KBR logo

IT Audit Manager

KBR
  • Arlington, VA
    2 days ago

    Job Description

    Title:

    IT Audit Manager

    KBR is seeking an experienced IT Audit Manager to join the Internal Audit & Advisory team. This role is responsible for leading and overseeing the organization's IT Sarbanes-Oxley (SOX) compliance program, including the planning, execution, and reporting of IT General Controls (ITGC), application controls, automated controls, interface controls, and Software Development Lifecycle (SDLC) control testing. The IT Audit Manager will partner closely with IT leadership, business process owners, internal controls teams, and external auditors to ensure an effective control environment, timely remediation of identified deficiencies, and ongoing compliance with SOX 404 requirements.

    The ideal candidate brings strong experience managing IT SOX programs within complex global organizations, demonstrated expertise in IT control frameworks and risk assessment methodologies, and a proven ability to lead and develop audit teams while driving high-quality, risk-based audit execution.

    Key Responsibilities

    • Manage the annual IT SOX compliance program, including planning, execution, monitoring, and reporting activities across IT control domains.
    • Develop and maintain risk-based testing strategies and audit plans covering IT General Controls (ITGCs), application controls, automated controls, interface controls, and SDLC controls.
    • Oversee walkthroughs, control assessments, and testing activities to evaluate the design and operating effectiveness of key IT controls.
    • Lead and review testing of ITGCs, including access management, change management, IT operations, and system development controls.
    • Direct testing and evaluation of SDLC controls, including development approvals, testing evidence, release management, and production migration processes.
    • Oversee testing of key automated controls, application controls, system interfaces, and management reports used in financial reporting processes.
    • Manage and mentor onshore and offshore IT audit and SOX testing teams, ensuring consistency, quality, and adherence to established audit methodologies.
    • Review workpapers, testing documentation, and audit evidence to ensure accuracy, completeness, and compliance with professional standards.
    • Partner with IT management, Internal Controls, business process owners, and external auditors to coordinate testing activities, address control issues, and facilitate audit reliance.
    • Evaluate identified control deficiencies, assess potential SOX impact and severity, and provide recommendations for corrective actions.
    • Monitor remediation activities, validate the effectiveness of corrective actions, and track resolution through completion.
    • Prepare and present status reports, executive dashboards, testing summaries, and risk updates to management and key stakeholders.

    Basic Qualifications

    Education & Experience

    • Bachelor's degree in Information Systems, Information Technology, Computer Science, Accounting, Finance, Audit, or a related field.
    • Minimum of 10 years of progressive experience in IT audit, IT risk management, IT controls, IT compliance, or related disciplines.
    • Minimum of 4 years of experience leading and managing IT SOX compliance programs and audit teams.
    • Experience conducting and overseeing SOX 404 testing within large, complex, and global organizations.
    • Demonstrated experience leading cross-functional initiatives involving IT, Internal Controls, Finance, and external audit stakeholders.
    • Experience managing distributed, onshore, and offshore resources in a testing or audit environment.

    Technical & Leadership Skills

    • Deep knowledge of IT General Controls (ITGCs), including access management, change management, IT operations, and system development controls.
    • Strong expertise in SOX 404 compliance requirements, control testing methodologies, and internal control frameworks.
    • Experience evaluating and testing application controls, automated controls, interface controls, and system-generated reports.
    • Strong understanding of Software Development Lifecycle (SDLC) processes and associated control requirements.
    • Proven ability to assess control design and operating effectiveness, identify risks, and evaluate control deficiencies.
    • Strong analytical, problem-solving, and risk assessment skills.
    • Ability to manage multiple priorities, projects, and deadlines in a fast-paced environment.
    • Effective leadership, coaching, and team development capabilities.
    • Excellent verbal and written communication skills with the ability to present complex technical and compliance matters to diverse audiences.
    • Strong stakeholder management and relationship-building skills across business and technology functions.

