Regis University logo

Manager IT Audit

Salary
$130K–$160K
USD
Hiring from
United States
Work type
Hybrid
Posted
Sep 24, 2026
Is this job info correct?

Take your career to the next level! In the last few years our goal has been expansion, creating growth opportunities for many of our team members. Not only are we serious about growth, but we are also serious about helping our customers during hard financial times.

We take pride in providing solutions and offering a helping hand, not only to our customers but also to the communities we serve. As we continue to expand and grow into a national leader in consumer financing, we invite you to consider joining our team.

If you're passionate about making a meaningful impact in people's lives and bringing a personal touch to finance, we'd love to have you on board!

Job Purpose

The Manager, IT Audit reports to the Senior Manager, Internal Audit and is responsible for leading the Company’s end-to-end IT SOX program supporting internal control over financial reporting. Under the direction of the Senior Manager, Internal Audit, this role leads the planning, risk assessment, scoping, evaluation of the effectiveness of IT controls, issue evaluation, and reporting of IT SOX-related activities across the organization, including the annual key reports and query testing.

The Manager serves as a subject matter expert of IT SOX, partnering with IT leadership, business process owners, control owners, Internal Audit leadership, and external auditors to ensure IT General Controls, IT application controls, automated controls, interfaces, key reports/queries, and related technology-dependent controls are appropriately designed, operating effectively, and supported by audit-ready documentation.

This position is dedicated to IT SOX and is accountable for driving high-quality, risk-based execution; aligning testing documentation against established methodology; evaluating the severity and financial reporting impact of deficiencies; monitoring remediation through closure; and communicating results, themes, and control implications to management in a clear and timely manner.


IT SOX Planning, Scoping & Program Management

  • Assist the Senior Manager, Internal Audit in the development and execution of the annual SOX audit plan, including identification of financially relevant systems, applications, infrastructure components, service organizations, key reports/queries, interfaces, and technology dependencies supporting key business processes.
  • Develop and maintain risk-based IT SOX testing strategies, and status reporting to support timely completion of walkthroughs, design assessments, operating effectiveness testing, deficiency evaluation, and remediation validation by established deadlines.
  • Assist the Senior Manager, Internal Audit with the maintenance of IT SOX program documentation, including risk and control matrices, process narratives, control descriptions, system inventories, scoping rationale, testing templates, and evidence standards.
  • Monitor changes in systems, applications, infrastructure, service providers, access models, and technology processes to assess SOX impact and update scoping, control coverage, and testing plans accordingly.

IT SOX Execution, Testing & Documentation

  • Lead and/or review walkthroughs, control design assessments, and operating effectiveness testing for IT General Controls, including logical access, change management, IT operations, job monitoring, backup and recovery, incident management, and system development lifecycle controls.
  • Serve as first-level reviewer for IT SOX testing activities, ensuring workpapers clearly document procedures performed, evidence obtained, exceptions identified, conclusions reached, and alignment to with Internal Audit’s SOX methodology, COSO, COBIT, and external auditor expectations.
  • Partner with control owners to clarify control requirements, evidence expectations, documentation standards, frequency of execution, and control precision to promote consistency and audit readiness.
  • Manage testing progress, evidence requests, review notes, open items, and issue resolution to ensure the IT SOX program remains on schedule and supports year-end external audit reliance.

Deficiency Evaluation, Remediation & SOX Reporting

  • Identify, document, and evaluate IT control deficiencies, including root cause, affected systems, compensating controls, likelihood, magnitude, aggregation considerations, and potential impact on ICFR and external audit reliance.
  • Lead discussions with IT management, business process owners, Internal Audit leadership, and external auditors to assess deficiency severity, determine remediation expectations, and align on management action plans.
  • Track remediation activities through completion, validate corrective actions, evaluate sustainability of remediation, and confirm whether control gaps have been appropriately resolved.
  • Prepare clear, concise reporting on IT SOX status, testing results, deficiencies, remediation progress, emerging themes, and control environment implications for management and governance stakeholders.
  • Identify opportunities to rationalize controls, improve control design, automate manual activities, reduce repeat findings, and enhance the efficiency and effectiveness of the IT SOX program.

External Auditor Coordination & Stakeholder Engagement

  • Serve as a primary liaison with external auditors for IT SOX planning, walkthroughs, testing approach, evidence requests, reliance strategy, deficiency evaluation, remediation validation, and year-end audit support.
  • Build effective working relationships with IT leaders, system owners, control owners, business process owners, Internal Audit team members, and external audit teams to promote timely execution and issue resolution.
  • Communicate complex IT control matters, SOX implications, and remediation expectations to technical and non-technical stakeholders in a practical, business-oriented manner.
  • Provide guidance and training to IT control owners on SOX requirements, control execution, evidence retention, documentation quality, and audit readiness expectations.

