IT Audit Manager
KBR
Title:IT Audit ManagerKBR is seeking an experienced IT Audit Manager to join the Internal Audit & Advisory team. This role is responsible for leading and overseeing the organization's IT Sarbanes-Oxley (SOX) compliance program, including the planning, execution, and reporting of IT General Controls (ITGC), application controls, automated controls, interface controls, and Software Development Lifecycle (SDLC) control testing. The IT Audit Manager will partner closely with IT leadership, business process owners, internal controls teams, and external auditors to ensure an effective control environment, timely remediation of identified deficiencies, and ongoing compliance with SOX 404 requirements.The ideal candidate brings strong experience managing IT SOX programs within complex global organizations, demonstrated expertise in IT control frameworks and risk assessment methodologies, and a proven ability to lead and develop audit teams while driving high-quality, risk-based audit execution.Key ResponsibilitiesManage the annual IT SOX compliance program, including planning, execution, monitoring, and reporting activities across IT control domains.Develop and maintain risk-based testing strategies and audit plans covering IT General Controls (ITGCs), application controls, automated controls, interface controls, and SDLC controls.Oversee walkthroughs, control assessments, and testing activities to evaluate the design and operating effectiveness of key IT controls.Lead and review testing of ITGCs, including access management, change management, IT operations, and system development controls.Direct testing and evaluation of SDLC controls, including development approvals, testing evidence, release management, and production migration processes.Oversee testing of key automated controls, application controls, system interfaces, and management reports used in financial reporting processes.Manage and mentor onshore and offshore IT audit and SOX testing teams, ensuring consistency, quality, and adherence to established audit methodologies.Review workpapers, testing documentation, and audit evidence to ensure accuracy, completeness, and compliance with professional standards.Partner with IT management, Internal Controls, business process owners, and external auditors to coordinate testing activities, address control issues, and facilitate audit reliance.Evaluate identified control deficiencies, assess potential SOX impact and severity, and provide recommendations for corrective actions.Monitor remediation activities, validate the effectiveness of corrective actions, and track resolution through completion.Prepare and present status reports, executive dashboards, testing summaries, and risk updates to management and key stakeholders.Basic QualificationsEducation & ExperienceBachelor's degree in Information Systems, Information Technology, Computer Science, Accounting, Finance, Audit, or a related field.Minimum of 10 years of progressive experience in IT audit, IT risk management, IT controls, IT compliance, or related disciplines.Minimum of 4 years of experience leading and managing IT SOX compliance programs and audit teams.Experience conducting and overseeing SOX 404 testing within large, complex, and global organizations.Demonstrated experience leading cross-functional initiatives involving IT, Internal Controls, Finance, and external audit stakeholders.Experience managing distributed, onshore, and offshore resources in a testing or audit environment.Technical & Leadership SkillsDeep knowledge of IT General Controls (ITGCs), including access management, change management, IT operations, and system development controls.Strong expertise in SOX 404 compliance requirements, control testing methodologies, and internal control frameworks.Experience evaluating and testing application controls, automated controls, interface controls, and system-generated reports.Strong understanding of Software Development Lifecycle (SDLC) processes and associated control requirements.Proven ability to assess control design and operating effectiveness, identify risks, and evaluate control deficiencies.Strong analytical, problem-solving, and risk assessment skills.Ability to manage multiple priorities, projects, and deadlines in a fast-paced environment.Effective leadership, coaching, and team development capabilities.Excellent verbal and written communication skills with the ability to present complex technical and compliance matters to diverse audiences.Strong stakeholder management and relationship-building skills across business and technology functions.Preferred QualificationsCertified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), or equivalent professional certification.Prior experience within a publicly traded organization with mature SOX compliance requirements.Experience supporting external audit reliance strategies and coordinating with external auditors.Knowledge of leading control frameworks and governance standards, including COBIT, NIST, and related IT risk frameworks.Experience supporting digital transformation, ERP implementations, cloud environments, or large-scale technology change initiatives.Advanced experience with data analytics, audit automation, or continuous controls monitoring tools.Additional Compensation: KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels, per internal policy or contractual designation. Additional compensation may be in the form of sign on bonus, relocation benefits, short term incentives, long term incentives, or discretionary payments for exceptional performance.Benefits: KBR offers a selection of competitive lifestyle benefits which could include a 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule. We support career advancement through professional training and development.Belong, Connect and Grow at KBRAt KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team’s philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver – Together. KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.SummaryLocation: Arlington, Virginia; Colorado Springs, Colorado; Washington, DCType: Full time
