IT Audit Advisory - ManagerOpportunity ID
10059
Department
Advisory
Location(s)
Parsippany
State
New Jersey
Function
Risk Advisory
Job Description
We currently have an exciting career opportunity for a
Manager to join the
Cybersecurity & Digital Trust team in our
Risk Advisory practice.
CohnReznick is a hybrid firm and most of our professionals are located within a commutable distance to one of our offices. This position is considered hybrid which means team members are expected to be thoughtful and intentional in how they create opportunities for in-person collaboration. While the cadence of in-office presence is determined at the team level, our professionals are encouraged to be in the office/together in person on average 3 days a week.
YOUR TEAM. Join a diverse team of fun-loving, energetic professionals with decades of experience managing security, technology, and privacy risks in nearly every industry sector who have a passion for creating tailored solutions that go beyond technology offerings or tools and help clients reduce cost of compliance while mitigating risks.
YOUR ROLE. Responsibilities include but not limited to:The Manager will lead the execution of IT audit, IT risk management, and cybersecurity assessment engagements for a diverse client base, including organizations subject to regulatory, contractual, and federal cybersecurity requirements. This role will play a key part in performing risk-based IT audits, cyber maturity and compliance assessments, and advisory services.
IT Audit & IT Risk
- Assess technology risks and provide value-added advisory services aligned with the clients' strategies and enterprise risk profiles.
- Evaluate client IT environments including IT systems, processes, risk, and controls to ensure compliance with prevailing standards, laws and regulations.
- Assess clients' IT governance frameworks and controls to identify weaknesses in IT process, systems and infrastructure and help ensure operational effectiveness and efficiency.
- Work with clients in a broad array of industries including banking, financial services, information technology, not-for-profit, government contracting, life sciences, manufacturing, etc.
- Assess and facilitate clients' compliance with laws, regulations, and industry standards such as Sarbanes-Oxley (SOX), NIST, FFIEC, NYDFS, FISCAM, FISMA, SSAE/SOC, Cloud Security Framework, FedRAMP, OMB A-123, COBIT, ISO27001, etc.
- Understand clients' organizations and provide pragmatic, value-added solutions and best practices.
- Conclude on the business impact to the organization as it relates to identified cybersecurity, technology, and/or privacy risks.
- Prepare formal written reports for senior management and audit committees and provide recommendations to strengthen and improve operations, risk mitigation, and compliance.
- Maintain knowledge of emerging IT risks and trends to ensure audit procedures and processes remain up to date.
- Plan, manage, and execute simultaneous complex engagements, maintain quality standards, and proactively manage client issues and expectations.
- Lead and supervise teams of professionals to ensure timely and effective completion of projects and balance client needs with profitability.
- Handle day-to-day practice and client administrative matters (performance reviews, staffing, budget-to-actuals monitoring, etc.)
- Undertake other special technology risk and cybersecurity projects as requested by the clients based on the mission, objectives, and risks of the clients.
- Identify areas for risk transformation and automation to assist clients with reducing the cost of compliance, and consider data analytics, RPA, and/or AI to promote efficiency.
- Develop and maintain relationships with key client stakeholders, including senior management and outside audit firms.
- Participate in business development activities such as professional networking, proposal development, etc.
- Recruit, manage, develop, train, coach and mentor staff on projects and assess performance for engagement and year-end reviews.
- Other related duties assigned as needed.
Cybersecurity & CMMC Assessments
- Perform cybersecurity assessments and readiness reviews aligned to CMMC, NIST SP 800-171, NIST CSF, ISO27001, and other recognized frameworks.
- Support or lead CMMC gap assessments, readiness assessments, and advisory activities for organizations in the Defense Industrial Base (DIB).
- Assist in evidence collection, validation, and analysis for cybersecurity and compliance assessments.
- Contribute to development of client deliverables, including assessment reports, risk summaries, and management presentations.
Client Delivery & Engagement Support
- Serve as a day-to-day engagement team member, managing assigned workstreams and coordinating with team members and client stakeholders.
- Simultaneously serve multiple engagements while maintaining high quality standards
- Work with clients in a broad array of industries including information technology, financial services, retail & consumer products, pharmaceuticals, electronics, manufacturing, media, and government contracting etc.
- Facilitate client interviews and walkthroughs to understand IT environments, security controls, and operational processes.
- Ensure workpapers and deliverables meet quality, consistency, and documentation standards.
- Understand clients' organizations and provide value-added solutions and best practices
- Identify emerging risks, trends, and improvement opportunities for clients.
Team Collaboration & Development
- Mentor and review work performed by Consultants and Analysts.
- Share knowledge and best practices related to IT audit, cybersecurity, and CMMC requirements.
- Contribute to internal methodology development, tools, and training initiatives.
YOUR EXPERIENCE. The successful candidate will have:- Bachelor's degree in Information Systems, Computer Science, Accounting, Cybersecurity, or a related field.
- 7+ years of relevant experience in IT audit, IT risk, cybersecurity, or technology advisory roles. 3+ years in management.
- Certified Information Systems Auditor (CISA)
- Certified CMMC Assessor (CCA) or active progress toward CMMC Assessor certification - strongly preferred.
- Additional certifications a plus, such as: CISSP, CRISC, CISM, CIA, etc.
- Ability to work onsite 3 days per week, and travel up to 50% (domestic and international)
- Hands-on experience performing IT audits, IT risk assessments, or cybersecurity assessments in a professional services environment
- Strong understanding of internal controls, risk management concepts, and common cybersecurity frameworks.
- Background and understanding of the risks and controls in technologies such as web, cloud, client/server, open systems architecture, data warehousing, and imaging
- Proficient understanding of cloud security, Identity and Access Management, ERP, Operating Systems, Databases, and Network Infrastructure components
- Knowledge of risk and controls related to emerging technologies such as AI, blockchain, and automation.
- Working knowledge of Cloud Security Framework, General Data Protection Requirement (GDPR), COBIT 5, ISO 27001/2, HIPAA, California Consumer Protection Act (CCPA), NIST 800-171/800-53/NIST 800-37
- Excellent written and verbal communication skills, with the ability to explain technical concepts to non-technical audiences.
- Ability to manage multiple priorities and work effectively in a client-facing consulting environment.
- Participate in business development activities such as proposal writing, professional networking, and thought leadership development
In
New Jersey, the salary range for a
Manager is $110,000 to $180,000. Salary is one component of the CohnReznick total rewards package, which includes a discretionary performance bonus, generous paid time off, expanded, and inclusive parental benefits, and access to best-in-class learning and development platforms, to name a few. To learn more about life at CohnReznick, visit
.#LI-NS1 #GD #LI-Hybrid