- Company Name
- Mars
- Job Title
- Global IT Audit Senior Manager - Cyber Security & Data Privacy
- Job Description
-
**Job Title:** Global IT Audit Senior Manager – Cyber Security & Data Privacy
**Role Summary:**
Senior leader responsible for overseeing complex IT internal audit work across all business segments, with primary focus on data privacy and cyber‑security. Leads audit and consulting projects, provides strategic input to the risk‑based annual internal audit plan, and serves as a key partner to cyber‑security and privacy leadership.
**Expactations:**
- Minimum 8 years IT audit experience; ≥ 5 years in a Big 4 accounting or IT‑consulting firm.
- Deep expertise in privacy principles, regulations (GDPR, CCPA, LGPD, PIPL, etc.) and cyber‑security control frameworks (NIST, ISO 27001, CIS Controls).
- Proven ability to lead multi‑disciplinary audit teams, communicate findings to senior management, and build collaborative relationships.
- Fluent written and spoken English; additional languages are a plus.
**Key Responsibilities:**
- Develop and maintain the data‑privacy and cyber‑security audit plan; contribute to the overall risk‑based internal audit strategy.
- Oversee IT Audit Managers executing audits of cyber‑security, data privacy, emerging technologies, and third‑party vendor risk.
- Partner with Cybersecurity and Privacy leaders to align audit scope, share results, and address risks.
- Lead planning, scoping, and execution of audit/consulting engagements; design new work programs for privacy and security.
- Supervise multiple concurrent audit engagements; provide quality reviews of workpapers and reports.
- Conduct IA risk assessments for cyber‑security and privacy; participate in governance forums for emerging tech controls.
- Deliver audit findings through clear written reports and oral presentations to senior management.
- Coach business units on governance, risk, and control improvements; foster productive relationships across the organization.
**Required Skills:**
- Expert knowledge of privacy laws and principles; hands‑on experience with DSAR, DPIA, SCC, cross‑border data transfers.
- Proficiency evaluating technical cyber controls: network architecture, EDR, vulnerability management, cloud security, SOC operations.
- Strong understanding of security frameworks (NIST, ISO 27001, CIS), and of network, API, AI model, OS, and OT security.
- Experience testing privacy controls, issue management, and remediation.
- Excellent analytical and report‑writing abilities; capable of translating complex technical issues into actionable insights.
- Strong stakeholder management, teamwork, and consulting skills.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Systems, Accounting, Business Administration, or related field.
- Preferred certifications: CISA, CISSP, CISM, CRISC, ISO 27001 Lead Auditor, CIPP/E, CIPM, or equivalent privacy/security credentials.