- Technology Audit & Advisory Senior Manager (Tysons Corner - Hybrid)Step into a leadership role with a dynamic and collaborative professional services... ...and proposal preparation.Areas of Focus:Cybersecurity and IT risk managementIT frameworks and General Controls (ITGC)...SuggestedWork experience placementLocal areaRemote work
$99k - $232k
...Industry/Sector Not Applicable Specialism Business Controls Management Level Manager Job Description & Summary The Opportunity As an IT Audit Controls/SOX Manager, you will play a pivotal role in delivering comprehensive internal audit services across various...SuggestedFull timeH1b$130k - $150k
...IT Systems Audit Manager And Subject Matter Expert (SME)At Credence, we support our clients' mission-critical needs, powered by technology. We provide cutting-edge solutions, including AI/ML, secure cloud, digital transformation, and advanced intelligence capabilities...SuggestedTemporary workWork at officeImmediate startWork from home- ...Financial/IT Audit Manager (Secret Clearance Needed)We are seeking a highly qualified IT Audit Manager to join our team in Arlington, VA. The ideal candidate will possess a Master's Degree in Accounting, Finance, Information Technology, or Business Management, or hold...SuggestedRemote workWork from homeFlexible hours2 days per week3 days per week
$120k - $150k
...For more than 40 years, Wil has provided expert accounting, auditing, and consulting services to a growing number of federal, state... ...contact a recruitment team member. The Opportunity: The IT Audit Manager is responsible for leading the planning and execution of...SuggestedFull timeContract workPart timeWork at officeLocal areaImmediate startRemote workWork from homeMonday to FridayFlexible hoursWeekend workAfternoon shift$101k - $155k
...The Basics: The ideal candidate brings extensive experience leading audit and compliance programs across multiple frameworks and certifications. The IT Audit Manager builds and runs Tanium's audit program, leading a team of auditors, developing audit methodology, and...Full timeLive inWorldwideFlexible hours- ...submission to CISO and CIO approval.Ensure all assessment and audit reports are uploaded properly to the DOC FISMA tool.Conduct reviews... ..., the Privacy Act, and possess a working knowledge of Risk Management and associated Artifacts required by FISMACyberCore has, on many...
- ...detailed knowledge and expertise required to manage the security aspects of assigned... ...otherwise, involving the security of assigned IT systems.In coordination with SO team, develop... ...vulnerabilities identified during risk assessments, audits, inspections, etc.Provide the required...Full timeWork experience placementLocal areaFlexible hours
$90k - $140k
...Create Waivers or Risk Acceptance Memos to assist in the effective management of system risks Conduct an annual assessment in accordance with... ...Vulnerability Management (ISVM)/Patch Management Provide audit support for assigned systems (Financial, A-123, FISMA, internal...Local areaFlexible hours$115.4k - $192.3k
...partner with Engineering, Cloud Operations, DevOps, Product, and Compliance teams to maintain authorization, manage continuous monitoring activities, support audits and assessments, and drive security improvements across the platform. The ideal candidate combines strong...Full timeFor contractorsWork experience placementLocal area$99k - $225k
Information Systems Security Officer, Senior The Opportunity: Manage the day-to-day operations and effectiveness of security-related programs and initiatives. Assess the costs associated with potential threats and solutions required to eliminate or minimize threats....Full timeContract workPart timeWork at officeLocal areaRemote work$99.2k - $145k
...strategic security guidance, challenge and oversight, helping ensure information security risks are effectively identified, assessed, and managed in alignment with enterprise policies, standards, and regulatory expectations. The successful candidate will become a trusted...Full timeWork at officeFlexible hoursDay shift$104k - $166k
...include:Assist the Information System Security Manager (ISSM) with information assurance efforts,... ...workflows, periodic access reviews, and audit compliance requirementsTranslate security... ...integrator and transformative enterprise IT provider, we deliver trusted, highly...Contract workShift work- ...developing and enforcing security policies, conducting regular security audits, and staying up to date with the latest cybersecurity threats... ...in accordance with Departmental directives and applicable Risk Management Implementation Plans (RMIPs).- Verify authenticator generation...Minimum wageFull timeContract workTemporary workWork experience placement
$92.21k - $125.15k
...position includes full life-cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the... ...such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance...Full timeLocal area- ...overseeing information assurance processes, security documentation, audit readiness, and coordination across technical and operational... ...obligations are met· Support continuous monitoring, risk management, and policy enforcement activities· Provide status reporting and...
