IT Audit Manager
Apexcare Talent Solutions
California St, Willits, CA 95490, USAJob Overview
Job Overview
We are seeking an experienced and analytical IT Audit Manager to lead our technology audit program, evaluate IT controls, and manage enterprise risk across our digital infrastructure. In this role, you will be responsible for designing and executing comprehensive risk-based IT audit plans, assessing cloud and on-premises technical controls, and evaluating compliance with regulatory frameworks. You will collaborate closely with Information Security, IT Engineering, Finance, and Executive Leadership to identify technical vulnerabilities, improve internal control structures, and drive continuous risk mitigation.
Key Responsibilities
Audit Strategy & Execution
- Lead end-to-end IT, technical, and operational audits, evaluating the adequacy and effectiveness of internal controls across systems, applications, networks, and databases.
- Develop, maintain, and execute a risk-based IT annual audit plan aligned with corporate objectives and regulatory requirements.
- Assess technical design and operating effectiveness of General Computer Controls (ITGC), application controls, and automated business process controls.
Governance, Risk & Compliance (GRC)
- Ensure organizational compliance with key regulatory frameworks and security standards (e.g., SOX ITGC, SOC 1 / SOC 2, ISO 27001, NIST CSF, HIPAA, GDPR).
- Evaluate identity and access management (IAM), change management, business continuity/disaster recovery (BC/DR), and incident response protocols.
- Partner with Cybersecurity and DevOps teams to conduct risk assessments on cloud environments (AWS, Azure, GCP) and continuous delivery workflows.
Reporting & Team Leadership
- Author clear, concise, and impact-driven IT audit reports detailing scope, root-cause findings, risk levels, and actionable remediation recommendations for executive leadership and the Audit Committee.
- Track and validate management remediation plans to ensure audit findings and control deficiencies are effectively resolved in a timely manner.
- Mentor and lead senior and mid-level IT auditors, promoting high standards of technical work, documentation, and professional development.
Required Skills & Qualifications
Technical Skills & Expertise
- ITGC & Frameworks: Deep mastery of IT General Controls (ITGC), COBIT, NIST, ISO 27001, and SOX IT testing methodologies.
- Cloud & Infrastructure Auditing: Hands-on experience auditing cloud environments (AWS, Azure, GCP), network security, databases (SQL, Oracle), and operating systems (Linux, Windows).
- Data Analytics & Tools: Proficiency in data analytics and CAATTs (Computer-Assisted Audit Techniques) using tools like SQL, Python, ACL, or Tableau to perform audit sampling and continuous control monitoring.
- GRC Tools: Familiarity with modern GRC and audit management platforms (e.g., Workiva, AuditBoard, ServiceNow GRC).
Soft Skills & Strategic Acumen
- Exceptional verbal and written communication skills, with a proven ability to explain complex technical risks to non-technical business leaders and board members.
- Strong objective analytical skills, combined with a collaborative approach to problem-solving and process improvement.
Preferred Qualifications
- Education: Bachelor’s or Master’s degree in Management Information Systems (MIS), Computer Science, Cybersecurity, Accounting, or a related field.
- Experience: 6+ years of combined experience in IT audit, IT risk management, or cybersecurity consulting, with at least 2 years in a managerial or lead capacity.
- Certifications: Active professional certification such as CISA (Certified Information Systems Auditor) is required; additional certifications (CRISC, CISSP, CIA, or CISM) are highly preferred.
Benefits & Compensation
- Salary Range: $145,000 – $180,000 annually (commensurate with experience) + performance bonus.
- Comprehensive health, vision, and dental insurance plans.
- 401(k) retirement plan with company match.
- Flexible paid time off (PTO) and company-paid holidays.
- Professional development stipend for annual CPE credits, certifications, and conferences.