Manager, IT Auditor
$99.5k - $119.5kBain & Company
General Information Job Title Manager, IT Auditor Job ID 110041 Work Areas Finance Employment Type Permanent Full-Time Location(s) Atlanta, Boston, Dallas Description & Requirements WHAT MAKES US A GREAT PLACE TO WORK We are proud to be consistently recognized as one of the world’s best places to work, a champion of diversity and a model of social responsibility. Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally. WHERE YOU’LL FIT WITHIN THE TEAM As a Manager, IT Auditor, you will hold a senior individual contributor role within the Internal Audit function, operating as part of the organization’s third line of defense. In this role, you will work closely with Global Internal Audit leadership, which reports directly into the Chief Risk Officer and the Board Risk Subcommittee. Your work will focus on providing independent assurance over the design and operating effectiveness of the organization’s technology processes and controls through risk-based audit engagements, delivering insights that help management strengthen technology processes, controls, and risk management practices. Perform and lead assigned IT audit engagements across technology risk areas such as cybersecurity, cloud environments, AI and generative AI, third-party risk, data governance, and IT operations. You will lead end-to-end audit engagements on a continuous or risk-based cycle throughout the year, bringing strong IT audit knowledge and a risk-based perspective to each engagement. The role carries no direct reports to start; you will coach team members on engagements, with the opportunity to take on formal supervisory responsibility as the function grows. WHAT YOU’LL DO Audit Planning & Execution Lead assigned IT audit engagements within the approved annual audit plan, developing risk-based audit procedures and testing approaches consistent with established audit methodology and risk priorities. Assess the governance and controls around AI and generative AI tools (e.g., Claude, ChatGPT, Copilot), acceptable use, data privacy, model and vendor due diligence, human-in-the-loop review, and output validation. Design audit programs, end-to-end process walkthroughs, test procedures, and sampling strategies tailored to the risk profile of each engagement. Test core IT general controls, covering logical access and periodic user access reviews, change and configuration management, IT operations and job scheduling, and backup and recovery. Test cybersecurity controls, covering vulnerability and patch management, security monitoring and threat detection, identity and access security, and incident response readiness. Audit data governance and oversight, including data ownership and stewardship, classification and retention, data quality controls, traceability and access rights, and the effectiveness of governance forums in exercising oversight over data use. Identify process gaps and control design weaknesses and recommend sustainable, repeatable control improvements to process owners. Review the software development lifecycle, including design approval, secure coding, testing and UAT, release management, segregation of duties, and post-implementation review.Governance & Stakeholder Engagement Present audit findings, recommendations, and status updates to senior internal management. Provide guidance to stakeholders on IT audit findings, control effectiveness, and identified technology risks. Collaborate with the first and second lines of defense to understand and support alignment on established control objectives and risk tolerances. Recommend improvements to key controls in collaboration with process and control owners, identify opportunities to reduce duplicative or low-value controls and recommend appropriate improvements, and identify opportunities to improve continuous control monitoring and automated testing. Coordinate with external certification bodies, assessors, and third-parties in support of external certification and attestation programs (e.g., CMMC, ISO 27001, SOC 1/SOC 2), including readiness assessments, evidence requests, and findings follow-up.Reporting & Issue Management Produce high-quality internal audit reports with clear, risk-rated findings and actionable recommendations. Perform root-cause analysis on control failures, distinguishing design gaps from execution breakdowns so remediation addresses the underlying process rather than the symptom. Monitor remediation progress, assess management action plans, validate completion of agreed actions, and report status to relevant stakeholders. Maintain audit documentation in accordance with IIA Standards and internal quality assurance requirements.Collaboration & Development Coach and support team members during assigned audit engagements and provide feedback to promote consistent application of audit methodology. Peer review workpapers and support consistent application of established audit methodology across assigned engagements. Contribute to enhancements to IT audit tools, analytics, and audit practices, including appropriate use of AI-enabled automation to support audit planning, testing, and reporting.ABOUT YOU Required Knowledge, Skills & Abilities Deep understanding of IT risk, control frameworks, and audit methodology (IIA Standards, COSO, COBIT, NIST Cybersecurity Framework). Strong knowledge of IT general controls and IT audit methodology, with working knowledge of cybersecurity, cloud risk, vendor management, and related technology risk areas sufficient to assess controls against established frameworks. Practical experience auditing data governance and oversight frameworks, including data ownership, classification and retention, data quality, and data traceability. Working knowledge of application development lifecycle and change management controls across waterfall, agile, and DevOps delivery models. Familiarity with AI risk and governance frameworks (NIST AI RMF, ISO/IEC 42001, EU AI Act) as applied to enterprise AI deployments. Experience supporting external certification and attestation engagements (e.g., CMMC, ISO 27001, SOC 1/SOC 2), including interfacing directly with certification bodies, assessors, or third-parties. Proficiency with analytics tools (SQL, Power BI, ACL/Galvanize) and AI assistants such as Claude or ChatGPT to support continuous auditing and automation. Able to convey complex technical risk, in writing and verbally, to non-technical audiences and manage stakeholders at all levels. Able to coach colleagues and peer review workpapers, holding engagements to a consistent methodology and quality standard. High degree of professional scepticism, integrity, and objectivity.Experience & Qualifications Bachelor’s degree in Information Technology, Computer Science, Accounting Information Systems, or a related field; advanced degree preferred. 