Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

IT Audit Manager

KBR Inc

Title:

IT Audit Manager

KBR is seeking an experienced IT Audit Manager to join the Internal Audit & Advisory team. This role is responsible for leading and overseeing the organization's IT Sarbanes-Oxley (SOX) compliance program, including the planning, execution, and reporting of IT General Controls (ITGC), application controls, automated controls, interface controls, and Software Development Lifecycle (SDLC) control testing. The IT Audit Manager will partner closely with IT leadership, business process owners, internal controls teams, and external auditors to ensure an effective control environment, timely remediation of identified deficiencies, and ongoing compliance with SOX 404 requirements.

The ideal candidate brings strong experience managing IT SOX programs within complex global organizations, demonstrated expertise in IT control frameworks and risk assessment methodologies, and a proven ability to lead and develop audit teams while driving high-quality, risk-based audit execution.

Key Responsibilities

  • Manage the annual IT SOX compliance program, including planning, execution, monitoring, and reporting activities across IT control domains.

  • Develop and maintain risk-based testing strategies and audit plans covering IT General Controls (ITGCs), application controls, automated controls, interface controls, and SDLC controls.

  • Oversee walkthroughs, control assessments, and testing activities to evaluate the design and operating effectiveness of key IT controls.

  • Lead and review testing of ITGCs, including access management, change management, IT operations, and system development controls.

  • Direct testing and evaluation of SDLC controls, including development approvals, testing evidence, release management, and production migration processes.

  • Oversee testing of key automated controls, application controls, system interfaces, and management reports used in financial reporting processes.

  • Manage and mentor onshore and offshore IT audit and SOX testing teams, ensuring consistency, quality, and adherence to established audit methodologies.

  • Review workpapers, testing documentation, and audit evidence to ensure accuracy, completeness, and compliance with professional standards.

  • Partner with IT management, Internal Controls, business process owners, and external auditors to coordinate testing activities, address control issues, and facilitate audit reliance.

  • Evaluate identified control deficiencies, assess potential SOX impact and severity, and provide recommendations for corrective actions.

  • Monitor remediation activities, validate the effectiveness of corrective actions, and track resolution through completion.

  • Prepare and present status reports, executive dashboards, testing summaries, and risk updates to management and key stakeholders.

Basic Qualifications

Education & Experience

  • Bachelor's degree in Information Systems, Information Technology, Computer Science, Accounting, Finance, Audit, or a related field.

  • Minimum of 10 years of progressive experience in IT audit, IT risk management, IT controls, IT compliance, or related disciplines.

  • Minimum of 4 years of experience leading and managing IT SOX compliance programs and audit teams.

  • Experience conducting and overseeing SOX 404 testing within large, complex, and global organizations.

  • Demonstrated experience leading cross-functional initiatives involving IT, Internal Controls, Finance, and external audit stakeholders.

  • Experience managing distributed, onshore, and offshore resources in a testing or audit environment.

Technical & Leadership Skills

  • Deep knowledge of IT General Controls (ITGCs), including access management, change management, IT operations, and system development controls.

  • Strong expertise in SOX 404 compliance requirements, control testing methodologies, and internal control frameworks.

  • Experience evaluating and testing application controls, automated controls, interface controls, and system-generated reports.

  • Strong understanding of Software Development Lifecycle (SDLC) processes and associated control requirements.

  • Proven ability to assess control design and operating effectiveness, identify risks, and evaluate control deficiencies.

  • Strong analytical, problem-solving, and risk assessment skills.

  • Ability to manage multiple priorities, projects, and deadlines in a fast-paced environment.

  • Effective leadership, coaching, and team development capabilities.

  • Excellent verbal and written communication skills with the ability to present complex technical and compliance matters to diverse audiences.

  • Strong stakeholder management and relationship-building skills across business and technology functions.

Preferred Qualifications

  • Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), or equivalent professional certification.

  • Prior experience within a publicly traded organization with mature SOX compliance requirements.

  • Experience supporting external audit reliance strategies and coordinating with external auditors.

  • Knowledge of leading control frameworks and governance standards, including COBIT, NIST, and related IT risk frameworks.

  • Experience supporting digital transformation, ERP implementations, cloud environments, or large-scale technology change initiatives.

  • Advanced experience with data analytics, audit automation, or continuous controls monitoring tools.

Additional Compensation: KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels, per internal policy or contractual designation. Additional compensation may be in the form of sign on bonus, relocation benefits, short term incentives, long term incentives, or discretionary payments for exceptional performance.

Benefits: KBR offers a selection of competitive lifestyle benefits which could include a 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule. We support career advancement through professional training and development.

Belong, Connect and Grow at KBRAt KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team's philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver - Together.

KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the IT Audit Manager in Washington DC vacancy
  • $120k - $150k

     ...For more than 40 years, Wil has provided expert accounting, auditing, and consulting services to a growing number of federal, state...  ...contact a recruitment team member.   The Opportunity:   The IT Audit Manager is responsible for leading the planning and execution of... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Immediate start
    Remote work
    Work from home
    Monday to Friday
    Flexible hours
    Weekend work
    Afternoon shift

    Williams Adley

    Washington DC
    a month ago
  •  ...sprints and provide subject matter expertise regarding financial audit issues in order to assist with the development of requirements, for...  ...(1) Subject matter expertise regarding financial and/or IT audit issues in order to assist with the development of requirements... 
    Suggested

    RightWorks Inc

    Washington DC
    3 days ago
  •  ...all security matters Develop and maintain System Security Plans (SSPs) Conduct security assessments and authorize systems Manage Plans of Action and Milestones (POA&Ms) Coordinate with system owners and stakeholders Oversee continuous monitoring activities... 
    Suggested
    Contract work

    Zantech

    Washington DC
    23 hours ago
  •  ...emergency response deployment Required Experience or Knowledge 5+ years in cybersecurity and information systems security NIST Risk Management Framework implementation Security control assessment and testing Vulnerability analysis and remediation Technical risk... 
    Suggested
    Contract work

    Zantech

    Washington DC
    23 hours ago
  • $160k

     ...expertise and guidance for the security, authorization, vulnerability management, and continuous monitoring activities required to operate and...  ...management, incident management, change management, audit and compliance, and access-control activities. Monitor and support... 
    Suggested
    Contract work
    For contractors
    Work at office
    Local area
    Remote work

    Age-Solutions

    Washington DC
    1 day ago
  •  ...security documentation, supporting Risk Management Framework (RMF) activities, tracking vulnerabilities...  ...reviews. Support cybersecurity audits, inspections, and compliance assessments....  ...assurance, information security, or IT security. Working knowledge of cybersecurity... 
    Full time
    Contract work
    Part time

    Rividium Inc

    Washington DC
    4 days ago
  •  ...Security Officer (ISSO) to provide on-site cybersecurity and Risk Management Framework (RMF) sustainment support in Washington, D.C., for a...  ..., artifact updates, and post-change verification. Track audit, penetration-test, and assessment findings through corrective action... 
    Contract work

    C3EL

    Washington DC
    3 days ago
  • $300k - $350k

     ...ownership of a highly technical, responsive, and ambitious security, IT, and compliance org. Your mandate is to resource, mature, and...  ...business terms and making tradeoffs with speed of execution. Vet and manage relationships with external security vendors, auditors, and... 
    Work at office
    Immediate start
    Relocation package

    Private Tech

    Washington DC
    3 days ago
  • $102k - $127k

     ...support the world's finest law enforcement organization and help the people that keep us safe. In this job you will support OCIO FISMA audit readiness and compliance reviews by identifying gaps, organizing evidence, and driving corrective-action closure. Lead security... 
    Contract work

    ECS Limited

    Washington DC
    3 days ago
  • $135k - $140k

     ...operation of Security Information and Event Management (SIEM) and Network Anomaly Detection and...  .... Maintain an efficient and secure IT computing infrastructure on the bank's environment...  ...artifacts for internal and external audits. Serve as the bank's designee for regulatory... 
    Work at office

    CityFirst Bank

    Washington DC
    4 days ago
  •  ...ensure systems strictly comply with Risk Management Framework (RMF) requirements and federal...  ...Conduct comprehensive security assessments, audits, and vulnerability scans to identify...  ..., SCAP tools, and large-scale enterprise IT programs. Preferred Qualifications:... 
    Work experience placement

    Macpower Digital Assets Edge

    Washington DC
    2 days ago
  • $150k

     .... The Information Systems Security Officer (ISSO) will support and maintain DoD authorization efforts, execute RMF activities, manage security documentation, and collaborate with engineering teams to ensure compliance across cloud-based environments. Information... 
    Remote work

    Piper Companies

    Washington DC
    3 days ago
  •  ...Security Officer serves as the advisor to Census Bureau executive management on all areas of Information Technology Security and is...  ...information security systems including monitoring and evaluating IT investments and infrastructure, and providing accountability for... 
    Full time
    Part time
    Interim role
    Work at office

    US Census Bureau

    Suitland, MD
    2 days ago
  •  ...passion for building high-quality, scalable, advanced IT solutions in a collaborative, fast-paced, outcome-driven...  ...to protect information systems. • Risk Assessment and Management: They conduct regular security audits, vulnerability assessments, and risk analyses to... 
    Full time

    CGI

    Arlington, VA
    4 days ago
  •  ...Chief Information Security Officer The Chief Information Security Officer serves as the advisor to Census Bureau executive management on all areas of Information Technology Security and is responsible for: # Developing and communicating the overall information... 
    Work at office

    US Department of Commerce

    Suitland, MD
    3 days ago
  •  ...in the Department of Homeland Security (DHS), Federal Emergency Management Agency (FEMA), Office of the Chief Information Officer, located...  ...architectural planning and delivery of information technology (IT) services across the enterprise and in support of FEMA program offices... 
    Permanent employment
    Full time
    Part time
    Work at office
    Relocation

