SVP, Head of Corporate Audit for Information Technology
About the Role
We are seeking a Senior Vice President (SVP) of Corporate Audit – Head of Corporate Audit for Information Technology. This pivotal leadership role within Corporate Audit reports directly to the General Auditor and is responsible for establishing, directing, and executing Corporate Audit’s strategy for activities related to Global Technology Services. Based in the Boston office four days a week, this executive will lead the infrastructure, cyber, and horizontal IT audit functions and serve as a member of the global Corporate Audit Management Committee, influencing and collaborating on the global Corporate Audit strategy and methodology.
Corporate Audit independently assesses the effectiveness of the internal control environment, proactively advises on risk management, and influences the organization’s culture of risk excellence. This role plays a critical part in ensuring the overall success of the organization, helping navigate employees and the business as a whole while driving cutting-edge, scalable solutions.
Responsibilities
- Set the strategy for all IT infrastructure, cyber, and business IT risk coverage and audits globally.
- Build, develop, and sustain a high-performing organization by cultivating a strong pipeline of leaders and technical experts, fostering upward mobility, succession readiness, and a culture of excellence, accountability, and role-model leadership.
- Build out continuous auditing processes, including the use of data analytics.
- Collaborate closely with global peers for business and legal entity audits.
- Advise the General Auditor and the E&A Committee of the Board on technology risks.
- Maintain key stakeholder relationships across the organization, including the CIO, CISO, CTO, and other senior leaders.
- Manage, build, and develop a diverse global team of auditors providing expert advice and assurance on technology risks, including cyber risks and threats.
- Ensure the IT audit function is well integrated with the overall audit program.
- Communicate audit findings and recommendations effectively to the bank’s leadership team.
- Monitor and track progress on audit findings and recommendations.
- Serve as a subject matter expert for technology risk and controls frameworks, including NIST, and apply them effectively in audit work.
- Develop credible and strong working relationships with key regulators and communicate audit strategy and results effectively.
- Participate as an active non-voting member of governance and risk committees and management steering committees, promoting balanced discussions and encouraging challenge and debate.
- Establish and maintain strong working partnerships with peers while leading business and legal entity audits globally.
- Role model cross-cultural awareness and help establish and maintain a collaborative and inclusive global work environment.
- Drive transformation and continuous improvement in Corporate Audit practices, processes, and operational activities.
Requirements
- Minimum of 20 years of experience in infrastructure, cyber, IT risk management, or consulting, with at least 10 years of experience in IT audit or assurance leadership roles.
- Proven audit leader with expert knowledge of industry practices and professional standards.
- Minimum of 15 years of corporate audit experience in a large, global financial services firm.
- 10+ years of experience leading global teams with board-facing responsibilities.
- Thought leader in AI and emerging technologies.
- Strong Risk Management experience - expert skills in recognizing and assessing risk.
- Exceptional leadership, strategic planning, and communication skills with experience presenting to the highest level of executives and the board.
- Ability to manage complex programs in a fast-paced, highly regulated environment with proven impactful results that are industry-leading.
- Bachelor’s degree in Information Technology, Computer Science, or a related field; master’s degree preferred.
- Professional certifications in related fields (e.g., CISSP, CISA, or CISM) are required.
Skills
- Demonstrated understanding of technology risk management, including qualitative and quantitative assessments, IT and data processes and controls, global industry standards, leading frameworks, and emerging risks.
- Expertise in evaluating cyber security, cyber resiliency, and cyber maturity, with the ability to develop and implement effective audit coverage strategies.
- Strong knowledge of cyber and cloud technologies and tools, with the ability to assess associated risks, including data-driven monitoring and penetration test approaches.
- Proven interpersonal and communication skills at the executive and board level, with the ability to translate technology risk language into business terminology.
- Expertise in developing and maintaining relationships with multiple stakeholders, including board members, senior executives, management, and team members.
- Strong execution skills and experience leading a global team in large-scale project management activities.
- Highly organized, with extensive analytical, problem-solving, influence, and negotiation skills.
- Commitment to driving cultural values: Choose to Own it, Break through Silos, Deliver Results with Integrity and Speed, Do Better Every Day, Care for Colleagues, Clients, and Community.
Pay
Salary Range: $225,000 - $337,500 Annual. The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location, the applicable range could differ.
Benefits
- Retirement savings plan (401K) with company match.
- Insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages.
- Paid-time off including vacation, sick leave, short-term disability, and family care responsibilities.
- Access to Employee Assistance Program.
- Incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans).
- Eligibility for certain tax-advantaged savings plans.