    Preferred Qualifications

    • Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), or equivalent professional certification.
    • Prior experience within a publicly traded organization with mature SOX compliance requirements.
    • Experience supporting external audit reliance strategies and coordinating with external auditors.
    • Knowledge of leading control frameworks and governance standards, including COBIT, NIST, and related IT risk frameworks.
    • Experience supporting digital transformation, ERP implementations, cloud environments, or large-scale technology change initiatives.
    • Advanced experience with data analytics, audit automation, or continuous controls monitoring tools.

    Additional Compensation: KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels, per internal policy or contractual designation. Additional compensation may be in the form of sign on bonus, relocation benefits, short term incentives, long term incentives, or discretionary payments for exceptional performance.

    Benefits: KBR offers a selection of competitive lifestyle benefits which could include a 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule. We support career advancement through professional training and development.

    Belong, Connect and Grow at KBR

    At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team's philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver - Together.

    KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

    Numbers & Facts

    LocationArlington, VA
    IndustryConstruction - Industrial Facilities and Infrastructure
    Company Size10,000 employees or more
    Year Founded1998
    Websitehttps://www.kbr.com/en

    About Company

    When you become part of the When you become part of the KBR team, your opportunities are endless. As a leading global technology, engineering, procurement and construction company serving the hydrocarbons and government services industries. For decades it has been the company that customers turn to for their most challenging assignments.

    With operations in 40 countries, KBR has more than 25,000 people delivering services to customers in over 70 countries. Together they represent an unmatched reservoir of talent and experience in a wide range of markets.

    Whatever the assignment, no matter how complex or demanding, KBR can marshal resources across every product line to respond quickly and effectively to changing markets and customer needs.

    Whether it's providing the technology and consulting know-how to develop our customers' valuable assets; designing and constructing the infrastructure and facilities to develop energy resources in some of the world's more remote and challenging locations; providing support and services for men and women of their countries' armed forces; or navigating the intricacies of undertaking major projects in geopolitically or culturally sensitive environments, our clients depend on KBR because they know that We Deliver.

    Join us and you'll be part of a dynamic, elite team of professionals who understand what it takes to get a job done and has the experience, knowledge and determination to succeed.”

    Skills

    • Accountingunmatched
    • Analysis Skillsunmatched
    • Auditingunmatched
    • Automationunmatched
    • Business Processesunmatched
    • Business Skillsunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Change Managementunmatched
    • Cloud Computingunmatched
    • Coachingunmatched
    • Communication Skillsunmatched
    • Computer Scienceunmatched
    • Control Objectives for Information and related Technology (COBIT)unmatched
    • Corrective Actionunmatched
    • Cross-Functionalunmatched
    • Data Analysisunmatched
    • Design Evaluationunmatched
    • Documentationunmatched
    • ERP (Enterprise Resource Planning)unmatched
    • External Auditunmatched
    • Financial Auditunmatched
    • Financial Reportingunmatched
    • Information Technology & Information Systemsunmatched
    • Information Technology/Systems Auditunmatched
    • Internal Auditunmatched
    • Leadershipunmatched
    • Management of Information Systems/Technology (MIS)unmatched
    • Mentoringunmatched
    • Multitaskingunmatched
    • Offshoringunmatched
    • Presentation/Verbal Skillsunmatched
    • Problem Solving Skillsunmatched
    • Program Planningunmatched
    • Quality Assurance Methodologyunmatched
    • Regulatory Complianceunmatched
    • Release Management/Engineeringunmatched
    • Reporting Dashboardsunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • SOX 404unmatched
    • Sarbanes-Oxley Act (SOX)unmatched
    • Software Development Lifecycle (SDLC)unmatched
    • Status Reportsunmatched
    • Strategic Planningunmatched
    • Systems Administration/Managementunmatched
    • Team Buildingunmatched
    • Technical Leadershipunmatched
    • Technical Presentationunmatched
    • Test Automationunmatched
    • Test Plan/Scheduleunmatched
    • Test Strategyunmatched
    • Testingunmatched
    • Time Managementunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Writing Skillsunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder