Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

IT Audit Manager

Full-time

KBR

Title:
IT Audit Manager

KBR is seeking an experienced IT Audit Manager to join the Internal Audit & Advisory team. This role is responsible for leading and overseeing the organization's IT Sarbanes-Oxley (SOX) compliance program, including the planning, execution, and reporting of IT General Controls (ITGC), application controls, automated controls, interface controls, and Software Development Lifecycle (SDLC) control testing. The IT Audit Manager will partner closely with IT leadership, business process owners, internal controls teams, and external auditors to ensure an effective control environment, timely remediation of identified deficiencies, and ongoing compliance with SOX 404 requirements.

The ideal candidate brings strong experience managing IT SOX programs within complex global organizations, demonstrated expertise in IT control frameworks and risk assessment methodologies, and a proven ability to lead and develop audit teams while driving high-quality, risk-based audit execution.

Key Responsibilities
  • Manage the annual IT SOX compliance program, including planning, execution, monitoring, and reporting activities across IT control domains.
  • Develop and maintain risk-based testing strategies and audit plans covering IT General Controls (ITGCs), application controls, automated controls, interface controls, and SDLC controls.
  • Oversee walkthroughs, control assessments, and testing activities to evaluate the design and operating effectiveness of key IT controls.
  • Lead and review testing of ITGCs, including access management, change management, IT operations, and system development controls.
  • Direct testing and evaluation of SDLC controls, including development approvals, testing evidence, release management, and production migration processes.
  • Oversee testing of key automated controls, application controls, system interfaces, and management reports used in financial reporting processes.
  • Manage and mentor onshore and offshore IT audit and SOX testing teams, ensuring consistency, quality, and adherence to established audit methodologies.
  • Review workpapers, testing documentation, and audit evidence to ensure accuracy, completeness, and compliance with professional standards.
  • Partner with IT management, Internal Controls, business process owners, and external auditors to coordinate testing activities, address control issues, and facilitate audit reliance.
  • Evaluate identified control deficiencies, assess potential SOX impact and severity, and provide recommendations for corrective actions.
  • Monitor remediation activities, validate the effectiveness of corrective actions, and track resolution through completion.
  • Prepare and present status reports, executive dashboards, testing summaries, and risk updates to management and key stakeholders.
Basic Qualifications

Education & Experience
  • Bachelor's degree in Information Systems, Information Technology, Computer Science, Accounting, Finance, Audit, or a related field.
  • Minimum of 10 years of progressive experience in IT audit, IT risk management, IT controls, IT compliance, or related disciplines.
  • Minimum of 4 years of experience leading and managing IT SOX compliance programs and audit teams.
  • Experience conducting and overseeing SOX 404 testing within large, complex, and global organizations.
  • Demonstrated experience leading cross-functional initiatives involving IT, Internal Controls, Finance, and external audit stakeholders.
  • Experience managing distributed, onshore, and offshore resources in a testing or audit environment.
Technical & Leadership Skills
  • Deep knowledge of IT General Controls (ITGCs), including access management, change management, IT operations, and system development controls.
  • Strong expertise in SOX 404 compliance requirements, control testing methodologies, and internal control frameworks.
  • Experience evaluating and testing application controls, automated controls, interface controls, and system-generated reports.
  • Strong understanding of Software Development Lifecycle (SDLC) processes and associated control requirements.
  • Proven ability to assess control design and operating effectiveness, identify risks, and evaluate control deficiencies.
  • Strong analytical, problem-solving, and risk assessment skills.
  • Ability to manage multiple priorities, projects, and deadlines in a fast-paced environment.
  • Effective leadership, coaching, and team development capabilities.
  • Excellent verbal and written communication skills with the ability to present complex technical and compliance matters to diverse audiences.
  • Strong stakeholder management and relationship-building skills across business and technology functions.
Preferred Qualifications
  • Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), or equivalent professional certification.
  • Prior experience within a publicly traded organization with mature SOX compliance requirements.
  • Experience supporting external audit reliance strategies and coordinating with external auditors.
  • Knowledge of leading control frameworks and governance standards, including COBIT, NIST, and related IT risk frameworks.
  • Experience supporting digital transformation, ERP implementations, cloud environments, or large-scale technology change initiatives.
  • Advanced experience with data analytics, audit automation, or continuous controls monitoring tools.
Additional Compensation: KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels, per internal policy or contractual designation. Additional compensation may be in the form of sign on bonus, relocation benefits, short term incentives, long term incentives, or discretionary payments for exceptional performance.

Benefits: KBR offers a selection of competitive lifestyle benefits which could include a 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule. We support career advancement through professional training and development.

Belong, Connect and Grow at KBR

At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team's philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver - Together.

KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.
Vacancy posted a month ago
Similar jobs that could be interesting for youBased on the IT Audit Manager in Arlington, VA vacancy
  •  ...Required skillset: Must have 5+ years in IT Audit/IT Risk Management, with SOX and either ICFR or ITGC Big 4 experience, especially from E&Y is a huge plus, but not required AWS technical skills must be familiar with Lambdas, S3 buckets, databases... 
    Suggested

    3B Staffing LLC

    McLean, VA
    5 days ago
  • $45 - $60 per hour

     ...Job Title: Financial/IT Audit Manager (Secret Clearance Needed) Location: Arlington, VA Rate/HR: $45-60/hr Overview: We are seeking a highly qualified IT Audit Manager to join our team in Arlington, VA. The ideal candidate will possess a Master... 
    Suggested
    Remote work
    Work from home
    Flexible hours
    2 days per week
    3 days per week

    She Recruits LLC

    Arlington, VA
    4 days ago
  • $120k - $150k

     ...For more than 40 years, Wil has provided expert accounting, auditing, and consulting services to a growing number of federal, state...  ...contact a recruitment team member.   The Opportunity:   The IT Audit Manager is responsible for leading the planning and execution of... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Immediate start
    Remote work
    Work from home
    Monday to Friday
    Flexible hours
    Weekend work
    Afternoon shift

    Williams Adley

    Washington DC
    a month ago
  •  ...correction or mitigation actions. Develop Plan of Action and Milestones (POAMs) in response to reported security vulnerabilities. Manage the risks to ISs and other FBI assets by coordinating appropriate correction or mitigation actions, and oversee and track the... 
    Suggested
    Work at office

    MANTECH

    Washington DC
    25 minutes ago
  • Technology Audit & Advisory Senior Manager (Tysons Corner - Hybrid)Step into a leadership role with a dynamic and collaborative professional services...  ...and proposal preparation.Areas of Focus:Cybersecurity and IT risk managementIT frameworks and General Controls (ITGC)... 
    Suggested
    Work experience placement
    Local area
    Remote work

    Robert Half

    McLean, VA
    2 days ago
  • $103.8k - $218.1k

     ...environment, collaborating with Lead ISSOs, IT system owners, stakeholders, and...  ...the Intermediate ISSO will execute Risk Management Framework activities for ATO decisions, ensure...  ...technical vulnerability assessments, providing audit support documentation, and responding to... 
    Full time
    Contract work
    Work experience placement
    Work at office
    Flexible hours

    CACI International

    Washington DC
    3 days ago
  •  ...support Federal cybersecurity operations focused on continuous monitoring, RMF execution, authorization maintenance, vulnerability management, audit readiness, and cybersecurity governance. Senior ISSOs serve as cybersecurity subject matter experts supporting assigned... 
    Hourly pay

    Momentum Engineering

    Washington DC
    2 days ago
  • $116.5k

     ...developing and enforcing security policies, conducting regular security audits, and staying up to date with the latest cybersecurity threats...  ...in accordance with Departmental directives and applicable Risk Management Implementation Plans (RMIPs). Verify authenticator... 
    Work experience placement

    MAXIMUS

    Arlington, VA
    4 days ago
  • $70k - $145k

     ...TestPros delivers innovative independent IT assessment solutions to critical challenges...  ...implementation and maintenance of Risk Management Framework (RMF) processes. Develop, review...  ...boards (CCBs) as required. Support audits, inspections, and cybersecurity... 
    Contract work
    For contractors
    Work experience placement
    Interim role
    Immediate start

    TestPros

    Washington DC
    4 days ago
  •  ...• Must display subject matter experience in application security, vulnerability testing, system testing, and/or Agile lifecycle management • Strong LOB knowledge/experience for the type of business they are aligned to (e.g..CSBB/GBM) • 1-2 years of risk management... 
    Work at office
    Flexible hours
    Shift work
    Day shift

    Bank of America

    Washington DC
    3 days ago
  • $120k - $200k

     ...accreditation artifacts into a structured, auditable repository. - Support audits,...  ...systems. - Experience accrediting IT systems against U.S. Government standards...  ...- Understanding of configuration management and automation tools (e.g., Puppet, Terraform... 
    Full time
    Flexible hours

    Contact Government Services, LLC

    Arlington, VA
    3 days ago
  •  ...and requirements to maintain the ATO ~ Experience working with system stakeholders to assess and manage system cybersecurity risk ~ Ability to synthesize complex IT system information and communicate system status and requirements in written products and verbal presentations... 

    Softrams

    Washington DC
    4 days ago
  • $131.6k

     ...and procedures to acquire and maintain an Information System's Authority to Operate (ATO) under the Federal Information Security Management Act (FISMA) of 2002. Lead RMF A&A efforts, including activities within the A&A cycle and outside of the ISSO functions, work directly... 
    Remote work
    1 day per week

    Chenega Corporation

    Arlington, VA
    4 days ago
  • $250k

     ...strategy to protect the firm's clients, information, and reputation. The CISO leads all aspects of cybersecurity, privacy, and risk management in alignment with the firm's strategic objectives and professional obligations. We offer competitive compensation and in... 
    Work at office

    Lewis Brisbois Bisgaard & Smith

    Washington DC
    3 days ago
  •  ...Security Officer (CISO) The CISO is responsible for overseeing and managing the organization's information security program, ensuring the...  ...procedures. Conduct risk assessments and manage security audits. Ensure compliance with relevant laws and regulations.... 

    Beyond SOF

    Washington DC
    2 days ago
  •  ...information security support for NOAA's satellite operations missions. You will help develop and maintain effective security and risk management programs on complex government information systems. As an Information System Security Officer, you will be expected to maintain... 
    Flexible hours

    Tactibit Technologies LLC

    Washington DC
    5 days ago
  • $210k - $235k

     ...mission. Whether it’s architecting critical IT solutions, producing actionable...  ...risks, vulnerabilities, anomalies, patching, auditing, automation, security hardening, best practices...  ...using cyber security and assessment management systems. Understanding of perimeter controls... 

    Bridge Core

    McLean, VA
    2 days ago
  • $120k - $160k

     ...Government. The ISSO will be responsible for managing the security aspects of an information...  ...personnel. Collect, review, and document audit records, including any anomalies....  ...Qualifications Experience with enterprise IT systems is highly desired. Strong understanding... 
    Contract work

    Modern Technology Solutions Inc

    Washington DC
    4 days ago
  •  ...coordinate cybersecurity accreditation efforts, partnering with Project Teams, the Services, Operations & Delivery Teams, and customers to manage requirements, timelines, documentation and compliance. The ideal candidate will have experience with system architecture and design... 

    STEM Solutions

    McLean, VA
    3 days ago
  • $140k - $150k

     ...assurance expertise for a large, complex IT infrastructure program in Washington DC....  ...controls that support the customers’ Risk Management Framework (RMF) and ICD 503 Security Accreditation...  ..., but not limited to the NIST RMF, audit log reviews, system monitoring, SPAA... 
    Full time

    Quantum Sky

    Washington DC
    14 hours ago
  •  ...ensuring compliance with security policies, and managing risk through the implementation of robust...  ...Operations Center (SOC) Analyst, IT Security Manager, Security Risk Analyst,...  ...Perform regular risk assessments and audits Monitor compliance with security policies... 
    Temporary work
    For contractors
    Immediate start
    Flexible hours

    Cymertek

    McLean, VA
    3 days ago
  •  ...passion for building high-quality, scalable, advanced IT solutions in a collaborative, fast-paced, outcome-driven...  ...to protect information systems. • Risk Assessment and Management: They conduct regular security audits, vulnerability assessments, and risk analyses to... 
    Full time

    CGI

    Arlington, VA
    13 hours ago
  • $110.18k - $183.63k

     ...compliance with cybersecurity standards and manages system risk. Ensure assigned systems...  ...(e.g., JCAM). Participate in security audits, assessments, and exercises. Report incidents...  ...of experience in Information Technology (IT) and/or Information Security (IS).... 
    Temporary work
    Flexible hours

    NTT DATA

    Arlington, VA
    3 days ago
  •  ...One Federal Solution provides senior ISSO support for cybersecurity risk management, A&A, FISMA compliance, continuous monitoring, and secure cloud/hybrid environments. We apply NIST, CNSSI 1253, and RMF principles to maintain compliance, strengthen security posture,... 
    Work at office

    One Federal Solution

    Washington DC
    4 days ago
  •  ...Engineer The Senior Cybersecurity Engineer serves as a subject matter expert in ensuring system security compliance and risk management throughout the program life cycle. This role involves driving Authorization to Operate (ATO) efforts, implementing NIST controls,... 
    Full time
    Interim role
    Flexible hours

    MDA Edge

    Washington DC
    4 days ago
  • $120.8k - $265.8k

     ...dynamic environment, collaborating with IT system owners, stakeholders, and cybersecurity...  ...engineering efforts for assigned Program Management Organizations with direct support to the...  ...developing remediation work plans for audit findings. The Senior ISSO will maintain Hardware... 
    Full time
    Contract work
    Work experience placement
    Work at office
    Flexible hours

    CACI International

    Washington DC
    5 days ago
  •  ...Task description and/or any specific requirements: Ability to manage responsibility for security assessments of a variety of...  ...necessary to assure that new and existing information technology (IT) systems meet the organization's information assurance (IA) and security... 
    Permanent employment
    Interim role
    Local area
    Remote work

    PLANIT Group

    Falls Church, VA
    5 days ago
  •  ...will be responsible for implementing and overseeing security policies, managing risk assessments, and ensuring compliance with relevant regulations and standards. You will work closely with other IT teams to identify vulnerabilities, develop security protocols, and monitor... 
    Temporary work
    For contractors
    Immediate start
    Flexible hours

    Cymertek

    McLean, VA
    5 days ago
  • $62k - $141k

     ...requesting customer authorization for company-managed classified endpoints, servers, networks,...  ...system, network, and security appliance auditing, virus scanning, and hardware and...  ...and patch management, including ensuring IT staff pushes patches to all systems, maintaining... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    5 days ago
  • $120k - $160k

     ...This role reports to the Security Program Management Office (SPMO) Manager and works directly...  ...monitoring, POA&M management, risk acceptance, audit responses, and remediation activities to...  ...secure high-end solutions in mission IT, enterprise IT, engineering services, and... 
    Work at office
    3 days per week

    Science Applications International Corporation

    Washington DC
    13 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to IT Audit Manager. Be the first to apply!