Cyber Security and Audit Manager 839483

Capstone Search Advisors

Wallingford, CT

JOB DETAILS
SKILLS
Accounting, Amazon Web Services (AWS), Auditing, CISA - Certified Information Systems Auditor, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Certified Internal Auditor (CIA), Cloud Computing, Computer Science, Computer Security, Consulting, Control Objectives for Information and related Technology (COBIT), Cryptography, Emerging Technology, Endpoint Security, External Audit, Fortune 500 Customers, GCP (Good Clinical Practices), ISO (International Organization for Standardization), Identity Data Management, Incident Response, Information Technology & Information Systems, Information Technology/Systems Audit, Information/Data Security (InfoSec), Internal Audit, Internet Security, Leadership, Manufacturing, Microsoft Windows Azure, Network Security, Organizational Skills, Program Evaluation, Regulations, Reporting Skills, Risk, Risk Analysis, Risk Management, Sarbanes-Oxley Act (SOX), Security Analysis, Security Attacks, Security Auditing, Software Development, Software Patches, Supply Chain, Technical Leadership, Technical Strategy, Writing Skills
LOCATION
Wallingford, CT
POSTED
1 day ago
Global Manufacturing company is seeking a Senior Cyber Security and Audit Manager. The Senior Manager leads complex cyber security audits, evaluates emerging technology risks, advises management on strategic technology initiatives, and helps strengthen the Company's overall cyber posture while maintaining the independence required of the Internal Audit function. While the role will have familiarity with IT General Controls (ITGCs), its primary focus is evaluating enterprise cybersecurity capabilities, technology risk management, operational resilience, and emerging technology risks.

Key Responsibilities
Cybersecurity & Technology Risk Leadership
? Lead the development and execution of the Company's cybersecurity and
technology risk audit strategy as part of the annual risk-based Internal Audit Plan.
? Serve as the Internal Audit subject matter expert on cybersecurity, technology
risk, and digital transformation.
? Partner with the Vice President of Internal Audit to identify emerging technology
and cybersecurity risks and incorporate them into the annual audit plan.
? Continuously monitor the external cyber threat landscape, evolving regulatory
requirements, and emerging technologies to ensure audit coverage remains
aligned with enterprise risks.
? Coordinate cybersecurity audit activities with external specialists, co-sourced
providers, and external auditors as appropriate.

Cybersecurity Assurance
Lead independent assessments of the design and operating effectiveness of controls across areas including:
? Cybersecurity Governance
? Security Operations (SOC)
? Identity & Access Management (IAM)
? Privileged Access Management (PAM)
? Cloud Security (AWS, Azure, GCP)
? Network and Infrastructure Security
? Endpoint Security
? Vulnerability & Patch Management
? Threat Detection & Incident Response
? Data Protection & Encryption
? Third-Party & Supply Chain Cyber Risk
? Disaster Recovery & Business Continuity
? Operational Technology (OT/ICS), where applicable
? Artificial Intelligence (AI) Governance and Security
? Secure Software Development (DevSecOps)

Qualifications
Education
Bachelors degree in Information Systems, Cybersecurity, Computer Science,
Information Technology, Engineering, Accounting, or another related STEM discipline.
Masters degree preferred.
Professional Certifications
One or more of the following certifications is required:
? Certified Information Systems Auditor (CISA)
? Certified Information Systems Security Professional (CISSP)
? Certified Information Security Manager (CISM)
? Certified in Risk and Information Systems Control (CRISC)
? Certified Internal Auditor (CIA)
Additional certifications such as CCSP, GIAC, CEH, Security+, or cloud security
certifications are preferred.

Experience
? 8-12+ years of progressive experience in cybersecurity, technology risk, cyber
consulting, cyber assurance, or IT audit, with a significant focus on enterprise
cybersecurity.
? Experience within a Fortune 500, Big Four Cyber Risk practice, or leading
cybersecurity consulting firm strongly preferred.
? Demonstrated experience leading complex cybersecurity audits and advisory
engagements across large, global organizations.
? Experience evaluating enterprise cybersecurity programs, cloud security, cyber
resilience, operational resilience, and technology governance.
? Working knowledge of IT General Controls (ITGCs) and SOX requirements, with
the ability to coordinate effectively with audit leaders responsible for ITGC
assurance.
? Deep knowledge of cybersecurity frameworks including NIST CSF, NIST 800-53,
ISO 27001, CIS Controls, COBIT, and applicable cybersecurity and privacy
regulations.
? Experience partnering with Chief Information Security Officers, technology
executives, and business leadership on cybersecurity risk management and
governance.
? Strong executive presence with exceptional communication, presentation,
stakeholder management, and report-writing skills.
? Demonstrated ability to translate complex technical risks into clear business
impacts and actionable recommendations.
? Experience leveraging data analytics, automation, and continuous monitoring to
enhance audit effectiveness.

About the Company

C

Capstone Search Advisors