IT Audit Manager
$125.05kMetropolitan Transportation Authority
Hours of Work 9:00 am - 5:30 pm (7.5 hours/day) or as required. Description Job Title: Audit (IT) Manager Dept/Div: Audit Services Supervisor: Assistant Auditor General Work Location: 2 Broadway, New York, NY 10004 Full/Part-Time: Full Salary: $125,053 Deadline: Until filled Position eligible for telework – one day per week. New hires may apply 30 days after effective date of hire. The Metropolitan Transportation Authority (MTA) is North America's largest transportation network, serving a population of 15.3 million people in the New York City area and surrounding regions. The MTA network includes the nation’s largest bus fleet and more subway and commuter rail cars than all other U.S. transit systems combined. MTA strives to provide a safe and reliable commute, excellent customer service, and rewarding opportunities. Job Summary Lead risk‑based IT audits, plan and execute audits covering general controls, application controls, cybersecurity, cloud (IaaS/PaaS/SaaS), identity and access management, network and endpoint security, databases, and data governance. Assist and support the Director/Assistant Auditor General in performing duties and act on the Director’s behalf in the Director’s absence. Coach and develop audit staff as required. Responsibilities Lead risk‑based IT audits: develop plans, execute audits, and manage delivery of findings. Audit Planning & Scoping: develop risk‑based engagement‑level audit plans, define objectives and scope, perform preliminary risk assessments, and establish detailed testing programs. Control Testing & Analytics: design and perform control tests using appropriate sampling and data analytics (ACL, IDEA, SQL, Python) to increase coverage, depth, and efficiency. Frameworks & Compliance: assess control maturity against NIST, COBIT, ISO 27001, ITIL, and relevant regulatory requirements. Cloud & ERP Focus: evaluate controls in major systems (AWS/Azure, enterprise applications/ERPs) including change management, configuration, interfaces, and data integrity. Cyber & Third‑Party Risk: perform audits of cybersecurity controls, incident response, vulnerability/patch management, and third‑party/vendor risk. Issue Management: identify root causes, quantify impact, recommend remediation, track action plans, and timely closure; escalates risks appropriately. Reporting & Communication: draft clear and concise audit reports; present findings to IT, business leaders, senior management, and board‑level committees. Stakeholder Engagement: build collaborative relationships with key stakeholders from IT, Legal, and other agency leadership; translate complex technical issues into business terms. Quality & Standards: ensure audits comply with the IIA’s IPPF and internal methodologies; contribute to methodology updates and audit tool optimization. Team Leadership: supervise auditors; provide coaching, on‑the‑job training, performance feedback, and foster continuous improvement. Continuous Auditing/Monitoring: implement continuous auditing and data‑driven risk indicators to proactively detect anomalies. Other duties as assigned. Compliance with policies and standards. Work outside regular hours as required. Observe contractors’ work, review invoices, and address contractor performance issues where applicable. Escalate issues to other parties when needed. Required Knowledge/Skills/Abilities Demonstrated ability to work with all levels of the organization. Excellent analytical and business judgment skills. Proven ability to manage multiple projects simultaneously in a fast‑paced environment. Understanding of professional audit practices, including audit program and workpaper development. Excellent communication and interpersonal skills. Required Education and Experience Bachelor’s Degree in Arts/Sciences (BA/BS) Accounting, Business Administration, Computer Science, Information Technology, or a related field; an equivalent combination of education and experience may be considered in lieu of a degree. Minimum 8 years of satisfactory full‑time experience conducting IT audits in internal audit, public accounting/consulting, or a similar role within a complex organization. Preferred Strong knowledge of IT general controls, application controls, cybersecurity practices, and industry frameworks (NIST, COBIT, ISO 27001, ITIL). Minimum 1 year of prior information technology or computer systems experience. Minimum 1 year of supervisory/lead experience managing audit projects and mentoring staff. CIA, CISA, or CPA, and supervisory/lead experience within 1 year. Other Information May need to work outside normal hours (evenings and weekends). Travel may be required to other MTA locations or external sites. Annual Statement of Financial Disclosure (FDS) filing required for employees in policymaking positions per NYS law. Equal Employment Opportunity MTA and its subsidiary and affiliated agencies are Equal Opportunity Employers, including those concerning veteran status and individuals with disabilities. MTA encourages qualified applicants from diverse backgrounds, experiences, and abilities, including military service members. #J-18808-Ljbffr
