Position Summary
Loya Insurance is seeking a hands-on IT Audit Lead to build and lead a scalable technology audit and assurance capability. The role will provide independent, risk-based assurance over the technology controls that support financial reporting, cybersecurity, data privacy, regulatory compliance, and critical business operations.
The successful candidate will combine strong audit judgment with enough technical depth to work credibly with engineers, security leaders, data teams, and senior executives.
Key Responsibilities
· Assist with the develop and maintain a risk-based technology audit universe and annual assurance plan aligned with enterprise risk and regulatory priorities.
· Lead complex technology audits from planning and scoping through testing, reporting, and remediation follow-up.
· Assess IT general controls and technology risks across identity and access management, privileged access, change management, infrastructure, cloud, applications, cybersecurity, resilience, and third parties.
· Evaluate technology controls supporting a SOX 404 environment, Gramm-Leach-Bliley Act (GLBA), NAIC cybersecurity expectations, financial reporting, privacy, and critical operations.
· Establish practical audit methodology, evidence standards, workpaper expectations, repeatable testing, issue validation, and risk reporting.
· Translate technical observations into clear business risk, root cause, impact, accountable ownership, and actionable remediation recommendations.
· Partner constructively with Technology, Cybersecurity, Compliance, Finance, Data, and AI teams while maintaining third-line independence.
· Use data analytics, scripting, APIs, GRC tooling, or other automation to expand coverage and reduce dependence on manual sampling.
· Provide concise reporting on technology risk themes, audit results, remediation progress, emerging threats, and significant initiatives to senior leadership.
Required Qualifications and Skills
· Bachelor’s degree in information systems, computer science, accounting, finance, cybersecurity, business, or a related field; equivalent relevant experience may be considered in lieu of degree.
· Eight or more years of progressive experience in IT audit, technology risk, cybersecurity assurance, technology controls, or a closely related discipline.
· Demonstrated experience leading complex technology audits and managing work from risk assessment through final reporting and issue follow-up.
· Strong working knowledge of IT general controls, including logical access, privileged access, change management, technology operations, backup and recovery, and third-party technology risk.
· Ability to assess control design and operating effectiveness, evaluate evidence, identify root cause, and develop risk-based conclusions.
· Strong written, verbal, workshop facilitation, and presentation skills, including the ability to explain technical risk in business terms.
· Sound judgment, professional skepticism, independence, and the ability to operate effectively in a changing environment with limited existing structure.
Preferred Qualifications and Skills
· Experience building or enhancing the maturity of an IT audit, technology assurance, or technology risk program.
· Insurance or other regulated financial-services experience, including exposure to a SOX 404 environment, GLBA, NAIC cybersecurity requirements, or comparable regulatory frameworks.
· Working knowledge of modern IT environments and related controls, including cloud infrastructure, network and endpoint security, identity and privileged access management (IAM/PAM), vulnerability management, system development and change management (SDLC/DevOps), APIs, and cybersecurity practices.
· Experience assessing data governance, privacy, artificial intelligence, model risk, or automated decision systems.
· Hands-on experience with audit analytics or automation using SQL, Python, PowerShell, APIs, BI tools, or GRC platforms.
· Experience presenting to senior executives, or a board-level audience.
· CISA strongly preferred. CISSP, CIA, CRISC, CPA, CCSK, or relevant cloud/security certifications are additional strengths; technical depth and judgment should take precedence over certification count.
Core Competencies
· Builder mindset and practical execution
· Risk-based thinking and disciplined professional judgment
· Technical curiosity and learning agility
· Clear, concise communication
· Influence without compromising independence
· Constructive challenge and strong stakeholder management
#ADMIN
Pay: $115,000.00 - $145,000.00 per year
Education:
Experience:
- IT auditing: 8 years (Required)
Work Location: In person