IT Audit Manager
KBR Careers
Title IT Audit Manager KBR is seeking an experienced IT Audit Manager to join the Internal Audit & Advisory team. This role is responsible for leading and overseeing the organization's IT Sarbanes-Oxley (SOX) compliance program, including the planning, execution, and reporting of IT General Controls (ITGC), application controls, automated controls, interface controls, and Software Development Lifecycle (SDLC) control testing. The IT Audit Manager will partner closely with IT leadership, business process owners, internal controls teams, and external auditors to ensure an effective control environment, timely remediation of identified deficiencies, and ongoing compliance with SOX 404 requirements. The ideal candidate brings strong experience managing IT SOX programs within complex global organizations, demonstrated expertise in IT control frameworks and risk assessment methodologies, and a proven ability to lead and develop audit teams while driving high-quality, risk-based audit execution. Key Responsibilities Manage the annual IT SOX compliance program, including planning, execution, monitoring, and reporting activities across IT control domains. Develop and maintain risk-based testing strategies and audit plans covering IT General Controls (ITGCs), application controls, automated controls, interface controls, and SDLC controls. Oversee walkthroughs, control assessments, and testing activities to evaluate the design and operating effectiveness of key IT controls. Lead and review testing of ITGCs, including access management, change management, IT operations, and system development controls. Direct testing and evaluation of SDLC controls, including development approvals, testing evidence, release management, and production migration processes. Oversee testing of key automated controls, application controls, system interfaces, and management reports used in financial reporting processes. Manage and mentor onshore and offshore IT audit and SOX testing teams, ensuring consistency, quality, and adherence to established audit methodologies. Review workpapers, testing documentation, and audit evidence to ensure accuracy, completeness, and compliance with professional standards. Partner with IT management, Internal Controls, business process owners, and external auditors to coordinate testing activities, address control issues, and facilitate audit reliance. Evaluate identified control deficiencies, assess potential SOX impact and severity, and provide recommendations for corrective actions. Monitor remediation activities, validate the effectiveness of corrective actions, and track resolution through completion. Prepare and present status reports, executive dashboards, testing summaries, and risk updates to management and key stakeholders. Basic Qualifications Education & Experience Bachelor's degree in Information Systems, Information Technology, Computer Science, Accounting, Finance, Audit, or a related field. Minimum of 10 years of progressive experience in IT audit, IT risk management, IT controls, IT compliance, or related disciplines. Minimum of 4 years of experience leading and managing IT SOX compliance programs and audit teams. Experience conducting and overseeing SOX 404 testing within large, complex, and global organizations. Demonstrated experience leading cross-functional initiatives involving IT, Internal Controls, Finance, and external audit stakeholders. Experience managing distributed, onshore, and offshore resources in a testing or audit environment. Technical & Leadership Skills Deep knowledge of IT General Controls (ITGCs), including access management, change management, IT operations, and system development controls. Strong expertise in SOX 404 compliance requirements, control testing methodologies, and internal control frameworks. Experience evaluating and testing application controls, automated controls, interface controls, and system-generated reports. Strong understanding of Software Development Lifecycle (SDLC) processes and associated control requirements. Proven ability to assess control design and operating effectiveness, identify risks, and evaluate control deficiencies. Strong analytical, problem-solving, and risk assessment skills. Ability to manage multiple priorities, projects, and deadlines in a fast-paced environment. Effective leadership, coaching, and team development capabilities. Excellent verbal and written communication skills with the ability to present complex technical and compliance matters to diverse audiences. Strong stakeholder management and relationship-building skills across business and technology functions. Preferred Qualifications Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), or equivalent professional certification. Prior experience within a publicly traded organization with mature SOX compliance requirements. Experience supporting external audit reliance strategies and coordinating with external auditors. Knowledge of leading control frameworks and governance standards, including COBIT, NIST, and related IT risk frameworks. Experience supporting digital transformation, ERP implementations, cloud environments, or large-scale technology change initiatives. Advanced experience with data analytics, audit automation, or continuous controls monitoring tools. Additional Compensation: KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels, per internal policy or contractual designation. Additional compensation may be in the form of sign on bonus, relocation benefits, short term incentives, long term incentives, or discretionary payments for exceptional performance. Benefits: KBR offers a selection of competitive lifestyle benefits which could include a 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule. We support career advancement through professional training and development. Belong, Connect and Grow at KBR At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team’s philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver - Together. KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law. R2127914 #J-18808-Ljbffr