- ...Nordic is seeking an Audit Program Director to lead and actively execute the organization’s internal and external audit program across IT and related business functions. This hands-on role manages the full audit lifecycle—from planning to remediation tracking and evidence...Suggested
$300k - $350k
...personal data. Instead of accepting the status quo, we decided to fix it. National security professionals, journalists, parents, and... ...business terms and making tradeoffs with speed of execution. Vet and manage relationships with external security vendors, auditors, and...SuggestedOdd jobFull timeWork at officeImmediate startRelocation package$125k - $150k
...and Information Services is seeking to hire a Computer Systems Manager Non-Manager to serve as the Chief Information Security Officer (... ...documented - Produce documentation when / where needed. - Ensure all IT systems are equipped and updated with necessary cyber protection...SuggestedPermanent employmentFull timeWork at officeShift workWeekend workAfternoon shift- ...ticking every experience box. What you'll be doing Leading on audit defence, risk assessments, and technical architecture reviews... ..., risk register, regulatory engagement, and reporting. Manage the US GRC lead directly, and work closely with the US SecOps team...Suggested
$300k - $375k
...Architecture. You will take charge of strategy, improve processes, manage budgets, and build out teams to support ambitious growth goals.... ...GRC and Blue Team) Engage with industry forums, prepare audit and compliance reports, and present to company leadership Drive...SuggestedFull timeWork at officeWorldwide$350k - $400k
...the company's foremost authority on information security, risk management, and compliance. This leader will partner across Engineering, Product... ...ensure ongoing CPRA compliance, with direct accountability to audit and regulatory requirements Build and continuously mature a...Flexible hours$350k - $400k
...cybersecurity operations and compliance management. The CISO will play a critical leadership... ...beyond traditional perimeter defense and audit-driven compliance programs. We now face a... ...performance-based culture. Partner with IT, Legal, Risk, HR, and other business...Contract workLocal areaShift work- ...cybersecurity and represent the enterprise in examinations and audits. Oversee internal and external IT compliance efforts and remediation activities.... ...oversight of security operations, vulnerability management, incident response, and crisis management. Lead enterprise...Contract workTemporary work
$120k - $200k
...accreditation artifacts into a structured, auditable repository. - Support audits,... ...systems. - Experience accrediting IT systems against U.S. Government standards... ...- Understanding of configuration management and automation tools (e.g., Puppet, Terraform...Full timeFlexible hours- ...and market trends. Mentor internal teams and contribute to the evolution of the global Field CISO program. Work with product managers, business, and other teams at Check Point. Qualifications * 10+ years of experience in cybersecurity, including leadership or...
- ...operating within public company environments and an understanding of the complexities of cybersecurity governance, enterprise risk management, audit readiness, and SEC disclosure expectations. Experience preparing organizations for IPO readiness and scaling security...Full timeWork at officeLocal areaRemote workHome office
$65k - $150k
...provide Strategy Coordination, CISO Projects Management, Training & Culture, Metrics & Reporting,... ...TISR issues include those arising from Audit and Regulatory exams, ITRM deep dives,... ...implementation. Prepare response evidence for IT/IS related regulatory exams. Recommend...Work experience placement$350k - $400k
...cybersecurity incident response and crisis management program. Act as primary technical contact... ...all security team members. Partner with IT, Legal, Risk, HR, and other business... ...financial, and reputational risk. Regulatory & Audit Compliance Responsibilities Lead the...Full timeContract work- ...cybersecurity program and Operational Risk Management practices This role will drive security... ...party relationships Regulatory Compliance & Audit: Ensure compliance with financial... ...Collaboration: Partner with executive leadership, IT teams, and external stakeholders to align...Work at officeFlexible hours
$147.5k - $211k
...execution oversight for Enterprise Vulnerability Management across infrastructure, cloud, endpoints,... ...Orchestration & Integration with IT Operations Align vulnerability remediation... ...organization, Risk, and regulators/internal audit as needed. Translate technical risk into...3 days per week- ...Pfizer is seeking a CISO Communications Manager to develop and execute a strategic communications program that tells the CISO story to external clients and internal stakeholders. You will partner with the Senior Manager and CISO leadership to craft messaging across presentations...
