Confidential mandate
Technology and Cyber Internal Audit Vice President
Planned Hiring / New
Technology and Cyber Internal Audit Vice President mandate in New York, United States
Confidential Technology and Cyber Internal Audit Vice President in New York, United States, reporting to the Chief Audit Executive. Permanent Internal & Statutory Audit appointment at Vice President level, an ongoing appointment; full time.
The mandate
The Vice President will provide independent assurance over technology and cyber risks without anchoring coverage to a static control catalogue. The portfolio must follow the ways strategic change, privileged access, resilience, data dependency and third-party concentration alter exposure, while avoiding any public disclosure of the organisation's architecture or threat profile.
This permanent role owns the technology auditable universe, specialist plan, audit methodology, talent and communication of residual risk. It must integrate technical testing with governance and business consequence so that detailed findings neither disappear into jargon nor overstate what the evidence supports.
The Vice President may approve scope, demand authorised access, determine ratings, stop unsafe testing and escalate restrictions directly through the Chief Audit Executive. Technology management owns security and control remediation. Internal audit will not configure safeguards, select tools or assume operational monitoring.
The first year will produce a risk-led coverage map, renewed specialist methodology, targeted reviews of priority exposures and a technical succession plan. Success will be measured by earlier recognition of cross-domain risk, stronger evidence and action on root causes rather than growth in technical finding counts.
What you will own
- Reconstruct the technology and cyber audit universe around critical services, data, identity, change, resilience, third parties and governance.
- Prioritise coverage using consequence, threat exposure, control confidence, change velocity, concentration and independent-assurance gaps.
- Define safe-testing, evidence-handling and escalation protocols for sensitive environments without naming specific platforms publicly.
- Approve audit objectives that connect technical conditions to confidentiality, integrity, availability, compliance and decision impact.
- Establish specialist review and rating calibration so severe language is reserved for evidence-supported exposure.
- Coordinate reliance on technical assurance providers while independently testing their scope, competence and objectivity.
- Validate high-risk remediation through design and operating evidence rather than closure screenshots or management assertion.
- Develop audit leaders across cyber, technology resilience, data and change assurance with credible succession coverage.
Candidate qualifications
- At least 17 years in technology or cyber audit, including five years leading specialist internal-audit portfolios.
- Active US CPA or equivalent chartered-accountancy credential, supported by CISA, CIA, CISSP or a comparable licensed assurance qualification.
- Evidence of an audit that translated a technical weakness into a material governance or operating consequence without exaggeration.
- Deep knowledge of identity, change, resilience, data, third-party, cloud-governance and cyber-risk audit concepts without dependence on one stack.
- A case where you stopped or redesigned testing because the proposed method could affect a live service or compromise evidence.
- Experience challenging management reliance on specialist assurance whose scope or independence did not support the claimed comfort.
- A record of recruiting and developing scarce technical auditors while maintaining professional scepticism and audit discipline.
Working terms and boundaries
- This continuing appointment has first-year gates after universe approval, methodology calibration, priority reviews and talent assessment.
- Audit scope, evidence, rating and access escalation are included; technology operation, control ownership and tool selection remain excluded.
- Hybrid work is organised around sensitive fieldwork, committee reporting and specialist calibration, with approved handling of protected evidence.
- Technical testing must follow safe-authorisation protocols and may be suspended immediately when operational or evidential risk changes.
- Year-one completion requires risk-led coverage, independently validated priority issues, consistent ratings and viable specialist succession.
Application
Applications for this mandate are received in one way only: through the India Board Terminal's application process. It is automated end to end. Your Executive Passport travels to the mandate holder in its confidential form, your answers to the three questions below are read before anything else in your file, and every stage that follows is recorded on your applications page.
There is no address to write to and no intermediary to call. The mandate holder reads what the Terminal delivers and nothing else, which is what keeps the process the same for every applicant and keeps your name out of it until you release it. Applications close on 9 October 2026. Mandate reference AUD-PER-2026-NYC-22.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.