- Salary
- $165k – $190k/yr
- Location
- West Palm Beach, FL, US
- Type
- Full-time
- Department
- Finance
- Seniority
- Senior
- Source
- Breezy HR
Description
Ondas is seeking an experienced IT Audit Senior Manager to lead the Company’s information technology audit function. This role will provide independent, risk-based assurance over the effectiveness of IT general controls, cybersecurity safeguards, technology governance, and regulatory compliance programs.
The IT Audit Senior Manager will evaluate whether technology systems and processes appropriately support business objectives; protect Company assets; and maintain the confidentiality, integrity, and availability of information. The successful candidate will partner closely with Finance, Information Technology, Cybersecurity, business leaders, external auditors, and the Audit Committee to identify technology-related risks, drive remediation, and strengthen Ondas’s internal control environment.
Key Responsibilities
• Develop and execute a risk-based IT audit plan covering IT general controls (ITGCs), cybersecurity, information security, applications, infrastructure, cloud environments, and third-party service providers.
• Evaluate the design and operating effectiveness of controls related to user access management, privileged access, change management, IT operations, and segregation of duties.
• Assess controls supporting backup and recovery, disaster recovery, business continuity, network security, system configuration, and application security.
• Lead internal and co-sourced IT audit engagements, including audit planning, risk assessment, testing, documentation, reporting, and remediation follow-up.
• Manage external IT audit consultants and support the development of a scalable, high-performing IT audit team over time.
• Assess compliance with applicable frameworks, standards, and regulations, including SOX Section 404, COSO, the NIST Cybersecurity Framework, ISO 27001, CMMC, and relevant government-contracting requirements.
• Partner with Finance, Cybersecurity, IT, Legal, and operational leaders to identify, assess, and mitigate technology-related risks.
• Prepare clear, concise audit reports that communicate findings, risk ratings, root causes, and practical recommendations for management and the Audit Committee.
• Review SOC 1 Type II reports and assess the adequacy of complementary user entity controls; design and implement compensating controls as appropriate.
• Monitor remediation plans, validate corrective actions, and report on the status of open issues and control deficiencies.
• Support external auditors and regulatory examinations by coordinating audit requests, collecting evidence, facilitating walkthroughs, and responding to inquiries.
• Advise management on emerging technology risks, cybersecurity threats, system implementations, artificial intelligence governance, automation initiatives, and evolving compliance expectations.
• Promote continuous improvement in IT governance, risk management, compliance, and internal-control practices throughout the organization.
Qualifications
• Bachelor’s degree in Information Systems, Computer Science, Cybersecurity, Accounting, or a related field.
• 10+ years of progressive experience in IT audit, IT risk management, cybersecurity, internal audit, public accounting, or a related discipline.
• Demonstrated experience implementing or auditing IT general controls, including change management, user access management, IT operations, and segregation-of-duties controls.
• Experience evaluating IT application controls and reviewing service organization control reports, including SOC 1 Type II reports.
• Strong knowledge of SOX compliance requirements, internal-control frameworks, enterprise systems, cloud platforms, and cybersecurity frameworks.
• Working knowledge of COSO, NIST Cybersecurity Framework, ISO 27001, CMMC, and government-contracting control expectations.
• Ability to translate complex technical risks and control issues into clear, actionable recommendations for nontechnical business leaders and executive stakeholders.
• Strong project-management, analytical, communication, and relationship-building skills.
• Ability to work effectively in a fast-paced environment and manage multiple audit priorities simultaneously.
Preferred Qualifications
• Professional certifications such as CISA, CISSP, CIA, CPA, CRISC, CISM, or similar credentials.
• Experience supporting a publicly traded company’s SOX compliance program.
• Experience working with defense, homeland security, critical infrastructure, government contracting, or similarly regulated industries.
• Experience with emerging technology governance, including artificial intelligence, automation, cloud environments, and third-party risk management.
• Experience building, leading, or managing an IT audit function and external co-sourced audit providers.
Compensation and Benefits
The base salary range for this IT Audit Senior Manager position is $165,000–$190,000 per year. This range represents the good-faith estimate of the salary Ondas reasonably expects to pay for this role at the time of posting.
Actual compensation within this range will be determined based on factors such as relevant experience, skills, education, internal equity, and geographic location, in accordance with applicable law. This position may also be eligible for additional compensation and benefits, which may include annual incentive compensation, equity, health benefits, retirement plans, paid time off, and other benefits, subject to the terms of applicable plans and programs.
Equal Employment Opportunity
Ondas is an equal opportunity employer and is committed to providing a workplace free from discrimination and harassment. Employment decisions are made without regard to race, color, religion, creed, sex, pregnancy, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, protected veteran status, military status, or any other status protected by applicable federal, state, or local law.
About Ondas
Ondas is a leading provider of private wireless, drone, and automated data solutions. Through its subsidiaries, Ondas delivers autonomous aerial and ground robotics, connectivity, data collection, and information-processing capabilities to customers in the defense, homeland security, and critical infrastructure markets.