6–9 years of progressive experience in IT audit, cybersecurity, or IT risk management, including 2–3 years leading audit engagements end to end. Prior experience in a Big 4, consulting firm, or regulated industry is a strong asset. Certifications CISA – Certified Information Systems Auditor ISO 27001 Lead Auditor Additional Credentials Valued CRISC – Certified in Risk & Information Systems Control Cloud or cyber risk credentials (e.g., CCSP, Security+) AI governance credentials (e.g., IAPP AIGP, ISO/IEC 42001 Lead Auditor)US COMPENSATION INFORMATIONCompensation for this role includes base salary, annual discretionary performance bonus, 401(k) plan with an annual employer contribution based on years of service and Bain’s best in class benefits package (details listed below).Some local governments in the United States require a good-faith, reasonable salary range to be included in job postings for open roles. The estimated annualized compensation for this role is as follows:In Georgia, the good-faith, reasonable annualized full-time salary range for this role is between $99,500 and $119,500.In Massachusetts, the good-faith, reasonable annualized full-time salary range for this role is between $114,500 and $137,500.In Texas, the good-faith, reasonable annualized full-time salary range for this role is between $104,500 and $125,500.Placement within this range will vary based on several factors including, but not limited to experience, education, licensure/certifications, training and skill level.Annual discretionary performance bonusThis role may also be eligible for other elements of discretionary compensation4.5% 401(k) company contribution, which increases after 3 years of service and is 100% vested upon start dateBain & Company's comprehensive benefits and wellness program is designed to help employees achieve personal independence, protection and stability in the areas most important to you and your family.Bain pays 100% individual employee premiums for medical, dental and vision programs, offering one of the most comprehensive medical plans for employees without impacting your paycheckGenerous paid time off, including parental leave, sick leave and paid holidaysFully vested 401(k) company contributionPaid Life and Long-Term Disability insuranceWORKING MODEL / TRAVELThis role follows a hybrid model, requiring in-office presence at least one day per week.It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability. Go back
- The IT Internal Audit Contractor will work closely with Internal Audit management and will use IT audit knowledge and experience to contribute to a variety of concurrent audits, including risk-based assessments and compliance, regulatory and Sarbanes-Oxley reviews. Under...SuggestedFor contractors
$245k - $325k
...cybersecurity architecture, engineering, operations, governance, risk management, and compliance. This leader will build scalable, risk-based... ...recovery, and cyber resilience planning in partnership with IT and business stakeholders Governance, Risk & Compliance Lead...SuggestedContract workFor contractors$44.14 - $109.51 per hour
...team to align services with patient goals and preferences, while maintaining accurate documentation and using data to support panel management and performance improvement. The role requires strong communication, organizational, and advocacy skills to support vulnerable...SuggestedFull timeInternshipShift work- Boston Children’s Hospital seeks an RN Case Manager to coordinate comprehensive pediatric care across inpatient and outpatient settings. In this role, you will conduct clinical assessments, develop and manage care plans, support discharge planning, and connect families...Suggested
$81.15k - $83.57k
...Description Job Description Description The Information Technology Manager & Information Security Officer is a hybrid leadership and hands... ...to workforce development programs. Key Responsibilities IT Operations & Service Delivery Oversee day-to-day IT...SuggestedLocal areaRemote work$86.8k - $165.2k
...DoWork closely and effectively with the Information System Security Manager (ISSM)/ Information System Security Engineer (ISSE) and system... ..., and approvals process.Technically competent pool of Cyber/IT team who are willing to mentor, listen, and help you refine your...Temporary workWork experience placementWork at officeImmediate startRemote workRelocation packageFlexible hours$82.3k - $220k
...monitoring and authorization efforts of multiple classified information systems under the direction of the Information System Security Manager (ISSM). Performing a variety of technical, and non-technical Cyber Security functions. Responsibilities also include physical and...Full timeLocal area$225k
...perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and... ...CISO holds direct authority to define and approve the federal IT security boundary, manage enterprise risk, and escalate...For subcontractorWork at officeLocal area$99.8k - $131k
...Information Technology Auditor Corporate Audit Team Full Time Springfield,... ...and information technology/business area management while championing compliance with standards... ...led audit plan and review of enterprise IT audit projects that includes AI, Cybersecurity...Full timeWork experience placementWorldwide$243k - $365k
...relationships with Engineering, Product, Clinical, Regulatory and Quality, IT, Legal, Finance, and Commercial teams. Take on an external-... ...Minimum Qualifications ~8 years of progressive management experience in security engineering and/or information security organizations...Full timeWork experience placement- ...Position Summary: The Manager, Sterile Processing, will be responsible for managing the 24/7 operations of the Sterile Processing Department. They will monitor inventory and utilization levels to ensure adequate availability of patient care and treatment materials...All shiftsFlexible hoursShift work
- the client seeks an accomplished, strategic, and forward-looking leader to serve as its inaugural Chief Information Security Officer (CISO). In this role, you will define and advance a comprehensive, institute-wide information security strategy to safeguard the organization...
