Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

IT Audit Manager

KBR Inc

Title:

IT Audit Manager

KBR is seeking an experienced IT Audit Manager to join the Internal Audit & Advisory team. This role is responsible for leading and overseeing the organization's IT Sarbanes-Oxley (SOX) compliance program, including the planning, execution, and reporting of IT General Controls (ITGC), application controls, automated controls, interface controls, and Software Development Lifecycle (SDLC) control testing. The IT Audit Manager will partner closely with IT leadership, business process owners, internal controls teams, and external auditors to ensure an effective control environment, timely remediation of identified deficiencies, and ongoing compliance with SOX 404 requirements.

The ideal candidate brings strong experience managing IT SOX programs within complex global organizations, demonstrated expertise in IT control frameworks and risk assessment methodologies, and a proven ability to lead and develop audit teams while driving high-quality, risk-based audit execution.

Key Responsibilities

  • Manage the annual IT SOX compliance program, including planning, execution, monitoring, and reporting activities across IT control domains.

  • Develop and maintain risk-based testing strategies and audit plans covering IT General Controls (ITGCs), application controls, automated controls, interface controls, and SDLC controls.

  • Oversee walkthroughs, control assessments, and testing activities to evaluate the design and operating effectiveness of key IT controls.

  • Lead and review testing of ITGCs, including access management, change management, IT operations, and system development controls.

  • Direct testing and evaluation of SDLC controls, including development approvals, testing evidence, release management, and production migration processes.

  • Oversee testing of key automated controls, application controls, system interfaces, and management reports used in financial reporting processes.

  • Manage and mentor onshore and offshore IT audit and SOX testing teams, ensuring consistency, quality, and adherence to established audit methodologies.

  • Review workpapers, testing documentation, and audit evidence to ensure accuracy, completeness, and compliance with professional standards.

  • Partner with IT management, Internal Controls, business process owners, and external auditors to coordinate testing activities, address control issues, and facilitate audit reliance.

  • Evaluate identified control deficiencies, assess potential SOX impact and severity, and provide recommendations for corrective actions.

  • Monitor remediation activities, validate the effectiveness of corrective actions, and track resolution through completion.

  • Prepare and present status reports, executive dashboards, testing summaries, and risk updates to management and key stakeholders.

Basic Qualifications

Education & Experience

  • Bachelor's degree in Information Systems, Information Technology, Computer Science, Accounting, Finance, Audit, or a related field.

  • Minimum of 10 years of progressive experience in IT audit, IT risk management, IT controls, IT compliance, or related disciplines.

  • Minimum of 4 years of experience leading and managing IT SOX compliance programs and audit teams.

  • Experience conducting and overseeing SOX 404 testing within large, complex, and global organizations.

  • Demonstrated experience leading cross-functional initiatives involving IT, Internal Controls, Finance, and external audit stakeholders.

  • Experience managing distributed, onshore, and offshore resources in a testing or audit environment.

Technical & Leadership Skills

  • Deep knowledge of IT General Controls (ITGCs), including access management, change management, IT operations, and system development controls.

  • Strong expertise in SOX 404 compliance requirements, control testing methodologies, and internal control frameworks.

  • Experience evaluating and testing application controls, automated controls, interface controls, and system-generated reports.

  • Strong understanding of Software Development Lifecycle (SDLC) processes and associated control requirements.

  • Proven ability to assess control design and operating effectiveness, identify risks, and evaluate control deficiencies.

  • Strong analytical, problem-solving, and risk assessment skills.

  • Ability to manage multiple priorities, projects, and deadlines in a fast-paced environment.

  • Effective leadership, coaching, and team development capabilities.

  • Excellent verbal and written communication skills with the ability to present complex technical and compliance matters to diverse audiences.

  • Strong stakeholder management and relationship-building skills across business and technology functions.

Preferred Qualifications

  • Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), or equivalent professional certification.

  • Prior experience within a publicly traded organization with mature SOX compliance requirements.

  • Experience supporting external audit reliance strategies and coordinating with external auditors.

  • Knowledge of leading control frameworks and governance standards, including COBIT, NIST, and related IT risk frameworks.

  • Experience supporting digital transformation, ERP implementations, cloud environments, or large-scale technology change initiatives.

  • Advanced experience with data analytics, audit automation, or continuous controls monitoring tools.

Additional Compensation: KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels, per internal policy or contractual designation. Additional compensation may be in the form of sign on bonus, relocation benefits, short term incentives, long term incentives, or discretionary payments for exceptional performance.

Benefits: KBR offers a selection of competitive lifestyle benefits which could include a 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule. We support career advancement through professional training and development.

Belong, Connect and Grow at KBRAt KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team's philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver - Together.

KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the IT Audit Manager in Washington DC vacancy
  • Title:IT Audit ManagerKBR is seeking an experienced IT Audit Manager to join the Internal Audit & Advisory team. This role is responsible for leading and overseeing the organization's IT Sarbanes-Oxley (SOX) compliance program, including the planning, execution, and reporting... 
    Suggested
    Full time
    Temporary work
    Local area
    Relocation package
    Flexible hours

    KBR

    Arlington, VA
    6 days ago
  •  ...sprints and provide subject matter expertise regarding financial audit issues in order to assist with the development of requirements, for...  ...(1) Subject matter expertise regarding financial and/or IT audit issues in order to assist with the development of requirements... 
    Suggested

    RightWorks Inc

    Washington DC
    3 days ago
  • $120k - $150k

     ...For more than 40 years, Wil has provided expert accounting, auditing, and consulting services to a growing number of federal, state...  ...contact a recruitment team member.   The Opportunity:   The IT Audit Manager is responsible for leading the planning and execution of... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Immediate start
    Remote work
    Work from home
    Monday to Friday
    Flexible hours
    Weekend work
    Afternoon shift

    Williams Adley

    Washington DC
    20 days ago
  • Sikich LLC is looking for a motivated IT Audit Manager to supervise an audit team and design audit plans in Alexandria, VA. Ideal candidates will have 8+ years of experience in auditing and a Bachelor's degree, preferably in Information Systems. Leadership skills and an... 
    Suggested
    Flexible hours

    Sikich LLC

    Alexandria, VA
    2 days ago
  • $155k

    IT Audit Manager (US - Alexandria, VA, Columbus, OH, Indianapolis, IN) Sikich is seeking a highly motivated and detail-oriented auditing professional with strong leadership and information technology skills. This role is contingent upon award of contract. This position... 
    Suggested
    Contract work
    Interim role
    Work at office
    Flexible hours

    Sikich LLC

    Alexandria, VA
    2 days ago
  • DescriptionTechnology Audit & Advisory Senior Manager (Tysons Corner - Hybrid)Step into a leadership role with a dynamic and collaborative professional...  ...and proposal preparation.Areas of Focus:Cybersecurity and IT risk managementIT frameworks and General Controls (ITGC)... 
    Work experience placement
    Local area
    Immediate start
    Remote work

    Robert Half

    McLean, VA
    4 days ago
  • $155k

     ...Summary Sikich is seeking a highly motivated and detail-oriented auditing professional with strong leadership and information technology...  ...matter technical expertise to delivery team in financial management areas of financial reporting, internal control, and/or financial... 
    Full time
    Contract work
    Interim role
    Work at office
    Local area
    Flexible hours

    Sikich LLP

    Alexandria, VA
    1 day ago
  • Sikich LLP is looking for a detail-oriented auditing professional in Alexandria, Virginia. The role involves supervising an audit team, ensuring quality work, and requires an active Secret clearance. Candidates should have a bachelor's degree in Information Systems and... 
    Flexible hours

    Sikich

    Alexandria, VA
    1 day ago
  •  ...detailed knowledge and expertise required to manage the security aspects of assigned...  ...otherwise, involving the security of assigned IT systems.In coordination with SO team, develop...  ...vulnerabilities identified during risk assessments, audits, inspections, etc.Provide the required... 
    Full time
    Work experience placement
    Local area
    Flexible hours

    Coalfire

    Washington DC
    5 days ago
  •  ...submission to CISO and CIO approval.Ensure all assessment and audit reports are uploaded properly to the DOC FISMA tool.Conduct reviews...  ..., the Privacy Act, and possess a working knowledge of Risk Management and associated Artifacts required by FISMACyberCore has, on many... 

    CyberCore Technologies

    Washington DC
    2 days ago
  • $115.4k - $192.3k

     ...partner with Engineering, Cloud Operations, DevOps, Product, and Compliance teams to maintain authorization, manage continuous monitoring activities, support audits and assessments, and drive security improvements across the platform. The ideal candidate combines strong... 
    Full time
    For contractors
    Work experience placement
    Local area

    Reed Technology

    Washington DC
    11 hours ago
  • $99k - $225k

    Information Systems Security Officer, Senior The Opportunity: Manage the day-to-day operations and effectiveness of security-related programs and initiatives. Assess the costs associated with potential threats and solutions required to eliminate or minimize threats.... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Washington DC
    11 hours ago
  • $92.21k - $125.15k

     ...position includes full life-cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the...  ...such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance... 
    Full time
    Local area

    CONTACT GOVERNMENT SERVICES

    Washington DC
    4 days ago
  • $110.18k - $183.63k

     ...compliance with cybersecurity standards and manages system risk.Ensure assigned systems comply...  ...tool (e.g., JCAM).Participate in security audits, assessments, and exercises.Report...  ...of experience in Information Technology (IT) and/or Information Security (IS).Active Secret... 
    Full time
    Temporary work
    Work at office
    Remote work
    Flexible hours

    NTT DATA

    Arlington, VA
    1 day ago
  • $104k - $166k

     ...include:Assist the Information System Security Manager (ISSM) with information assurance efforts,...  ...workflows, periodic access reviews, and audit compliance requirementsTranslate security...  ...integrator and transformative enterprise IT provider, we deliver trusted, highly... 
    Contract work
    Shift work

    Peraton Corporation

    Washington DC
    1 day ago
  • $99.2k - $145k

     ...strategic security guidance, challenge and oversight, helping ensure information security risks are effectively identified, assessed, and managed in alignment with enterprise policies, standards, and regulatory expectations. The successful candidate will become a trusted... 
    Full time
    Work at office
    Flexible hours
    Day shift

