Grant Thornton LLP logo

Risk Cyber Internal Audit Manager

Grant Thornton LLP
  • New York, NY
  • $138,000–$172,500 Per Year
3 days ago

Job Description

As a member of Grant Thornton's Cybersecurity Internal Audit (IA Cybersecurity) team, you will have the opportunity to collaborate with our clients and deliver consulting and advisory services across a broad spectrum of areas related to cybersecurity. You will support clients in evaluating and enhancing their Cybersecurity risk posture through internal audits, control testing, and maturity assessments. You'll work closely with cross-functional across risk and compliance teams to assess risks, test controls, and provide actionable insights aligned with industry standards and regulatory frameworks.

As an IA Cybersecurity Risk Manager, you will get the opportunity to contribute to our clients'' business needs and grow within our practice by applying a collection of Cybersecurity capabilities, including governance, risk assessments, control testing, and technology operations for the Cybersecurity practice, all with the resources, environment, and support to help you excel.

From day one, you'll be empowered by the greater Cyber & Risk Advisory team to help clients make the moves that will help them achieve their vision and help you grow your Cybersecurity knowledge.

Your day-to-day may include:

  • Assist in planning and executing Cybersecurity internal audits, risk assessments, and control testing engagements.
  • Lead walkthroughs, interviews, and workshops with client stakeholders to understand security processes and technology environments.
  • Perform Cybersecurity control testing and Cybersecurity program capability assessments.
  • Conduct Cybersecurity maturity assessments using frameworks such as NIST CSF, CSA CCM, ISO/IEC 27001, COBIT, and HITRUST.
  • Support assessments for regulatory compliance including HIPAA, FedRAMP, GLBA, GDPR, and state-led data breach notification laws.
  • Document process, risk and control improvement considerations, develop risk-based recommendations, and develop client deliverables.
  • Identify emerging technology risks (i.e., AI, Cloud, Quantum-computing risks), deep-dive into AI model risks, supply-chain risks, document control deficiencies and develop risk mitigation strategies.
  • Develop roadmaps to help clients mitigate Cyber risks and enhance overall Cybersecurity posture.
  • Stay current on Cybersecurity trends, threat landscapes, and regulatory developments. This includes technical familiarity with common Cybersecurity tools, cloud environment/architecture, and threat vectors.
  • Provide mentorship and training to junior team members by reviewing their work, offering guidance on risk assessment methodologies, and supporting their professional development to enhance overall team capability.
  • Contribute to project management tasks such as scheduling, documentation, and status reporting to ensure smooth execution of projects.
  • Support client engagements from start to finish, which includes planning, fieldwork (including control testing), and reporting.
  • Participate in professional development activities and training sessions on regular basis.
  • Assist with business development initiatives, including proposal preparation, research, and developing client presentations.
  • Adhere to the highest degree of professional standards and strict client confidentiality.
  • Other job duties as assigned.

You have the following technical skills and qualifications:

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field is required.

  • Master's degree in Cybersecurity related field preferred

  • 5+ years of experience in Cybersecurity, internal audit, or IT risk.

  • CISA, CISSP or similar professional certifications (CISA, and CISSP) required.

  • Experience as a client serving professional for a consulting firm desired.

  • Familiarity with Cybersecurity frameworks and standards including (but not limited to):

  • NIST CSF, NIST 800-53, NIST 800-171

  • NIST AI RMF

  • CSA CCM

  • ISO/IEC 27001, ISO/IEC 27002

  • HIPAA, FedRAMP, GLBA, CCM

  • COBIT, HITRUST, PCI DSS

  • Functional understanding of IT, Cybersecurity, AI, cloud security, data protection, vulnerability management, and incident response.

  • Strong understanding of the cloud shared responsibility model and how that may impact clients.

  • Ability to communicate clearly and effectively (oral and written) with all internal and external stakeholders.