$120k - $150k
...For more than 40 years, Wil has provided expert accounting, auditing, and consulting services to a growing number of federal, state... ...contact a recruitment team member. The Opportunity: The IT Audit Manager is responsible for leading the planning and execution of...SuggestedFull timeContract workPart timeWork at officeLocal areaImmediate startRemote workWork from homeMonday to FridayFlexible hoursWeekend workAfternoon shift- ...We are seeking an experienced IT Audit Director with deep expertise in AI, cybersecurity, cloud infrastructure, and emerging technology... ...Looking For ~8+ years of experience in IT Audit, IT Risk Management, Information Security, or a related technology risk discipline...Suggested
- Job DescriptionECS is seeking a TS-cleared Junior Information Systems Security Officer (ISSO) to support one of our mission critical programs for the Department of Justice in Washington, DC.We offer the chance to support the world’s finest law enforcement organization and...Suggested
$151.66k
Agency: Federal Emergency Management AgencyDepartment: Department of Homeland SecuritySalary: Starting at $151,661 Per year (ES 00)Dates: Open 09/21/2026 to 10/05/2026Schedule: Full-timeWork type: PermanentRelocation: TruePosition ID: FEMA-26-JG-CISO-SESDocument ID: 88...Suggested$104k - $166k
...include:Assist the Information System Security Manager (ISSM) with information assurance efforts,... ...workflows, periodic access reviews, and audit compliance requirementsTranslate security... ...integrator and transformative enterprise IT provider, we deliver trusted, highly...SuggestedContract workShift work- ...correction or mitigation actions. Develop Plan of Action and Milestones (POAMs) in response to reported security vulnerabilities. Manage the risks to ISs and other FBI assets by coordinating appropriate correction or mitigation actions, and oversee and track the...Work at office
$120k - $200k
...accreditation artifacts into a structured, auditable repository. Support audits,... ...based systems. Experience accrediting IT systems against U.S. Government standards... ...configurations. Understanding of configuration management and automation tools (e.g., Puppet, Terraform...Full timeFlexible hours- ...the authoritative subject matter expert on security policy, risk management, and compliance within the Intelligence Community. What you’... ...improvements across AI/ML and data platforms Support audits, inspections, and reviews by government oversight authorities...Full timeRemote workHome officeRelocation packageFlexible hours
$131.6k
...and procedures to acquire and maintain an Information System's Authority to Operate (ATO) under the Federal Information Security Management Act (FISMA) of 2002. Lead RMF A&A efforts, including activities within the A&A cycle and outside of the ISSO functions, work directly...Remote work1 day per week- ...support Federal cybersecurity operations focused on continuous monitoring, RMF execution, authorization maintenance, vulnerability management, audit readiness, and cybersecurity governance Senior ISSOs serve as cybersecurity subject matter experts supporting assigned...Hourly pay
$120k - $170k
...seeking an Information System Security Officer (ISSO) to provide IT professional support for Information System Security Officer (... ...and unclassified networks in accordance with the DOJ/NIST Risk Management Framework (RMF). Develop and update artifacts for all control...- ...critical workstreams in RMF, continuous monitoring, and vulnerability management. You will work directly with federal staff to ensure systems... ...results and verifying log ingestion in Splunk. Incident & Audit Support: Provide critical ISSO support during cybersecurity...Full time
$120.8k - $265.8k
...dynamic environment, collaborating with IT system owners, stakeholders, and cybersecurity... ...engineering efforts for assigned Program Management Organizations with direct support to the... ...developing remediation work plans for audit findings. The Senior ISSO will maintain Hardware...Full timeContract workWork experience placementWork at officeFlexible hours$150k - $210k
...Officer supports cybersecurity, security authorization, and Risk Management Framework activities across a large-scale enterprise... ...Assessments and Documentation Conduct security assessments and audits. Identify vulnerabilities and recommend mitigations to strengthen...Full timeWork experience placement- ...implementing and overseeing security policies, managing risk assessments, and ensuring compliance... .... You will work closely with other IT teams to identify vulnerabilities, develop... ...Python, Bash) Experience with security audits and assessments YOUR FOREVER CAREER...Temporary workFor contractorsImmediate startFlexible hours
- ...Information Systems Security Office (ISSO) to work collaboratively with our Electronic Security team and our US Navy customer to develop and manage the Authority to Operate required for the Electronic Security System upgrade and integration. As an Information Systems Security...Work at office
$150k
...we specialize in the seamless delivery of IT modernization and elite cybersecurity... ...monitoring duties in alignment with the NIST Risk Management Framework (RMF), Departmental/Treasury... ...or as required. Ensure that system audit trails are regularly examined and anomalies...Contract workFor contractorsWork at office$114.13k - $171.2k
...resources. Develop a comprehensive Risk Management Framework (RMF) package including SSPs,... ...Accessors. Review and analyze system audit logs to identify anomalous activity and potential... ...(CPSO)/Facility Security Officer (FSO), IT Manager and team members to define,...Full timeContract workWork at office- ...cybersecurity technical lead responsible for implementing Risk Management Framework (RMF) activities, cloud security engineering, continuous... ..., cloud engineers, developers, and DevSecOps teams. Support audits and inspections from internal and external organizations....For contractorsFor subcontractorImmediate startFlexible hours
- ...sets the strategic direction for the firm’s Information Security Management System, security governance, risk management, incident response... ..., risk assessment, control monitoring, executive reporting, audit readiness, certification support, and continuous improvement. Serves...Work at officeRemote workRelocationVisa sponsorshipRelocation package
$120k - $175k
...Information System Owner (SO), Business Process Owner, and the Chief Information Security Officer (CISO) / Information System Security Manager (ISSM) on all matters, technical and otherwise, involving the security of an information system. Responsible for ensuring the...Contract workLocal area$145k - $155k
...cybersecurity policies, including ICD 503, DoD Instruction 8510.01 (Risk Management Framework), NIST SP 800-53 and related publications Prepare,... ...technology solutions. We deliver professional services in IT Design & Installation, Cybersecurity Engineering & Support,...Work at officeFlexible hours$165k - $200k
...Technologies has delivered the best solutions for unique business problems in the commercial and federal sectors ranging from Asset Management to IT Services. CDO employees demonstrate integrity, embrace teamwork, and embody a Can Do attitude in the delivery of superior...Full timeTemporary workWork at officeFlexible hoursNight shift$91k - $140k
...Dobbs Defense, we deliver mission-centric IT, Cyber, and data analytics solutions for... ...security controls in accordance with the Risk Management Framework (RMF), ensuring systems remain... ...assessments, vulnerability reviews, and audits using tools such as ACAS (Nessus), SCAP,...Local area$160k
...expertise and guidance for the security, authorization, vulnerability management, and continuous monitoring activities required to operate and... ...management, incident management, change management, audit and compliance, and access-control activities. Monitor and support...Contract workFor contractorsWork at officeLocal areaRemote work$103.8k - $218.1k
...environment, collaborating with Lead ISSOs, IT system owners, stakeholders, and... ...the Intermediate ISSO will execute Risk Management Framework activities for ATO decisions, ensure... ...technical vulnerability assessments, providing audit support documentation, and responding to...Contract workWork experience placementWork at officeLocal areaFlexible hours$78.6k - $160.2k
...Demonstrated ability to develop, implement, and oversee security and privacy controls, conduct security assessments, or ensure continuous audit readiness ~ Bachelor's in computer science, Cybersecurity, Data Science, Information Systems, Information Technology or Software...Local area$110k - $140k
...forefront of engineering, logistics, operations, science, program management, mission IT and cybersecurity solutions. Collaborative... ...standards and regulations Conduct security assessments and audits, identifying vulnerabilities and recommending mitigations to...Temporary workWork experience placementLocal areaRelocation package- Galapagos Federal Systems LLC is seeking an Information Systems Security Officer to oversee cybersecurity and IA for classified engineering and operational networks. The role ensures compliance with ICD 503, RMF, NIST SP 800-53, 800-37, 800-39, 800-30, CNSSI 1253, and ...
- ...emergency response deployment Required Experience or Knowledge 5+ years in cybersecurity and information systems security NIST Risk Management Framework implementation Security control assessment and testing Vulnerability analysis and remediation Technical risk...Contract work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Audit Manager. Be the first to apply!
- information technology instructor Arlington, VA
- IT infrastructure Arlington, VA
- entry-level information technology Arlington, VA
- information technology Arlington, VA
- information technology system analyst Arlington, VA
- junior IT professional Arlington, VA
- IT governance analyst Arlington, VA
- IT account executive Arlington, VA
- IT coordinator Arlington, VA
- IT scrum master Arlington, VA