    Bank of America

    Washington DC
    2 days ago
  • $99.2k - $145k

     ...environments• Must display subject matter experience in application security, vulnerability testing, system testing, and/or Agile lifecycle management• Strong LOB knowledge/experience for the type of business they are aligned to (e.g..CSBB/GBM)• 1-2 years of risk management... 
    Full time
    Work at office
    Flexible hours
    Day shift

    Bank of America

    Washington DC
    2 days ago
  •  ...sets the strategic direction for the firm’s Information Security Management System, security governance, risk management, incident response...  ..., risk assessment, control monitoring, executive reporting, audit readiness, certification support, and continuous improvement.... 
    Full time
    Work at office
    Remote work
    Relocation
    Visa sponsorship
    Relocation package

    DLA Piper

    Washington DC
    4 days ago
  •  ...policies and procedures for complex, classified systems. This role ensures compliance with federal regulations and industry standards, manages risk, and supports the system lifecycle from design through decommissioning.Security Governance & ComplianceDevelop, implement, and... 
    Temporary work

    Kroll

    Washington DC
    1 day ago
  • $107.9k - $195.05k

     ...Security Officer (ISSO) Leidos - Cyber & Analytics Business Area, Key Management & Analytics Division, Your Experience. A Critical Mission. Real...  ...policies, standards, and methodologies.Plan and coordinate IT security programs and policies and help develop system security... 
    Full time
    Immediate start
    Remote work

    Leidos

    Laurel, MD
    4 days ago
  •  ...utilities such as ACAS (Tenable Nessus) and SCAP (STIG benchmark) and manage a Plan of Actions and Milestones (POA&M) for remediation of...  ...environments such as Amazon Web Services (AWS).Experience accrediting IT systems against U.S. Government standards including NIST SP 800-5... 
    For contractors

    Barbaricum

    Washington DC
    4 days ago
  • $151.66k

     ...$151,661 Per year (ES 00)Dates: Open 08/13/2026 to 08/27/2026Schedule: Full-timeWork type: PermanentRelocation: FalsePosition ID: COO-26-IMP-12998414Document ID: 880328600Grade: ES 00Job category: Information Technology Management (2210)Hiring path: fed-internal-search

    United States Government

    Washington DC
    3 days ago
  •  ...assist, advise, and guide the MARS developers through the Risk Management Framework (RMF). The contractor will apply knowledge and understanding...  ...an award winning company that delivers Information Technology (IT) engineering services and solutions and non-IT subject matter... 
    For contractors
    Work experience placement
    For subcontractor
    Worldwide

    Constellation West

    Washington DC
    4 days ago
  • $120k - $160k

     ...of publications, particularly those associated with NIST's Risk Management Framework and the Federal Risk and Authorization Management Program...  ...civilian markets includes secure high-end solutions in mission IT, enterprise IT, engineering services, and professional services.... 
    Local area
    Remote work

    Science Applications International Corporation

    Washington DC
    4 days ago
  • $141.5k - $236k

     ...Explore thrilling projects in Digital Transformation, Cybersecurity, IT, Data Analytics and Software Development. Elevate your career...  ...HP WebInspect, and Network Mapper (NMAP). ~ Proven experience managing complex network documentation, inventorying networks, and... 
    Hourly pay
    Contract work
    Temporary work
    Work experience placement
    Work at office
    Local area
    Remote work

    ManTech International Corporation

    Washington DC
    5 days ago
  •  ...expected to construct and perpetually update bodies of evidence for managed information systems, custom applications, services, and...  ...assessments and coordinating with external entities to facilitate audits. Your day-to-day tasks will involve a high degree of collaboration... 
    Contract work
    Work at office

    ASM Research

    Alexandria, VA
    3 days ago
  • $120k - $145k

     ...Security Officer support for Security Assessment and Authorization, Risk Management Framework execution, authorization package development, continuous monitoring, vulnerability remediation, audit readiness, and security compliance for federal information systems. Salary... 
    Work experience placement

    ECS Limited

    Washington DC
    4 days ago
  •  ...operation of Security Information and Event Management (SIEM) and Network Anomaly Detection and...  .... Maintain an efficient and secure IT computing infrastructure on the bank's environment...  ...artifacts for internal and external audits. Serve as the bank's designee for regulatory... 
    Work at office

    City First Bank

    Washington DC
    6 days ago
  • Dexian Government Solutions is recruiting for a Senior Information Systems Security Officer to support our proposal effort for the DHS CIETS in DC Metro area.Position Overview:Serves as DHS I&A's senior offensive security and technical assessment specialist. This position...

    LinTech Global

    Washington DC
    1 day ago
  • $120k - $170k

     ...need for an Information System Security Officer (ISSO) to provide IT professional support for Information System Security Officer (...  ...and unclassified networks in accordance with the DOJ/NIST Risk Management Framework (RMF). Develop and update artifacts for all control... 
    Immediate start
    Worldwide

    Credence company

    Arlington, VA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to IT Audit Manager. Be the first to apply!