account risk, and experience with GRC/access governance tools (e.g., Oracle Risk Management Cloud or similar)
- Experience testing automated controls, interfaces, key reports, and IPE
- Data analytics capability, including SQL, Python, Alteryx, or similar, with a track record of building monitoring or full-population testing that stuck
- CISA required or strongly preferred; CISSP, CRISC, CIA, or cloud certifications a plus
- Working knowledge of cybersecurity frameworks (NIST, ISO 27001) and data privacy fundamentals; exposure to IoT/connected product environments a plus
- AI fluency, or a genuine drive to build it. You'll work with agentic AI teammates daily and help build them
Qualifications
- Rarely Satisfied: a control that works today isn't the finish line; you push for sustainable, scalable design
- Progress Over Perfection: you sequence remediation pragmatically and keep the program moving
- Details Make the Difference: in ITGC, one shared credential is the difference
- Winning Is a Team Sport: you partner with IT and InfoSec as allies, complementing the teams already on the risk
- Communicating for Impact: you turn technical findings into decisions leaders can act on today. No surprises
Skills
- Strong command of risk-based auditing
- Deep ITGC and SOX 404 expertise
- Strong command of access management and segregation of duties concepts
- Data analytics capability
- AI fluency
Benefits
Salary and Other Compensation: The annual salary range for this position is displayed below. Factors which may affect starting pay within this range may include geography/market, skills, education, experience and other qualifications of the successful candidate.
The Company offers the following benefits for this position, subject to applicable eligibility requirements:
- medical insurance
- dental insurance
- vision insurance
- flexible spending accounts
- health savings accounts (HSA) with company contribution
- 401(k) retirement plan with matching
- employee stock purchase program
- life insurance
- AD&D
- short-term disability insurance
- long-term disability insurance
- generous paid time off
- company holidays
- parental leave
- identity theft protection
- pet insurance
- pre-paid legal insurance
- back-up child and eldercare days
- product discounts
- referral bonus program