Manager, IT Auditor
Bain & Company
- Location
- Atlanta, Boston, Dallas
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 27 approvals (FY2023)
Skills
About this role
Description & Requirements
WHAT MAKES US A GREAT PLACE TO WORK We are proud to be consistently recognized as one of the world’s best places to work, a champion of diversity and a model of social responsibility. Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally. WHERE YOU’LL FIT WITHIN THE TEAM As a Manager, IT Auditor, you will hold a senior individual contributor role within the Internal Audit function, operating as part of the organization’s third line of defense. In this role, you will work closely with Global Internal Audit leadership, which reports directly into the Chief Risk Officer and the Board Risk Subcommittee. Your work will focus on providing independent assurance over the design and operating effectiveness of the organization’s technology processes and controls through risk-based audit engagements, delivering insights that help management strengthen technology processes, controls, and risk management practices. Perform and lead assigned IT audit engagements across technology risk areas such as cybersecurity, cloud environments, AI and generative AI, third-party risk, data governance, and IT operations. You will lead end-to-end audit engagements on a continuous or risk-based cycle throughout the year, bringing strong IT audit knowledge and a risk-based perspective to each engagement. The role carries no direct reports to start; you will coach team members on engagements, with the opportunity to take on formal supervisory responsibility as the function grows. WHAT YOU’LL DO Audit Planning & Execution Lead assigned IT audit engagements within the approved annual audit plan, developing risk-based audit procedures and testing approaches consistent with established audit methodology and risk priorities. Assess the governance and controls around AI and generative AI tools (e.g., Claude, ChatGPT, Copilot), acceptable use, data privacy, model and vendor due diligence, human-in-the-loop review, and output validation. Design audit programs, end-to-end process walkthroughs, test procedures, and sampling strategies tailored to the risk profile of each engagement. Test core IT general controls, covering logical access and periodic user access reviews, change and configuration management, IT operations and job scheduling, and backup and recovery. Test cybersecurity controls, covering vulnerability and patch management, security monitoring and threat detection, identity and access security, and incident response readiness. Audit data governance and oversight, including data ownership and stewardship, classification and retention, data quality controls, traceability and access rights, and the effectiveness of governance forums in exercising oversight over data use. Identify process gaps and control design weaknesses and recommend sustainable, repeatable control improvements to process owners. Review the software development lifecycle, including design approval, secure coding, testing and UAT, release management, segregation of duties, and post-implementation review. Governance & Stakeholder Engagement Present audit findings, recommendations, and status updates to senior internal management. Provide guidance to stakeholders on IT audit findings, control effectiveness, and identified technology risks. Collaborate with the first and second lines of defense to understand and support alignment on established control objectives and risk tolerances. Recommend improvements to key controls in collaboration with process and control owners, identify opportunities to reduce duplicative or low-value controls and recommend appropriate improvements, and identify opportunities to