IT Infrastructure Audit Director

Sumitomo Mitsui Banking CorporationCharlotte, NC
Hybrid

About The Position

SMBC is seeking an experienced Audit Director with a minimum of 10 years’ experience in the banking and finance/technology industry to conduct audit coverage for the firm's infrastructure and other related technology controls. Reporting to the Infrastructure Audit Team Head, the Audit Director will be responsible for (i) conducting infrastructure and other related technology audits, ensuring work is performed in accordance with IIA standards and Internal Audit Department (IAD) policies and procedures, and (ii) supporting the Infrastructure Audit Team Head in the execution of their duties. In addition, they will (i) support IAD Management team in helping to identify areas of coverage for planning, development, implementation, and maintenance of an internal audit program covering infrastructure and technology related areas across the Americas Division and (ii) conduct regular continuous monitoring activities covering infrastructure and technology related risks and related processes and controls within a prescribed timeframe. When acting as the Auditor in Charge, the individual will be assigned an audit team (approximately 2-4 individuals) depending on the size and complexity of the audit.

Requirements

  • Recommended minimum of 10 years of infrastructure audit experience in the banking and/or technology industry.
  • Knowledge and experience in various technology infrastructure platforms, e.g. Linux/Unix, Windows, Virtualization, Cloud, Middleware, Database, etc.
  • Knowledge and experience in various technology domains, including IT Change, SDLC, Asset Management, IT Governance, Incident and Problem Management, Access Management, etc.
  • Knowledge of cybersecurity related risks (i.e., Governance, Identify, Protect, Detect, Respond, Recover, Supply Chain, and Demand Management).
  • Knowledge of industry relevant standards (e.g., NIST, ITIL, COBIT) and related regulatory expectations (e.g., NYS DFS 500, FFIEC).
  • Knowledge of audit techniques, risk and internal controls assessment, and workpaper standards.
  • Ability to manage and execute audits, from planning to audit closing.
  • Strong strategic thinking skills including the ability to identify and assess technology related risks.
  • Ability to act as trusted advisor to senior management using discretion and sound judgment in identifying, analyzing, and reporting results.
  • Excellent communication (both verbal and written), presentation and professional skills including the ability to interact effectively at all levels within the organization.
  • Enthusiastic and self-motivated, effective under pressure and willing to take personal responsibility/accountability.
  • Bachelor’s Degree in Information Technology, MIS, Finance, or related field.
  • Working knowledge of Microsoft Office Suite (Outlook, Excel, Word, PowerPoint).

Nice To Haves

  • Advanced degree is a plus.

Responsibilities

  • Conduct regular audits of infrastructure and technology related areas assessing adherence to firm and regulatory requirements and assessing design, operating effectiveness and sustainability of associated controls.
  • Create audit issues and reports that clearly articulate results, conclusions and recommendations for review with senior audit management and auditees.
  • Challenge the ongoing coverage of infrastructure and technology related areas and present ideas for improvement.
  • Facilitate risk issue tracking to promote timely remediation.
  • Track and validate closure of issues raised by IAD, external auditors, regulators, and self-identified by stakeholders, including recommending additional actions when necessary.
  • Work collaboratively with colleagues and auditees to identify risk concerns and agree reasonable solutions.
  • Forge strong partnerships with colleagues in other technology and control functions including legal, compliance, data security and risk management to promote front-to-back collaboration across risk assessment and findings remediation.
  • Partner with audit colleagues in other business verticals and/or geographies to share best practices and drive greater consistency.
  • Seek out opportunities to engage with stakeholders outside of formal audit periods to drive deeper relationships.
  • Stay up-to-date with evolving industry/regulatory changes impacting the business and participate in appropriate control forums.
  • Conduct regular Continuous Monitoring activities and auditable entity updates.
  • Recognize the confidential nature of IAD communications and access to information; exercise discipline in protecting the confidentiality and security of information in accordance with IAD policies and procedures.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service