IT Auditor
For the firm’s Information Security & Privacy | Financial Services
- Must be a US Citizen or Green Card Holder.
Must live in the NYC, or Staten Island vicinity.
PLEASE DO NOT APPLY IF YOU LIVE OUTSIDE OF THE NYC AREA
Willing to travel to Woodbridge New Jersey.
Full Time
3 days onsite
Base comp around $180k
Key skills
GLBAFFEICImplement risk-based testing and monitoring programIT and Data privacy regulationsRisk mitigationA leading financial institution is seeking an experienced IT Auditor to play a critical role in developing and executing a robust second line of defense program focused on IT, Information Security, and Privacy compliance. This position ensures alignment with regulatory requirements, industry best practices, and internal policies, while serving as a trusted advisor to senior leadership on emerging risk and compliance issues.
This is an exciting opportunity to join a high-performing compliance team and help shape the technology risk management framework in a highly regulated, client-centric environment.
Key Responsibilities :
Develop and implement a risk-based testing and monitoring program covering IT, Information Security, and Privacy to ensure compliance with relevant regulations (e.g., GLBA, FFIEC IT Handbooks) and internal standards.Review and provide challenge to risk assessments conducted by IT and Information Security teams, particularly those aligned with GLBA-related obligations.Design and execute compliance testing programs tied to controls identified through risk assessments or ongoing monitoring efforts.Advise senior management on current and emerging IT and data privacy regulations, expectations, and industry standards.Prepare and deliver compliance reporting to senior stakeholders on the status of risk mitigation and control effectiveness.Support incident response activities, including breach investigations, remediation efforts, and, when applicable, regulatory communications in partnership with Legal and Security teams.Collaborate with IT, Information Security, and Internal Audit teams on regulatory exam preparation and response efforts.Develop and deliver training programs to educate staff on IT security and privacy compliance responsibilities.Ensure compliance is embedded into the organization’s technology initiatives, data governance efforts, and business processes.Participate in or report to internal governance committees focused on IT, Information Security, and Privacy oversight.Qualifications :
Bachelor’s degree in information technology, Computer Science, Business Administration, or a related field (preferred).5–10 years of experience in IT compliance, information security / privacy, internal audit, or as a regulatory examiner, ideally within banking, asset management, or broader financial services.Strong knowledge of relevant regulatory frameworks and standards, such as GLBA, FFIEC IT Handbooks, and industry best practices.Solid understanding of cybersecurity, IT controls, information systems, and data protection principles.Exceptional analytical, problem-solving, and communication skills, with the ability to engage stakeholders across business, IT, and legal functions.Comfortable working both independently and collaboratively across cross-functional teams.Preferred certifications : CISA, CIPP, or equivalent credentials in IT risk, audit, or privacy compliance.