  • Ability to deliver presentations to clients on Cybersecurity risk assessments, findings, and recommendations

  • Strong project management skills and the ability to execute multiple engagements and competing priorities in a rapidly growing, fast-paced, interactive, results-based team environment.

  • Ability to travel to client locations (as needed).

The base salary range for this position is between $138,000 and $172,500. Placement within the pay range is at Grant Thornton's discretion, and it is based on multiple factors, including but not limited to, job -related knowledge/skills, experience, business needs, progression within the role, geographic location, and internal equity. At Grant Thornton, compensation decisions are dependent upon the facts and circumstances of each position and candidate.

#Hybrid

#LI-LG1

At Grant Thornton, we believe in making business more personal and building trust into every result - for our clients and you. Here, we go beyond your expectations of a career in professional services by offering a career path with more: more opportunity, more flexibility, and more support. It's what makes us different, and we think being different makes us better.

In the U.S., Grant Thornton delivers professional services through two specialized entities: Grant Thornton LLP, a licensed, certified public accounting (CPA) firm that provides audit and assurance services ― and Grant Thornton Advisors LLC (not a licensed CPA firm), which exclusively provides non-attest offerings, including tax and advisory services.

In 2025, Grant Thornton formed a multinational, multidisciplinary platform with Grant Thornton Ireland. The platform offers a premier Trans-Atlantic advisory and tax practice, as well as independent American and Irish audit practices. With $2.7 billion in revenues and more than 50 offices spanning the U.S., Ireland and other territories, the platform delivers a singular client experience that includes enhanced solutions and capabilities, backed by powerful technologies and a roster of 12,000 quality-driven professionals enjoying exceptional career-growth opportunities and a distinctive cross-border culture.

Grant Thornton is part of the Grant Thornton International Limited network, which provides access to its member firms in more than 150 global markets.

Numbers & Facts

LocationNew York, NY
IndustryAccounting and Auditing Services
Salary$138,000–$172,500 Per Year
Company Size5,000 to 9,999 employees
Year Founded1924

About Company

At Grant Thornton, our people are talented, intellectually curious and driven to make a difference. People who come to work here are empowered to contribute from their very first client engagement. They develop their skills working alongside our partners and through our formal leadership and technical training programs. In short, it is our ambition to build better business professionals faster than our competitors. If you dream of working with innovative colleagues who support and inspire you, Grant Thornton is the place for you. Visit www.GrantThornton.jobs today.

Skills

  • Accounting Certificationsunmatched
  • Artificial Intelligence (AI)unmatched
  • Auditingunmatched
  • Business Developmentunmatched
  • Business Growthunmatched
  • CISA - Certified Information Systems Auditorunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Certified Public Accountant (CPA)unmatched
  • Cloud Architectureunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Consultingunmatched
  • Control Objectives for Information and related Technology (COBIT)unmatched
  • Cross-Functionalunmatched
  • Customer Experienceunmatched
  • Customer Support/Serviceunmatched
  • Develop and Maintain Customersunmatched
  • Document Controlunmatched
  • Documentationunmatched
  • Emerging Technologyunmatched
  • ISO (International Organization for Standardization)unmatched
  • Incident Responseunmatched
  • Industry Standardsunmatched
  • Information Technology & Information Systemsunmatched
  • Information Technology/Systems Auditunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internal Auditunmatched
  • International Electro-Technical Commission (IEC)unmatched
  • Internet Securityunmatched
  • Mentoringunmatched
  • Presentation/Verbal Skillsunmatched
  • Professional Servicesunmatched
  • Program Evaluationunmatched
  • Project/Program Managementunmatched
  • Proposal Writingunmatched
  • Public Accountingunmatched
  • Quantum Computingunmatched
  • Regulationsunmatched
  • Research & Development (R&D)unmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Risk Modelingunmatched
  • Sales Presentationunmatched
  • Service Deliveryunmatched
  • Strategic Planningunmatched
  • Technical Operationsunmatched
  • Testingunmatched
  • Training/Teachingunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Willing to Travelunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder