About the Role
The Senior Audit Manager supports the Deputy Chief Audit Officer in planning, supervising, and executing the Internal Audit plan, focusing on Information Technology and Information Security risks. This role acts as a subject matter expert in technology and cyber risk, while also providing audit coverage in Commercial Banking, Risk Management, and Operations. The position leads complex, risk-based audits, assesses governance, risk management, and control effectiveness, and ensures alignment with professional standards, regulatory expectations, and industry best practices.
Responsibilities
- Lead and supervise internal audits and targeted reviews with a primary emphasis on Information Technology, Information Security, cybersecurity, technology governance, third-party risk management, data protection, and system development life cycle controls.
- Serve as the Internal Audit subject matter expert for IT and Information Security, identifying emerging technology and cyber risks relevant to the Bank.
- Plan and execute audits across multiple business lines, including IT, Commercial Banking, Risk Management, and Bank Operations, ensuring appropriate integration of technology risks into all audits.
- Integrate data analytics and AI audit methodologies into the overall audit framework.
- Develop audit scopes, perform risk assessments, oversee testing, validate issues, and ensure appropriate coverage of IT-dependent controls.
- Identify control deficiencies, assess root causes and impact, and recommend practical, risk-based remediation strategies.
- Review and approve audit workpapers to ensure accuracy, completeness, and adherence to Internal Audit standards.
- Prepare, review, and edit audit reports to clearly communicate technology, information security, and business risks from a senior management and Audit Committee perspective.
- Evaluate management action plans and monitor the remediation of IT, information security, and business audit issues.
- Coordinate audit activities with internal stakeholders, regulators, and external or co-source auditors, particularly for targeted technology and cybersecurity reviews.
- Support enterprise risk assessment, SOX, and regulatory examination activities where technology or data risks are present.
- Provide coaching, technical guidance, and performance feedback to audit staff and managers.
- Stay current on regulatory guidance, industry standards, and emerging risks related to IT and information security, including FFIEC, NIST, and cybersecurity frameworks.
- Assist the DCAO with departmental initiatives, strategic projects, and regulatory or Board-level requests as assigned.
Requirements
- Minimum of 8–10 years of progressive internal audit, IT audit, information security, or risk management experience within a regulated financial services environment.
- Demonstrated experience leading complex IT and information security audits and supervising audit staff.
- Significant experience auditing or managing risks in data analytics, machine learning, or AI environments.
- Strong understanding of IT general controls, cybersecurity, cloud environments, data governance, third-party risk, and SDLC controls.
- Deep knowledge of AI/ML systems, model lifecycle, and related controls.
- Understanding of data analytics tools (e.g., Tableau, Python, SQL, Power BI, R) and audit automation.
- Working knowledge of banking regulations and technology-related regulatory expectations (e.g., FFIEC, OCC, FDIC guidance).
- Understanding of COSO internal control framework and its application to technology-enabled processes.
- Excellent analytical, organizational, and project management skills.
- Strong written and verbal communication skills, with the ability to translate complex technical issues for senior management and the Audit Committee.
Skills
- Information Technology
- Information Security
- Cybersecurity
- Technology Governance
- Third-Party Risk Management
- Data Protection
- System Development Life Cycle Controls
- Data Analytics
- AI Audit Methodologies
- AI/ML Systems
- Model Lifecycle
- COSO Internal Control Framework
- FFIEC
- NIST
- Tableau
- Python
- SQL
- Power BI
- R
Location
- New York, NY
Work Type
- Hybrid
Experience Level
- Senior
- 8-10 years
Education Level
- Bachelor’s degree in Accounting, Finance, Information Systems, Computer Science, or a related field.
- CISA certification strongly preferred
- CIA or CPA a plus
- Certification or training in AI ethics, data governance, or model risk management (e.g., MIT AI Ethics, NIST AI Risk Framework)
Salary/Compensations
- $160,000 – $180,000
About the Company
- Amalgamated Bank is an Equal Opportunity and Affirmative Action Employer.
- AmeriCorps, Peace Corps and other national service alumni are encouraged to apply.
- View our Pay Transparency Statement.
- Submission of a resume or any information regarding your qualifications does not constitute a promise or offer of employment.
- At Amalgamated Bank, we consider an applicant to be someone who has interviewed at least once, in person, with the hiring manager.
- Amalgamated Bank does not sponsor applicants for work visas.
Equal Opportunity
- Amalgamated Bank is an Equal Opportunity and Affirmative Action Employer, Minorities / Females / Individuals with Disability / Veterans.
- AmeriCorps, Peace Corps and other national service alumni are encouraged to apply.
