Full Job Description
Work at a Glance: Strategic advisor on technology, cybersecurity, AI, and regulatory risk.
Position Summary:
Reporting to the Chief Audit Executive, the Director Technology Risk Assurance leads the organization's technology risk assurance activities, including the identification and assessment of technology risk, cybersecurity, cloud, data governance, AI governance, and information assurance audit activities. The Director develops and executes a risk-based technology audit strategy and multi-year technology risk assurance roadmap that provides independent assurance regarding the effectiveness of governance, risk management, and internal controls across the organization's technology environment.
The position serves as the primary subject matter expert for technology-related risks and provides strategic guidance to the Chief Audit Executive regarding cybersecurity, cloud computing, infrastructure, application controls, emerging technologies, artificial intelligence, and regulatory compliance. The Director leverages data analytics, continuous auditing techniques, and where feasible AI-enabled audit tools to improve audit efficiency and effectiveness while ensuring alignment with professional standards and leading frameworks including NIST, COBIT, COSO, AI governance frameworks, and IIA standards.
Essential Duties/Responsibilities:
• Lead the development and execution of a comprehensive risk-based Technology Risk Assurance program, including cybersecurity, cloud, data governance, artificial intelligence, and IT governance audits.
• Collaborate with the Chief Audit Executive to identify emerging technology risks and incorporate them into annual and strategic audit plans. Develop recommendations regarding long-term technology risk assurance priorities and audit coverage.
• Evaluate the effectiveness of IT governance, cybersecurity, privacy, resilience, disaster recovery, cloud security, identity management, and technology risk management controls.
• Assess compliance with applicable standards and frameworks including NIST, COBIT, COSO, ISO 27001, CIS Controls, and industry best practices.
• Provide assurance over AI governance, responsible AI practices, model risk management, and compliance with emerging AI regulations and frameworks.
• Prepare and present technology audit results, emerging risk assessments, and key observations to executive leadership and for the Audit Committee as appropriate.
• Leverage technology, data analytics, automation, and AI tools to enhance audit coverage and efficiency.
• Engage in enterprise-wide technology risk assessments and provide recommendations to strengthen governance, risk management, and internal controls. Partner with business and technology leaders to promote effective risk management practices across the organization.
• Monitor remediation activities and validate management action plans related to technology audit observations (findings).
• Liaise with external auditors and the corporation's information technology and services security as necessary. Lead outsourced and co-sourced technology internal audits. Provide oversight, direction, and performance feedback to external consultants and audit resources assigned to technology assurance projects.
• Provides functional leadership and oversight of co-sourced technology audit resources, external consultants, and project teams. May supervise internal technology audit staff as organizational needs evolve.
• Maintain and enhance technology audit methodologies, templates, quality assurance practices, and use of TeamMate+ audit management software. Stay current on emerging risks, evolving regulations, cybersecurity threats, AI developments, and leading audit practices. Champion the use of data analytics, automation, continuous auditing techniques, and AI-enabled tools to improve audit effectiveness and efficiency.
• Perform other duties as assigned by the Chief Audit Executive.
Nature of Work Contacts:
As part of the audit work activities and internal relationship building, maintains close contacts with the corporate staff, Executive Senior Management, Officers and staff of the Audit Committee Chair, Information and Technology Service, External Auditors, and Third-Party Service Providers.
Fiscal Responsibilities:
Responsible for planning, monitoring, and managing expenditures associated with technology:
• Co-sourcing arrangements
• Specialized consulting engagements
• Technology audit tools and software licenses
Required Minimum Qualifications:
(a) Education: Bachelor's degree in computer science, cyber-security, Accounting, Business Administration, Information Systems Management, or other related fields (Master's degree preferred) and/or equivalent work experience.
(b) Experience:
• Minimum 8 years of progressive experience conducting IT audits, cybersecurity assessments, technology risk reviews, or information assurance engagements.
• Minimum 5 years leading technology audit engagements.
• Experience auditing cloud-based environments (AWS, Azure, Google Cloud) strongly preferred.
• Experience evaluating cybersecurity programs, technology governance, and emerging technology risks.
• Experience presenting audit results to executive management.
• Experience working in or with Internal Audit functions adhering to IIA Standards.
(c) Licenses, Certifications:
Required
Certified Information Systems Auditor (CISA)
Preferred
One or more of the following:
• Certified Internal Auditor (CIA)
• Certified Information Systems Security Professional (CISSP)
• Certified in Risk and Information Systems Control (CRISC)
• Certified Cloud Security Professional (CCSP)
• Certified Information Security Manager (CISM)
(d) Competencies, Knowledge, Skills & Abilities:
Technical Expertise
• Extensive knowledge of:
o NIST Cybersecurity Framework
o COBIT
o COSO Internal Control Framework
o AI Governance Frameworks
o IT General Controls (ITGCs)
o Application Controls
o Identity and Access Management
o Cloud Security
o Cybersecurity Governance
o Data Governance
o Vendor Risk Management
o Business Continuity and Disaster Recovery
Communication
• Exceptional written and verbal communication skills.
• Strong interpersonal and presentation skills, sufficient to build effective internal relationships;
• Ability to translate highly technical issues into business-focused observations and recommendations.
Data Analytics
• Ability to leverage technology to improve audit effectiveness and coverage.
(e) Technology: Microsoft Office Suite, Teammate (Preferred), Data Analytics tools (TM Analytics, SQL or similar) cloud Platforms (Azure, AWS, Google Cloud).
Preferred Qualifications:
A Master's degree in information systems, Cyber security, accounting, business administration, data analytics or related field. Experience conducting Cloud, cybersecurity, AI governance and digital transformation audits. Experience implementing continuous auditing and continuous monitoring programs.
Some knowledge of affordable housing or community development industries is helpful but not required.
Working Conditions:
(a) Travel: Up to 25%
(b) Physical/Sensory Demands: Fast paced professional environment requiring periodic extended hours to meet audit deadlines. Significant computer usage and virtual collaboration.
Salary Range: $140,000-$158,000
The salary offered for the role will be based on a variety of factors, including geographic location, internal equity, and the candidate's qualifications/professional experience.
Special Provisions: None specified.
Requisition Close Date: October 16, 2026, 5 p.m. ET