NeighborWorks America

Director, Technology Risk Assurance

NeighborWorks America • $140K — $158K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in computer science, cybersecurity, accounting, business administration, or related field; Master's preferred.
  • 8+ years of experience in IT audits, cybersecurity assessments, or information assurance.
  • 5+ years leading technology audit engagements.
  • Experience with cloud environments (AWS, Azure, Google Cloud) is strongly preferred.
  • Certified Information Systems Auditor (CISA) required; additional certifications like CIA, CISSP, or CCSP preferred.

Responsibilities

  • Lead the development of a comprehensive risk-based Technology Risk Assurance program.
  • Collaborate with the Chief Audit Executive to identify and integrate emerging technology risks into audit plans.
  • Evaluate the effectiveness of IT governance, cybersecurity, and technology risk management controls.
  • Assess compliance with standards like NIST, COBIT, and ISO 27001.
  • Provide assurance over AI governance and compliance with emerging AI regulations.
  • Prepare and present audit results and risk assessments to executive leadership.
  • Leverage technology and data analytics to enhance audit efficiency.

Benefits

  • Comprehensive health and wellness programs.
  • Professional development opportunities and training.
  • Flexible work arrangements and potential remote work options.
  • Generous paid time off and holiday schedule.
  • Retirement savings plan with company match.
Full Job Description
Work at a Glance: Strategic advisor on technology, cybersecurity, AI, and regulatory risk.

Position Summary:

Reporting to the Chief Audit Executive, the Director Technology Risk Assurance leads the organization's technology risk assurance activities, including the identification and assessment of technology risk, cybersecurity, cloud, data governance, AI governance, and information assurance audit activities. The Director develops and executes a risk-based technology audit strategy and multi-year technology risk assurance roadmap that provides independent assurance regarding the effectiveness of governance, risk management, and internal controls across the organization's technology environment.

The position serves as the primary subject matter expert for technology-related risks and provides strategic guidance to the Chief Audit Executive regarding cybersecurity, cloud computing, infrastructure, application controls, emerging technologies, artificial intelligence, and regulatory compliance. The Director leverages data analytics, continuous auditing techniques, and where feasible AI-enabled audit tools to improve audit efficiency and effectiveness while ensuring alignment with professional standards and leading frameworks including NIST, COBIT, COSO, AI governance frameworks, and IIA standards.

Essential Duties/Responsibilities:
• Lead the development and execution of a comprehensive risk-based Technology Risk Assurance program, including cybersecurity, cloud, data governance, artificial intelligence, and IT governance audits.
• Collaborate with the Chief Audit Executive to identify emerging technology risks and incorporate them into annual and strategic audit plans. Develop recommendations regarding long-term technology risk assurance priorities and audit coverage.
• Evaluate the effectiveness of IT governance, cybersecurity, privacy, resilience, disaster recovery, cloud security, identity management, and technology risk management controls.
• Assess compliance with applicable standards and frameworks including NIST, COBIT, COSO, ISO 27001, CIS Controls, and industry best practices.
• Provide assurance over AI governance, responsible AI practices, model risk management, and compliance with emerging AI regulations and frameworks.
• Prepare and present technology audit results, emerging risk assessments, and key observations to executive leadership and for the Audit Committee as appropriate.
• Leverage technology, data analytics, automation, and AI tools to enhance audit coverage and efficiency.
• Engage in enterprise-wide technology risk assessments and provide recommendations to strengthen governance, risk management, and internal controls. Partner with business and technology leaders to promote effective risk management practices across the organization.
• Monitor remediation activities and validate management action plans related to technology audit observations (findings).
• Liaise with external auditors and the corporation's information technology and services security as necessary. Lead outsourced and co-sourced technology internal audits. Provide oversight, direction, and performance feedback to external consultants and audit resources assigned to technology assurance projects.
• Provides functional leadership and oversight of co-sourced technology audit resources, external consultants, and project teams. May supervise internal technology audit staff as organizational needs evolve.
• Maintain and enhance technology audit methodologies, templates, quality assurance practices, and use of TeamMate+ audit management software. Stay current on emerging risks, evolving regulations, cybersecurity threats, AI developments, and leading audit practices. Champion the use of data analytics, automation, continuous auditing techniques, and AI-enabled tools to improve audit effectiveness and efficiency.
• Perform other duties as assigned by the Chief Audit Executive.

Nature of Work Contacts:

As part of the audit work activities and internal relationship building, maintains close contacts with the corporate staff, Executive Senior Management, Officers and staff of the Audit Committee Chair, Information and Technology Service, External Auditors, and Third-Party Service Providers.

Fiscal Responsibilities:

Responsible for planning, monitoring, and managing expenditures associated with technology:
• Co-sourcing arrangements
• Specialized consulting engagements
• Technology audit tools and software licenses

Required Minimum Qualifications:

(a) Education: Bachelor's degree in computer science, cyber-security, Accounting, Business Administration, Information Systems Management, or other related fields (Master's degree preferred) and/or equivalent work experience.

(b) Experience:
• Minimum 8 years of progressive experience conducting IT audits, cybersecurity assessments, technology risk reviews, or information assurance engagements.
• Minimum 5 years leading technology audit engagements.
• Experience auditing cloud-based environments (AWS, Azure, Google Cloud) strongly preferred.
• Experience evaluating cybersecurity programs, technology governance, and emerging technology risks.
• Experience presenting audit results to executive management.
• Experience working in or with Internal Audit functions adhering to IIA Standards.

(c) Licenses, Certifications:

Required

Certified Information Systems Auditor (CISA)

Preferred

One or more of the following:
• Certified Internal Auditor (CIA)
• Certified Information Systems Security Professional (CISSP)
• Certified in Risk and Information Systems Control (CRISC)
• Certified Cloud Security Professional (CCSP)
• Certified Information Security Manager (CISM)

(d) Competencies, Knowledge, Skills & Abilities:

Technical Expertise
• Extensive knowledge of:

o NIST Cybersecurity Framework

o COBIT

o COSO Internal Control Framework

o AI Governance Frameworks

o IT General Controls (ITGCs)

o Application Controls

o Identity and Access Management

o Cloud Security

o Cybersecurity Governance

o Data Governance

o Vendor Risk Management

o Business Continuity and Disaster Recovery

Communication
• Exceptional written and verbal communication skills.
• Strong interpersonal and presentation skills, sufficient to build effective internal relationships;
• Ability to translate highly technical issues into business-focused observations and recommendations.

Data Analytics
• Ability to leverage technology to improve audit effectiveness and coverage.

(e) Technology: Microsoft Office Suite, Teammate (Preferred), Data Analytics tools (TM Analytics, SQL or similar) cloud Platforms (Azure, AWS, Google Cloud).

Preferred Qualifications:

A Master's degree in information systems, Cyber security, accounting, business administration, data analytics or related field. Experience conducting Cloud, cybersecurity, AI governance and digital transformation audits. Experience implementing continuous auditing and continuous monitoring programs.

Some knowledge of affordable housing or community development industries is helpful but not required.

Working Conditions:

(a) Travel: Up to 25%

(b) Physical/Sensory Demands: Fast paced professional environment requiring periodic extended hours to meet audit deadlines. Significant computer usage and virtual collaboration.

Salary Range: $140,000-$158,000

The salary offered for the role will be based on a variety of factors, including geographic location, internal equity, and the candidate's qualifications/professional experience.

Special Provisions: None specified.

Requisition Close Date: October 16, 2026, 5 p.m. ET

About NeighborWorks America

NeighborWorks America is a nonprofit organization that provides affordable housing and community development services across the United States. The organization works with a network of more than 240 local organizations to provide a range of services, including homebuyer education, foreclosure prevention, financial coaching, and more. NeighborWorks America also advocates for policies that support affordable housing and community development. The organization was created by Congress in 1978 and is funded by the federal government, private foundations, and other sources.
Learn more about NeighborWorks America
Size
300 employees
Industry

Similar Jobs

More Jobs at NeighborWorks America

More Information Technology Jobs

Find similar Director, Technology Risk Assurance jobs: