Technology Transformation Audit Program Manager at Vaco, LLC
Mountain View, CA 94043
About the Job
- Manage and direct the work streams related to IT SOX compliance and application controls.
- Provide technical support in the assessment, design and implementation of ITGC requirements.
- Review new systems architecture and determine SOX scoping for ITGCC and IT application controls.
- Review control evidence for adherence to accuracy, completeness and precision of control execution for all ITGC.
- Review test findings, facilitate the remediation of ITGC control gaps, and escalate possible critical issues to senior management within IT.
- Guide the planning, scoping and execution of audits primarily in areas associated with technology and technology-related risks (e.g. cybersecurity, privacy, and business resilience) including reviews of new and enhanced products and supporting systems, process changes and system implementations.
- Work with Security and Privacy teams to understand the information security and privacy risk profile and use this knowledge for audit planning and execution.
- Partner with security and engineering teams to lead and manage and contribute to the technology audits
- Design, lead and execute audit programs, including security and privacy audits, operational process reviews, system implementation reviews, application and other IT-related risk areas. Create and lead ad-hoc analyses of financial and IT data.
- Work cross-functionally on technology implementation projects to provide IT controls expertise and test controls to meet information security and privacy requirements. Understand applicable laws and regulations to provide a point of view on audit requirements related to information security and privacy controls.
- Work with management and users to interpret the significance of audit findings, conclude on findings, make practical recommendations, and verify that remediation plans are implemented.
- Lead the report drafting process including framing of audit observations within the relevant business context, formulation of practical recommendations that balance stakeholder needs, and development of useful insights for management.
- Demonstrate strong technical skills and understanding of key security, privacy, agile engineering practices.
Qualifications
- 10+ years of progressive internal audit experience in either Big 4 public accounting, and/or in industry, including at least 3-5 years of supervisory responsibility
- Bachelor’s or Master’s degree in a relevant discipline (e.g. Computer Science) or equivalent work experience
- CISA, CISM and/or CISSP certifications preferred
- Demonstrated knowledge of technology risks, including direct experience evaluating the effectiveness of cybersecurity, privacy and engineering controls
- Working knowledge of information technology best practices and control frameworks such as NIST CSF, ISO27001 and COBIT
- Demonstrated influencing skills including the ability to explain complex topics in simple terms and inspire transformational improvement in internal controls
- Excellent written & verbal communication and presentation skills
Vaco values a diverse workplace and strongly encourages women, people of color, LGBTQ+ individuals, people with disabilities, members of ethnic minorities, foreign-born residents, and veterans to apply.
EEO Notice
Vaco is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law.
Vaco LLC and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco LLC and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact HR@vaco.com .
Vaco also wants all applicants to know their rights that workplace discrimination is illegal.
By submitting to this position, you agree that you will be giving Vaco the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal.
Privacy Notice
Vaco LLC and its parents, affiliates, and subsidiaries (“we,” “our,” or “Vaco”) respects your privacy and are committed to providing transparent notice of our policies.
- California residents may access Vaco’s HR Notice at Collection for California Applicants and Employees here.
- Virginia residents may access our state specific policies here.
- Residents of all other states may access our policies here.
- Canadian residents may access our policies in English here and in French here.
- Residents of countries governed by GDPR may access our policies here.
Pay Transparency Notice
Determining compensation for this role (and others) at Vaco depends upon a wide array of factors including but not limited to:
- the individual’s skill sets, experience and training;
- licensure and certification requirements;
- office location and other geographic considerations;
- other business and organizational needs.
With that said, as required by local law, Vaco believes that the following salary range referenced above reasonably estimates the base compensation for an individual hired into this position in geographies that require salary range disclosure. The individual may also be eligible for discretionary bonuses.