Ernst & Young

Director - Technology Risk

Ernst & Young$214K — $424K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree or equivalent in a related field.
  • 15+ years of relevant experience in technology risk, internal audit, or risk management.
  • At least 10 years in a leadership role managing a team.
  • Experience in technology-enabled Integrated Risk Management or Governance, Risk and Compliance programs.
  • Relevant certifications (CISSP/CISM/CCSP/CISA) preferred.

Responsibilities

  • Support the Chief Audit Executive in building a technology risk capability.
  • Lead the development of a technology-centric internal audit plan.
  • Conduct internal audits and advisory engagements across various technology risks.
  • Assess and evaluate key technology environments and controls.
  • Oversee the complete audit process from scoping to documentation.
  • Promote innovation and data analytics in audit practices.
  • Cultivate relationships with senior stakeholders to enhance audit communication.

Benefits

  • Competitive compensation package with performance-based rewards.
  • Comprehensive medical, dental, and prescription drug coverage.
  • Discretionary bonus program and defined contribution pension plan.
  • Generous vacation policy and additional paid days for longer weekends.
  • Learning opportunities for professional development and skills enhancement.
  • Flexibility in managing work responsibilities.
Full Job Description
The opportunity

We are looking for an experienced Director to join our Global Internal Audit team, as an Audit Leader. This role offers the opportunity to operate at a global executive level while further developing your leadership skills in an inclusive and diverse environment. The scope of Global Internal Audit encompasses both global systems and processes and those across the regions. You will be at the forefront helping EY with managing the risks and challenges of a rapidly changing digital landscape, ensuring compliance with evolving regulations, and identifying opportunities for innovation and continuous improvement to deliver valuable outcomes. If you love Technology and Digital / Cyber Risk and would like to gain a different perspective of our own large and globally diverse EY organization and want to make an impact, come join our team.

You will not be required to relocate, however you will need to be flexible to travel internationally and to accommodate international time zones.

Your key responsibilities
  • Support the Chief Audit Executive build a technology risk capability that will enable internal audit to provide confidence and assurance that EY's strategic technology and core platforms are protected and operating effectively. This includes AI, digital platforms and core business technologies e.g. Mercury / SAP.
  • Lead the development of the technology-focused internal audit plan encompassing risk assessments and the strategic internal audit approach to emerging digital, cybersecurity, data, compliance and process risks. This also will include monitoring the technology environment, follow-up activities and future audit or advisory coverage.
  • Lead internal audits and advisory engagements across IT risk management, cybersecurity, digital compliance (including ISO, PCI, Privacy and other leading security and technology frameworks and regulations), program risk, resilience, data governance and responsible AI.
  • Assess key technology environments, applications, systems, interfaces, IT dependencies and IT general controls to support risk-based audit scoping and execution.
  • Oversee end-to-end audit delivery, including scoping, planning, budgeting, resourcing, execution, reporting and completion of required documentation in accordance with GIA methodology.
  • Promote innovation, data analytics, automation and leading practices to enhance audit effectiveness and insight generation.
  • Cultivate trusted relationships with senior management, Audit Sponsors, stakeholders, second line functions and subject matter resources to support effective audit engagement, alignment on key risks and transparent communication of audit progress and outcomes, while maintaining GIA's independence, objectivity and professional scepticism.
  • Lead the development of high-quality audit reports and deliverables that clearly communicate key risks, findings and actionable insights, ensuring consistency with GIA reporting standards, required reviews and stakeholder expectations.
  • Develop and strengthen GIA's technology audit capabilities by supporting recruitment, managing and coaching team members and subject matter resources, fostering knowledge sharing, technical upskilling and an inclusive, high-performing team environment.


Skills and attributes for success

The successful candidate will be an experienced Technology Risk Director with strong experience in cybersecurity, new technology (e.g. AI / automation and related tools), technology governance and risk management, risk management and internal audit. The primary capability is to bring broad experience across IT governance, cybersecurity, digital compliance, ERP, resilience, data governance, responsible AI and technology-enabled transformation. This technology experience needs to be combined with the ability to lead complex global projects and internal audits, building trust and engagement with senior stakeholders and deliver clear, risk-based insights that support effective governance, risk management and control improvement.

In addition, you are able to:
  • Foster an inclusive, innovative and high-performing team environment by actively coaching, mentoring and developing team members.
  • Deliver high-quality audit and advisory work within agreed timelines and budgets, while proactively managing risks, monitoring progress and keeping stakeholders informed of key outcomes and emerging matters.
  • Communicate clearly and effectively, providing actionable insights and practical recommendations on control issues, risk implications and opportunities to address identified gaps.
  • Stay current on business, technology and industry trends relevant to EY's evolving risk landscape.


To qualify for the role you will ideally have:

Education
  • A bachelor's degree or equivalent qualification in a related field, with approximately 15+ years of relevant experience in technology risk, internal audit, public accounting, risk management or a large global organization.
  • Certifications and / or accreditations in Information Security, Microsoft, SAP, AI or other relevant technologies.


Experience
  • At least 10 years of experience in a leadership role managing a team, and demonstrated experience in the following areas:
    • Technology-enabled Integrated Risk Management (IRM) or Governance, Risk and Compliance (GRC) programs
    • Portfolio, Program and Project risk management consulting and/or assurance services
    • Regulatory Compliance (e.g. Privacy, SoCI Act, SoX, Spam Act)
    • Resiliency - design, build, implementation of business and technology resilience programs
    • AI Governance, Responsible Use of AI (incl. Responsible AI strategy, AI Governance framework)
    • Governance, Risk and Compliance
    • Internal Controls and Internal Audit (incl. Controls optimisation, SoX)
    • Assurance - technology-focused internal audit (incl. IT General Controls, Cyber Security, and AI Governance)


Certification requirements:

CISSP/CISM/CCSP/CISA certification desired; non-certified hires will be supported in acquiring relevant certifications.

This job posting relates to an existing vacancy within our organization.

What we offer you (Canada)

We offer a competitive compensation package where you'll be rewarded based on your performance and recognized for the value you bring to our business. In addition, our Total Rewards package allows you to decide which benefits are right for you and which ones help you create a solid foundation for your future. Our Total Rewards package includes a discretionary bonus program, a comprehensive medical, prescription drug and dental coverage plan, a defined contribution pension plan, a great vacation policy plus firm paid days that allow you to enjoy longer long weekends throughout the year, statutory holidays and paid personal days (based on province of residence), and a range of exciting programs and benefits designed to support your physical, financial and social well-being. Plus, we offer:

  • Support and coaching from some of the most engaging colleagues in the industry

  • Learning opportunities to develop new skills and progress your career

  • The freedom and flexibility to handle your role in a way that's right for you


Are you ready to shape your future with confidence? Apply today.

About Ernst & Young

Ernst & Young (EY) is a multinational professional services firm that provides audit, tax, consulting, and advisory services to clients in a wide range of industries. The firm was founded in 1989 through the merger of Ernst & Whinney and Arthur Young & Co., and has since grown to become one of the largest professional services firms in the world. EY is committed to building a better working world by helping its clients solve their toughest challenges, and by creating a positive impact on the communities it serves.
Learn more about Ernst & Young
Size
300,000 employees
Industry
Founded
1989

Similar Jobs

More Jobs at Ernst & Young

More Information Technology Jobs

Find similar Director - Technology Risk jobs: