Cyber Security and Audit Manager 839483

Capstone Search Advisors

  • Wallingford, CT
  • 30+ days ago

    Highlights

    The Senior Manager leads complex cyber security audits, evaluates emerging technology risks, advises management on strategic technology initiatives, and helps strengthen the Company's overall cyber posture while maintaining the independence required of the Internal Audit function. While the role will have familiarity with IT General Controls (ITGCs), its primary focus is evaluating enterprise cybersecurity capabilities, technology risk management, operational resilience, and emerging technology risks.

    Numbers & Facts

    LocationWallingford, CT

    Description

    Global Manufacturing company is seeking a Senior Cyber Security and Audit Manager. The Senior Manager leads complex cyber security audits, evaluates emerging technology risks, advises management on strategic technology initiatives, and helps strengthen the Company's overall cyber posture while maintaining the independence required of the Internal Audit function. While the role will have familiarity with IT General Controls (ITGCs), its primary focus is evaluating enterprise cybersecurity capabilities, technology risk management, operational resilience, and emerging technology risks.

    Key Responsibilities
    Cybersecurity & Technology Risk Leadership
    ? Lead the development and execution of the Company's cybersecurity and
    technology risk audit strategy as part of the annual risk-based Internal Audit Plan.
    ? Serve as the Internal Audit subject matter expert on cybersecurity, technology
    risk, and digital transformation.
    ? Partner with the Vice President of Internal Audit to identify emerging technology
    and cybersecurity risks and incorporate them into the annual audit plan.
    ? Continuously monitor the external cyber threat landscape, evolving regulatory
    requirements, and emerging technologies to ensure audit coverage remains
    aligned with enterprise risks.
    ? Coordinate cybersecurity audit activities with external specialists, co-sourced
    providers, and external auditors as appropriate.

    Cybersecurity Assurance
    Lead independent assessments of the design and operating effectiveness of controls across areas including:
    ? Cybersecurity Governance
    ? Security Operations (SOC)
    ? Identity & Access Management (IAM)
    ? Privileged Access Management (PAM)
    ? Cloud Security (AWS, Azure, GCP)
    ? Network and Infrastructure Security
    ? Endpoint Security
    ? Vulnerability & Patch Management
    ? Threat Detection & Incident Response
    ? Data Protection & Encryption
    ? Third-Party & Supply Chain Cyber Risk
    ? Disaster Recovery & Business Continuity
    ? Operational Technology (OT/ICS), where applicable
    ? Artificial Intelligence (AI) Governance and Security
    ? Secure Software Development (DevSecOps)

    Qualifications
    Education
    Bachelors degree in Information Systems, Cybersecurity, Computer Science,
    Information Technology, Engineering, Accounting, or another related STEM discipline.
    Masters degree preferred.
    Professional Certifications
    One or more of the following certifications is required:
    ? Certified Information Systems Auditor (CISA)
    ? Certified Information Systems Security Professional (CISSP)
    ? Certified Information Security Manager (CISM)
    ? Certified in Risk and Information Systems Control (CRISC)
    ? Certified Internal Auditor (CIA)
    Additional certifications such as CCSP, GIAC, CEH, Security+, or cloud security
    certifications are preferred.

    Experience
    ? 8-12+ years of progressive experience in cybersecurity, technology risk, cyber
    consulting, cyber assurance, or IT audit, with a significant focus on enterprise
    cybersecurity.
    ? Experience within a Fortune 500, Big Four Cyber Risk practice, or leading
    cybersecurity consulting firm strongly preferred.
    ? Demonstrated experience leading complex cybersecurity audits and advisory
    engagements across large, global organizations.
    ? Experience evaluating enterprise cybersecurity programs, cloud security, cyber
    resilience, operational resilience, and technology governance.
    ? Working knowledge of IT General Controls (ITGCs) and SOX requirements, with
    the ability to coordinate effectively with audit leaders responsible for ITGC
    assurance.
    ? Deep knowledge of cybersecurity frameworks including NIST CSF, NIST 800-53,
    ISO 27001, CIS Controls, COBIT, and applicable cybersecurity and privacy
    regulations.
    ? Experience partnering with Chief Information Security Officers, technology
    executives, and business leadership on cybersecurity risk management and
    governance.
    ? Strong executive presence with exceptional communication, presentation,
    stakeholder management, and report-writing skills.
    ? Demonstrated ability to translate complex technical risks into clear business
    impacts and actionable recommendations.
    ? Experience leveraging data analytics, automation, and continuous monitoring to
    enhance audit effectiveness.

    Similar Jobs

    See more jobs