- ...background in network security, threat detection, and vulnerability management In-depth knowledge of securing cloud environments (e.g.,... ...an award-winning company that delivers Information Technology (IT) engineering services and solutions and non-IT subject matter expertise...For contractorsFixed term contractWorldwideRelocation package
$99.2k - $145k
...environments• Must display subject matter experience in application security, vulnerability testing, system testing, and/or Agile lifecycle management• Strong LOB knowledge/experience for the type of business they are aligned to (e.g..CSBB/GBM)• 1-2 years of risk management...Full timeWork at officeFlexible hoursDay shift- ...policies and procedures for complex, classified systems. This role ensures compliance with federal regulations and industry standards, manages risk, and supports the system lifecycle from design through decommissioning.Security Governance & ComplianceDevelop, implement, and...Temporary work
- ...utilities such as ACAS (Tenable Nessus) and SCAP (STIG benchmark) and manage a Plan of Actions and Milestones (POA&M) for remediation of... ...environments such as Amazon Web Services (AWS).Experience accrediting IT systems against U.S. Government standards including NIST SP 800-5...For contractors
$62k - $141k
...system development life cycle. Conduct hands-on validation and verification of system security hardening, vulnerability management and analysis, and audit log review by applying technical expertise and specific functional, working, and general industry knowledge to ensure...Full timeContract workPart timeWork at officeLocal areaRemote work- An established industry player is seeking a Project Manager to oversee high-priority projects and ensure successful... ...The ideal candidate will have a Bachelor's degree in IT or Accounting, along with relevant IT audit experience. This position offers an exciting...
- ...will be responsible for implementing and overseeing security policies, managing risk assessments, and ensuring compliance with relevant regulations and standards. You will work closely with other IT teams to identify vulnerabilities, develop security protocols, and monitor...Temporary workFor contractorsImmediate start
- ...engineering, computer engineering, computer science, or a closely related IT discipline.Significant experience navigating technical... ...Guardium, HP WebInspect, and Network Mapper (NMAP).Proven experience managing complex network documentation, inventorying networks, and...Work at officeRemote work
$120k - $145k
...Security Officer support for Security Assessment and Authorization, Risk Management Framework execution, authorization package development, continuous monitoring, vulnerability remediation, audit readiness, and security compliance for federal information systems.Salary...Work experience placement- ...Security Officer (CISO)The CISO is responsible for overseeing and managing the organization's information security program, ensuring the... ...and procedures.Conduct risk assessments and manage security audits.Ensure compliance with relevant laws and regulations.Collaborate...
- ...development and evaluation of attack scenarios.Prepares and delivers technical reports and briefings.Has a complete understanding of Risk Management Framework and implements the process on program systems/networks.Performs or reviews technical security assessments of computing...
- ...Systems Security Officer supporting the Case Management Modernization (CMM) Program. The CMM... ...phases of ATO.Coordinate with customer's IT security team, engineering team, and other... ...security breach escalation procedures, security auditing procedures, and use of firewalls and...Work experience placementWork at officeFlexible hours
$99k - $109k
...Devis is a leading provider of innovative software development, management, and consulting services, specializing in cutting-edge... ...authorization, continuous monitoring, vulnerability and POA&M management, audit support, and compliance. You will work directly in the agency's...Contract workRemote workMonday to Friday- ...system ATO and requirements to maintain the ATOExperience working with system stakeholders to assess and manage system cybersecurity riskAbility to synthesize complex IT system information and communicate system status and requirements in written products and verbal...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Audit Manager. Be the first to apply!
- information technology IT intern Arlington, VA
- IT student Arlington, VA
- visa sponsorship IT Arlington, VA
- IT associate Arlington, VA
- information technology intern Arlington, VA
- IT project coordinator Arlington, VA
- senior director it Arlington, VA
- it operations coordinator Arlington, VA
- information technology support Arlington, VA
- IT coordinator Arlington, VA


