IT Internal Audit Manager
Department: Finance
Employment Type: Full Time
Location: US-Arizona-Tempe-Corp HQ
Description
IT Internal Audit Manager
Internal Audit‘s vision is be a trusted business advisor as it relates to our areas of expertise: Governance, Risk, and Control. We do this by monitoring the risk environment across Align and providing insights to enable effective risk management. As well as evaluate the efficiency, effectiveness and maturity of our processes and systems. We work closely with teams and leadership to achieve a strong control environment that enhances and protects organizational value. We serve the entire company from a compliance perspective and staff and develop our team to be control experts who deliver objective and reliable results.
Position Summary
Reporting to the VP of Global Internal Audit , the IT Internal Audit Manager leads the technology audit portfolio globally and serves as the department’s subject matter expert on IT, cybersecurity, and data. This leader plans and executes IT general controls (ITGC) and application control testing in support of SOX, delivers risk-based technology and cybersecurity audits, and advises on transformation initiatives where technology, data, and automation drive the outcome. The role blends deep technical audit expertise with business partnering: the successful candidate is equally comfortable challenging a cloud configuration, reviewing major ERP transformations, including relevant SDLC controls and briefing executives and the Audit Committee in plain language.
Essential Duties and Responsibilities
IT Audit Planning and Execution
• Develop and maintain the annual IT audit plan using a risk-based approach, refreshed for emerging technology, cyber, and regulatory risk; align the plan with the enterprise risk management (ERM) program and the broader internal audit plan.
• Scope, lead, and deliver IT audits end to end — planning, risk and control matrices, fieldwork, issue development, reporting, and follow-up — in accordance with the IIA Global Internal Audit Standards.
• Lead audits across domains including cybersecurity, cloud (AWS/Azure/SaaS), identity and access management, change and release management, IT operations and resiliency, data privacy, IT third-party/vendor risk, and major system implementations and ERP transformations.
• Perform pre- and post-implementation reviews of significant technology programs, providing independent assurance on project governance, data conversion, cutover readiness, and control design.
SOX and Technology Controls
• Own the IT scope of the SOX program: ITGC scoping and risk assessment, control design evaluation, test plan development, testing execution, deficiency evaluation, and aggregation of IT findings with the financial statement audit.
• Evaluate and advise on automated controls, IT-dependent manual controls, key reports, and interface/data integrity controls within SAP and adjacent platforms.
• Coordinate directly with external auditors and process owners on scoping, reliance, evidence, and remediation timelines; drive efficiency through control rationalization and reliance strategies.
• Assess the control implications of emerging technologies, including AI/automation use cases, and advise management on appropriate governance, human oversight, and monitoring.
Cybersecurity and InfoSec Partnership
• Provide independent assessment of the information security program against recognized frameworks (NIST CSF, ISO 27001, CIS Controls), including vulnerability and patch management, logging and monitoring, incident response, and security awareness.
• Cultivate a collaborative, non-adversarial relationship with the CISO and InfoSec leadership; align audit coverage with the security roadmap while preserving independence and objectivity.
• Support ad hoc security reviews, penetration/attack-surface validation exercises, and readiness assessments as requested by management.
Analytics, Automation, and Continuous Auditing
• Build and scale data analytics across the audit lifecycle — full-population testing, anomaly detection, segregation-of-duties analysis, and continuous control monitoring — using tools such as Power BI, SQL, Python, or equivalent.
• Champion the use of automation and AI within the internal audit function to improve coverage, cycle time, and insight quality.
Investigations and Advisory
• Provide forensic and technical support to investigations, including data preservation, log and system analysis, and independent evaluation of findings, coordinating with Legal, HR, and Compliance.
• Advise business and IT leadership on control design for new processes and systems, maintaining an independent and objective perspective.
Leadership and Communication
• Mentor, coach, and develop audit staff and co-source/outsource resources; manage budgets, schedules, and quality across concurrent engagements.
• Communicate findings, root causes, business impact, and practical recommendations to senior management; negotiate management action plans with clear owners and due dates and track them to closure.
• Contribute materials and technology risk perspective to Audit Committee and executive reporting; represent the department in executive forums.
• Build and maintain strong cross-functional relationships across IT, Commercial, Finance, Legal, and Compliance.
What we're looking for
• Frameworks: Practical command of COSO, COBIT, NIST CSF, ISO 27001, and SOX 404 requirements; familiarity with data privacy regulations (GDPR, CCPA/CPRA, HIPAA).
• Analytical rigor: Excellent problem-solving skills with a proactive mindset; able to move from raw data to a defensible conclusion and a practical recommendation.
• Project leadership: Proven ability to manage multiple concurrent audits with precision, attention to detail, and on-time delivery.
• Communication: Strong written and verbal presentation skills; able to translate technical issues into business risk for non-technical executives.
• Collaboration: Team-oriented, credible, and influential without authority; fosters a positive, open working environment.
• Integrity: Demonstrated independence, objectivity, and sound judgment in sensitive and confidential matters.
Education and Experience
• Bachelor’s degree in Information Systems, Computer Science, Accounting, Finance, or a related field, or equivalent experience.
• Master’s degree (MIS, Accounting, Finance, MBA) preferred.
• Minimum of 6+ years of IT audit, IT risk, or information security experience, including SOX ITGC ownership; Manager-level candidates will be considered with 6+ years.
• Prior experience in a leadership, supervisory, or advisory capacity; Big 4 or large-firm technology risk experience strongly preferred, ideally combined with in-house corporate audit experience.
• Experience in a global, publicly traded company; medical device, life sciences, or manufacturing industry experience is a plus.
Preferred Certifications
• CISA strongly preferred; CISSP, CRISC, CISM, CIA, CPA, or cloud certifications (AWS/Azure) are advantageous.
Tools and Technology
• Enterprise platforms and audit tooling such as SAP, ServiceNow, Workday, Salesforce, GRC/audit management systems, Power BI, SQL, Python, and the Microsoft 365 suite.
Work Schedule / Hours
• Regular business hours with flexibility based on project demands and global time zones.
• Ability and willingness to travel domestically and internationally, up to 20%.
.
.