    Federal Emergency Management Agency

    Washington DC
    4 days ago
  • $120k - $135k

     ...specializing in providing Cybersecurity, Agile Software Development, Data Management and Analysis, Cloud Engineering and Services, DevSecOps, and...  ...level RMF package evaluations for Navy RDT&E, PIT, and Business IT systems within a strict 5-business-day turnaround window.... 
    Interim role
    Remote work
    Flexible hours
    3 days per week

    Soliel

    Washington DC
    4 days ago
  • $145k - $155k

     ...cybersecurity policies, including ICD 503, DoD Instruction 8510.01 (Risk Management Framework), NIST SP 800-53 and related publications Prepare,...  ...technology solutions. We deliver professional services in IT Design & Installation, Cybersecurity Engineering & Support,... 
    Work at office
    Flexible hours

    Galapagos

    Washington DC
    23 hours ago
  •  ...Authority to Operate (ATO). The role includes following the Risk Management Framework (RMF) process for full test, partial test, continuous...  ...regulations, and industry standards. Experience conducting audits and assessments to verify adherence to security requirements.... 

    Base-2 Solutions

    Washington DC
    23 hours ago
  •  ...evaluation of attack scenarios. Prepares and delivers technical reports and briefings. Has a complete understanding of Risk Management Framework and implements the process on program systems/networks. Performs or reviews technical security assessments of... 

    Base-2 Solutions

    Washington DC
    3 days ago
  •  ...expected to construct and perpetually update bodies of evidence for managed information systems, custom applications, services, and...  ...assessments and coordinating with external entities to facilitate audits. Your day-to-day tasks will involve a high degree of collaboration... 
    Contract work
    Work at office

    ASM Research

    Alexandria, VA
    3 days ago
  •  ...Senior Executive Service Position This position is in the Department of Homeland Security (DHS), Federal Emergency Management Agency (FEMA), Office of the Chief Information Officer, located in Washington, D.C. The Chief Information Security Officer is responsible... 
    Work at office

    US Government Jobs

    Washington DC
    23 hours ago
  • $62k - $141k

     ...The Opportunity: Cyber threats evolve constantly. In this role, you'll turn complex risk into clear action by supporting Risk Management Framework (RMF) activities and driving Assessment and Authorization (A & A) packages through an Authorization to Operate (ATO). You... 
    Full time
    Contract work
    Part time
    Local area
    Remote work

    Booz Allen Hamilton

    Bethesda, MD
    1 day ago
  •  ...background in network security, threat detection, and vulnerability management In-depth knowledge of securing cloud environments (e.g.,...  ...an award-winning company that delivers Information Technology (IT) engineering services and solutions and non-IT subject matter expertise... 
    For contractors
    Fixed term contract
    Worldwide
    Relocation package

    Constellation West

    Washington DC
    2 days ago
  • $120k - $150k

     ...we specialize in the seamless delivery of IT modernization and elite cybersecurity...  ...monitoring duties in alignment with the NIST Risk Management Framework (RMF), Departmental/Treasury...  ...or as required. Ensure that system audit trails are regularly examined and anomalies... 
    Contract work
    For contractors
    Work at office

    APTNEXUS

    Arlington, VA
    4 days ago
  •  ...cybersecurity technical lead responsible for implementing Risk Management Framework (RMF) activities, cloud security engineering, continuous...  ...cloud engineers, developers, and DevSecOps teams. • Support audits and inspections from internal and external organizations. •... 

    Gray Analytics

    Washington DC
    23 hours ago
  • $141.5k - $236k

     ...Explore thrilling projects in Digital Transformation, Cybersecurity, IT, Data Analytics and Software Development. Elevate your career...  ...Professional (CISSP), Certified Information Systems Security Manager - Informatin System Security Management Professional (CISSP-ISSMP... 
    Hourly pay
    Contract work
    Temporary work
    Work experience placement
    Work at office
    Local area
    Remote work

    ManTech International Corporation

    Washington DC
    23 hours ago
  •  ...support, authorization support, continuous monitoring, vulnerability management, incident response coordination, and system security oversight...  ...Monthly security reporting Security metrics reporting Audit artifact development Lead incident response activities.... 
    Fixed term contract
    Work at office

    Strategic Operational Solutions

    Washington DC
    1 day ago
  •  ...and procedures are established and followed. Assists with the management of security aspects of the information system and performs day-...  ...enclave's information assurance program Plan and coordinate the IT security programs and policies Manage and control changes to... 
    Local area

    BTS Software Solutions

    Laurel, MD
    1 day ago
  •  ...: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt The...  ...operation of complex, multi-enclave IT and Research & Development (R&D) systems....  ...ConMon strategies. Review ACAS dashboards, audit logs (e.g., Splunk, Elastic), and system... 
    Full time
    Work at office
    Local area
    Flexible hours

    Apavo Corporation

    Washington DC
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to IT Audit Manager. Be the first to apply!