Leadership & Team Development

  • Mentor, coach, and develop audit staff through ongoing feedback, technical guidance, and professional development opportunities.
  • Assist in training employees, reviewing performance, and supporting resolution of team concerns or engagement challenges.
  • Lead by example by demonstrating professionalism, integrity, accountability, and sound judgment in a fast-paced and evolving environment.
  • Demonstrate accountability, professional skepticism, sound judgment, and ownership in managing the full IT SOX lifecycle from planning through reporting.

Minimum Qualifications

  • Education: Bachelor’s degree in Accounting, Finance, Information Systems, Computer Science, Management Information Systems, or a related field.
  • Required Experience: 8+ years of experience in IT audit, IT SOX, SOX 404 compliance, IT risk advisory, or internal controls, including experience leading IT SOX testing activities.
  • Strong working knowledge of ITGC domains, including logical access, change management, IT operations, system development lifecycle, privileged access, segregation of duties, and key report/interface controls.
  • Experience planning and executing SOX walkthroughs, control design assessments, operating effectiveness testing, deficiency evaluation, remediation tracking, and management reporting.
  • Experience evaluating IT application controls, automated controls, key reports, interfaces, and technology dependencies supporting financial reporting processes.
  • Demonstrated ability to review audit workpapers, assess evidence quality, document conclusions, and apply SOX methodology in a manner that supports external audit reliance.
  • Strong understanding of internal control and IT governance frameworks, including SOX, COSO, COBIT, and relevant IT control leading practices.
  • Ability to communicate technical IT control issues, deficiency implications, and remediation expectations clearly to both technical and non-technical stakeholders.
  • Strong project management, analytical, organizational, problem-solving, and independent decision-making skills.

Preferred Qualifications

  • CISA strongly preferred; CPA, CIA, CISM, CISSP, CRISC, or related certifications are a plus.
  • Prior experience with a public company, financial services organization, Big Four accounting firm, or co-source/internal audit provider supporting IT SOX programs.
  • Experience supporting IT SOX programs for ERP systems, financial applications, databases, operating systems, cloud platforms, and third-party service providers.
  • Experience assessing SOX impact of system implementations, access model changes, infrastructure changes, cloud migrations, and technology transformation initiatives.
  • Knowledge of cybersecurity, identity and access management, data management, business continuity, disaster recovery, and third-party risk concepts as they relate to SOX-relevant systems.
  • Experience identifying opportunities to improve SOX efficiency through control rationalization, automation, data analytics, standardized evidence, and streamlined external audit coordination.

Critical Competencies

  • End-to-end ownership of IT SOX planning, scoping, execution, deficiency evaluation, remediation tracking, and reporting.
  • Deep technical knowledge of ITGCs, ITACs, automated controls, key reports, interfaces, privileged access, segregation of duties, and technology dependencies supporting ICFR.
  • Strong ability to evaluate control design, operating effectiveness, evidence sufficiency, deficiency severity, and financial reporting impact.
  • High-quality audit documentation, review discipline, professional skepticism, and defensible conclusions aligned with SOX methodology and external auditor expectations.
  • Strong stakeholder management skills with the ability to influence IT leaders, control owners, business process owners, co-source partners, and external auditors.
  • Clear, concise communication of IT SOX status, control issues, remediation expectations, and executive-level reporting themes.
  • Strong project management capabilities, including ownership of testing calendars, evidence requests, open items, review notes, milestones, and remediation deadlines.

Working Conditions


  • This is a hybrid position requiring a combination of onsite and remote work, based on business needs and individual performance.

  • Direct Reports

    1-3 direct reports (internal and/or co-source) supporting the SOX function.
  • The base compensation is between $130,000-$160,000 and varies by experience and location



If you are a job applicant who resides in the state of California, please review our California Employee Privacy Policy at the following link: https://regionalfinance.com/wp-content/uploads/2022/11/UPDATED-Employee-Privacy-Policy-11.2022.pdf

Regional is an equal opportunity employer and does not discriminate on the basis of race, color, religion, creed, national origin, sex (including pregnancy, childbirth, and related medical conditions), sexual orientation, gender identity, transgender status, age, disability, genetic information, veteran status, uniform service, or any other characteristic protected by applicable law (“Protected Characteristics”). Regional’s policy of non-discrimination applies to all phases of the employment process and relationship, including, but not limited to, recruitment and selection; compensation and benefits; professional development and training; promotions and opportunities; transfers; social and recreational programs; layoff; and terminations.

Similar jobs

Apply for this job