Jobs · Information Technology · Massachusetts

SENIOR MANAGER, IT INTERNAL AUDIT

SharkNinja France · Needham, MA · Yesterday
Information TechnologyFull-time

Responsibilities

  • Facilitate the ERM program: build the smoke detectors
  • Engineer the technical side of risk sensing: continuous monitoring, anomaly detection, and analytics that surface emerging risk signals across systems and data
  • Own the technology, cybersecurity, data privacy, and third-party dimensions of the enterprise risk assessment, including for connected and IoT products
  • Feed what the data shows into the risk-based plan, so IA's effort reflects where risk actually lives, not where it lived last year
  • Execute risk-based business reviews: advisory and assurance
  • Lead technology-focused business reviews driven by the risk assessment, including cyber, data privacy, system implementations, and third-party technology
  • Embed data analytics across the function's reviews, testing full populations, not samples
  • Run every engagement through our why/what/how lens and the three-lines qualifier: partner with IT and InfoSec as allies, coordinate without duplicating, and engage exactly where IA adds unique value
  • Help define how SharkNinja audits AI: shape the governance and assurance approach for AI-enabled processes and tools
  • Lead pre- and post-implementation reviews for major system deployments and enhancements
  • Assess ICFR (SOX): own the technology control environment assessment
  • Lead the ITGC dimension of IA's assessment of the effectiveness of internal control over financial reporting
  • Tackle high-priority gaps including privileged and service account access, segregation of duties, and access governance
  • Assess automated controls, key reports, and IPE assurance, ensuring the system-driven controls and data the assessment relies on are actually reliable
  • Coordinate across the three lines and with external audit so reliance is maximized and duplication eliminated
  • Deliver rapid insights
  • Be the technical trusted resource: fast, risk-based answers on technology, security, and AI initiatives

Requirements

  • 8+ years of progressive IT audit, IT risk, or technology risk advisory experience; Big 4 / national firm foundation plus in-house experience strongly preferred
  • Strong command of risk-based auditing: technology risk assessment, planning driven by risk, and reporting that connects technical findings to business impact
  • Deep ITGC and SOX 404 expertise across ERP environments, with Oracle Cloud/EBS experience strongly preferred and Coupa or other procure-to-pay platforms a plus, including experience coordinating across the three lines and positioning work for external auditor reliance
  • Strong command of access management and segregation of duties concepts, including privileged and service account risk, and experience with GRC/access governance tools (e.g., Oracle Risk Management Cloud or similar)
  • Experience testing automated controls, interfaces, key reports, and IPE
  • Data analytics capability, including SQL, Python, Alteryx, or similar, with a track record of building monitoring or full-population testing that stuck
  • CISA required or strongly preferred; CISSP, CRISC, CIA, or cloud certifications a plus
  • Working knowledge of cybersecurity frameworks (NIST, ISO 27001) and data privacy fundamentals; exposure to IoT/connected product environments a plus
  • AI fluency, or a genuine drive to build it. You'll work with agentic AI teammates daily and help build them

Qualifications

  • Rarely Satisfied: a control that works today isn't the finish line; you push for sustainable, scalable design
  • Progress Over Perfection: you sequence remediation pragmatically and keep the program moving
  • Details Make the Difference: in ITGC, one shared credential is the difference
  • Winning Is a Team Sport: you partner with IT and InfoSec as allies, complementing the teams already on the risk
  • Communicating for Impact: you turn technical findings into decisions leaders can act on today. No surprises

Skills

  • Strong command of risk-based auditing
  • Deep ITGC and SOX 404 expertise
  • Strong command of access management and segregation of duties concepts
  • Data analytics capability
  • AI fluency

Benefits

Salary and Other Compensation: The annual salary range for this position is displayed below. Factors which may affect starting pay within this range may include geography/market, skills, education, experience and other qualifications of the successful candidate.

The Company offers the following benefits for this position, subject to applicable eligibility requirements:

  • medical insurance
  • dental insurance
  • vision insurance
  • flexible spending accounts
  • health savings accounts (HSA) with company contribution
  • 401(k) retirement plan with matching
  • employee stock purchase program
  • life insurance
  • AD&D
  • short-term disability insurance
  • long-term disability insurance
  • generous paid time off
  • company holidays
  • parental leave
  • identity theft protection
  • pet insurance
  • pre-paid legal insurance
  • back-up child and eldercare days
  • product discounts
  • referral bonus program

Similar jobs