- ...Job Description Summary Under the general supervision of the Case Management Manager acts as a patient advocate/Case Manager to SSH&EC... ...processes, and data analysis. Knowledge of utilization management as it relates to third party payers Knowledge of post-acute care community...Daily paid16 hoursWork experience placementSummer holidayShift workNight shiftWeekend work
$129.6k - $144k
...Primary Purpose of Position This position provides first-level supervision (FLS) of the Operations Technicians. The Shift Manager proactively ensures environmental compliance with federal, state and local agencies and is responsible for the full development and...Full timeLocal areaShift work$120k - $180k
...the enterprise, deliver timely and personalized engagement, and orchestrate seamless, end-to-end experiences as One Jazz. The Manager, Customer Analytics & Insights, plays a key role in delivering data-driven insights that support franchise strategy, performance...Remote workWorldwideFlexible hours- ...Position Title: Project Manager Location: Boston, Massachusetts, United States Department: Project Manager Description: H&H is offering a unique opportunity for a Project Manager to join and manage projects for our Massachusetts' clients. We are looking...Work at officeLocal area
$109.2k - $174.6k
The Role:The Manager, Site Engagement and Feasibility leads the execution of feasibility and site engagement strategies for assigned studies. This role works cross-functionally to ensure timely and informed site selection, startup planning, and site communication. The Manager...Permanent employmentFull timeWork experience placementWork from home$135k - $155k
...easier for everyone to experience the world.KAYAK for Business (K4B) is KAYAK's corporate travel platform — built to help companies manage business travel through a modern online booking experience, AI-powered features, and a connected network of travel management...Work at officeFlexible hours- Job SummaryThe Front-End Manager is responsible for overseeing all front-end operations, including cash handling, customer service, and team performance. This role ensures accurate transaction processing, adherence to company standards, and efficient execution of front-...
- ...and game changing solutions in our inclusive culture that values diversity of ideas, experiences and backgrounds.You are a confident Manager who spots and stays ahead of the SAP platform , industry and Finance trends and knows how to translate client goals into clear and...Full timeWork experience placementLive inWork at officeLocal area
$124k - $280k
...identify vulnerabilities, develop secure systems, and provide proactive solutions to safeguard sensitive data.In identity and access management at PwC, you will focus on confirming secure and efficient access to systems and data for employees and/or clients. Your work will...Full timeH1b$175.3k - $322.9k
Position Summary ServiceNow Senior Manager Our Deloitte Cyber team understands the unique challenges and opportunities businesses... ...solution designs and architect, including but not limited to:IT Operations Management (ITOM)IT Asset Management (ITAM)Integrated...Local area$99k - $232k
...ApplicableSpecialismCybersecurity & PrivacyManagement LevelManagerJob Description & SummaryThe OpportunityAs a Microsoft Entra ID Identity and Access Management Manager you will lead client support work focused on secure access strategy, identity governance, and the design and...Full timeH1b$150k - $170k
IT accelerates the success of IDEXX employees and customers by providing scalable and innovative solutions and leadership. We are a... ...alignment and cross-functional communication.We are seeking a Senior Manager of DevOps to lead DevOps engineers supporting IDEXX’s Veterinary...Local areaWorldwideFlexible hours$141.2k - $278.3k
...Recruiting for this role ends on 11/1/2026. Work you'll do As a Manager, Functional Transformation on the Moveworks team, you will be responsible... ...experience solutions that help clients transform their HR and IT service delivery practices. We drive significant cost savings,...Local areaVisa sponsorship- ...architecture. Additionally, you have the communication and people skills to inspire teams to bring their A-game.The Work:As an SAP Basis Manager on SAP transformation projects, you will:Lead Basis workstream delivery across S/4HANA Greenfield, Brownfield conversion, BTP...Full timeWork experience placementLive inWork at officeLocal area
$146.62k - $179.2k
...motivated for change. Just imagine the possibilities of what we can do together. How You Will Achieve More:We are seeking a Senior Manager of Contracts to join our Legal team. This individual will serve as a key operational and strategic partner for contract drafting, negotiation...Full timeContract work$100k - $160k
...you’re ready to shape the future of fabrication, come build it with us.Your Impact: We are seeking a highly skilled and motivated Manager, Google Ads who will play a crucial role in driving our global paid acquisition strategies. You are a hands-on performance marketer...Work at officeWorldwideFlexible hours$113.15k - $270.02k
...our culture because it is an investment in our people, our future, and what we stand for as a firm.KPMG is currently seeking a Tax Manager or Senior Manager to join our State and Local Tax (SALT) practice. Responsibilities:Participate in multi-state alternative investment...Local areaRemote work$107k - $120k
...children or powering the systems and partnerships that make it all possible, at Bright Horizons, you’re the difference.The Senior Manager, HRSC Benefits & Leave Administration, provides strategic leadership and operational oversight for the Benefits and Leave Administration...Full timeTemporary workWork at officeLocal areaRemote workWork from homeWork visaFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Manager, IT Auditor. Be the first to apply!