- ...involved in real estate transactions. The CISO will be responsible for designing and implementing a comprehensive security and risk management program, leading critical security domains, and ensuring compliance with regulatory requirements. A key aspect of the role is to...Local area
- ...thoughtful, responsible innovation. And through it all, we lead with purpose, love, and... ...where you inherit a legacy infrastructure, manage a large team, and maintain the status quo.... ...they operate within defined boundaries, audit their own actions, and surface anomalies in...Full timeContract workFor contractorsFor subcontractorWork at officeRemote workDay shift
- ...About the Company Established data management and secure communications firm serving highly... ...'s security strategy, partnering with IT and management to enhance network infrastructure... ...compliance calendar, overseeing security audits, and coordinating responses to security...
- ...Analytics Market Research Specialties market research analysis insights data and analytics customer experience management advisory services and advisory services Business Classifications B2B SAAS About the Role The Company is in...
- ...PwC is seeking a Digital Assurance & Transparency - IT Audit Senior Associate to assess controls and governance across clients' digital environments. You will mentor staff, interpret complex data, and help clients navigate regulatory requirements. The role offers growth...
- ...Withum is seeking an IT SOX Auditor/Consultant to support our SOX practice across diverse industries including technology, manufacturing... ...Requirements include a BA/BS in a related field, 1–2 years ITGC audit/consulting experience at a public accounting firm, and strong...Work at office3 days per week
- ...Our Client, a Large Financial Services institution , is seeking an IT Audit Supervisor/ Manager to join their growing IT Audit team in New York. This position is HYBRID and will 3 days per week in office. Responsibilities Act as Team Lead, overseeing the planning, execution...Work at office3 days per week
- ...Support due diligence, integrations, and audits Build a roadmap that will improve cyber maturity... ...in plain business terms. Risk Management & Compliance Identify, assess, and prioritize... ...‑prem environments. Partner closely with IT and operations teams to embed security...Temporary workWork experience placement
$250k - $275k
...Operations Center). The CISO will collaborate with senior IT and business leaders to drive a proactive, risk-based... ...in risk treatment planning. Engage with internal audit, legal, and compliance teams to manage regulatory obligations and audit readiness. Promote accountability...Immediate startFlexible hours- ...Senior IT Auditor The Senior IT Auditor is responsible for assessing and evaluating... ...auditors to support a strong risk management and control environment. Responsibilities... ...scoping and risk assessment analysis of SOX audit planning. Leads SOX end-to-end walk-throughs...
$70k - $90k
...practice has created an opportunity for an IT SOX Auditor/Consultant to work with our... ...controls to support ongoing SOX consulting and audit engagements for a diverse client base... ...Controls including Access, Change Management, Computer Operations, etc. Obtaining, analyzing...Work at officeLocal area$200k - $250k
...governance framework, including policies, standards, and risk management processes Partner closely with Engineering, Infrastructure, Product... ...into technical and business workflows Lead and manage external audits, certifications, and assessments, acting as the primary point...Work at officeWork from homeFlexible hours$165k - $210k
...performance marketing. The Opportunity We're hiring a Director, IT & Security to own internal technology end-to-end: the systems,... ...cleanly everywhere, from the SaaS stack to our proprietary platform. Managing it well is table stakes. The real mandate is a point of view on...Work at officeShift work$300k - $375k
...Engineering & Architecture. You will drive strategy, improve processes, manage budgets, and build and mentor teams to support ambitious growth.... ...in GRC and Blue Team Engage with industry forums, prepare audit and compliance reports, and present to company leadership Drive...Visa sponsorship
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Audit Manager. Be the first to apply!
- IT professional services engineer New York, NY
- IT infrastructure New York, NY
- IT account executive New York, NY
- information technology support New York, NY
- IT delivery manager New York, NY
- information technology specialist New York, NY
- entry level IT tech New York, NY
- free IT training and placement New York, NY
- information technology remote New York, NY
- information technology summer intern New York, NY


