
Senior IT Audit Manager
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Create and uphold a risk-focused IT audit plan.
• Execute regular IT risk evaluations across systems, applications, infrastructure, and emerging technological areas.
• Oversee comprehensive IT audit projects from initial planning and scoping to fieldwork, reporting, and resolution of issues.
• Coordinate kickoff, status update, and conclusion meetings with process owners, system owners, and upper management.
• Design and implement IT control testing, including ITGC assessments for access management, change management, computer operations, and SDLC.
• Evaluate cybersecurity measures, encompassing network security, identity and access management, vulnerability management, and incident response.
• Review AWS and other cloud infrastructure security controls for reliability and compliance.
• Conduct audits of EHR and EMR systems and clinical application controls, ensuring adherence to HIPAA Security Rule, CCPA, and state regulatory requirements.
• Assist in the development of AI governance frameworks and controls addressing model governance, data quality, bias risk, and emerging AI regulations.
• Generate process narratives, system flowcharts, risk and control matrices, testing workpapers, and audit reports.
• Collaborate with management to design, address, and validate IT controls.
• Monitor audit issues and remediation strategies until resolution.
• Keep abreast of the evolving IT risk, cybersecurity, and regulatory environments.
• Report to the Head of Internal Audit and collaborate with technology and business leadership.
• Bachelor’s degree in Information Systems, Information Technology, Computer Science, or a related technical field.
• Current Certified Information Systems Auditor (CISA) certification.
• Over 7 years of progressive experience in IT auditing within business risk advisory consulting or internal audit with a focus on IT.
• Practical experience with IT general controls (ITGC) testing, including access management, change management, computer operations, and SDLC.
• Familiarity with COBIT, COSO, NIST 800-53, ISO 27001, and ISACA IT audit standards and professional practices.
• Experience auditing cybersecurity and cloud infrastructure controls, including AWS, Azure, or GCP.
• Understanding of HIPAA Security Rule stipulations.
• Experience with auditing application controls across SaaS platforms and regulated healthcare technology environments, including EHR and EMR systems.
• Proven use of AI tools to improve audit execution and control testing.
• Capability to independently manage IT audit engagements and handle multiple concurrent projects.
• Excellent written and verbal communication skills that are clear and concise.
• Preferred: Experience in public accounting with a focus on IT auditing or technology risk advisory.
• Preferred: CRISC, CISSP, CISM, or CIA certification.
• Preferred: Experience with SOX ITGC compliance in a pre-IPO, newly public, or high-growth environment.
• Preferred: Background in AI governance, data privacy, DevOps/SDLC security controls, GRC platforms, and digital health or telehealth.
• Must disclose whether visa sponsorship is required now or in the future.
• Medical, Dental & Vision coverage.
• Flexible Spending / Health Savings Accounts.
• Generous Paid Time Off (PTO).
• Hybrid work flexibility.
• 401(k) plan with Company Match.
• Life Insurance.
• Pet Insurance.
• Competitive salary and compensation package.
Health Advocate
Astreya
Mitsubishi Motors North America, Inc.
Sitetracker
Get handpicked remote jobs straight to your inbox weekly.