Senior Manager, IT Audit, Cyber

Scotiabank•Dallas, TX
•Onsite

About The Position

As the 3rd Line of Defence, Internal Audit provides enterprise-wide, independent, and objective assurance over the design and operations of the Bank’s internal controls, risk management and governance processes. We are professionals who thrive in a challenging environment and work with management to find solutions to address control weaknesses. The Senior Audit Manager leads and supports risk-based internal audit activities across IT Infrastructure and Cybersecurity, applying strong technical expertise, sound judgment, and disciplined engagement management to execute the Audit Department’s global mandate. The role ensures audit strategies, plans, testing, and reporting are delivered in compliance with governing regulations, internal policies, professional standards, and procedures. The Senior Audit Manager is a dynamic, innovative, and trusted advisor who uses data and cybersecurity expertise to deliver industry-leading assurance and actionable insights. The role communicates complex technical risks clearly to senior management, regulators, and other stakeholders, while coaching audit teams and helping safeguard the Bank and its customers.

Requirements

  • University/Post secondary degree in Business or equivalent.
  • Relevant Audit or business certifications. e.g., CISA, CISSP, CISM).
  • At least 7+ years of relevant experience.
  • Working knowledge of the operations and regulatory environments for each unit as applicable.
  • Proven ability to work in high levels of ambiguity and in a rapidly changing environment.
  • Highly proficient at applying Scotiabank methodology and using risk-based auditing standards and practices.
  • Strong analytical skills in the use of data analytics or visualization tools.
  • Ability to execute and supervise multiple projects at any given time.
  • Highly developed interpersonal and communication skills (verbal and written).
  • Strong people management and coaching/development skills.
  • Curiosity mindset.
  • Bachelor’s degree in cybersecurity, information technology, computer science, engineering, accounting, business, or a related discipline; relevant advanced degree is an asset.
  • Technical: Significant experience auditing or assessing cybersecurity and technology risks and controls, with sufficient technical depth to evaluate complex environments, challenge evidence, and apply applicable regulatory requirements and recognized frameworks.
  • Management: Demonstrated ability to lead multiple risk-based audits or projects, manage scope, budgets, resources, timelines, quality, and issue escalation, and coach diverse teams in a dynamic environment.
  • Communication: Exceptional written, verbal, presentation, negotiation, and influencing skills, including the ability to translate complex technical matters into concise, actionable messages for technical teams, business leaders, senior executives, Audit Committees, and regulators.
  • Strong critical thinking, professional skepticism, data analysis, relationship management, and sound judgment, with the ability to identify root causes and develop practical, risk-based recommendations.

Nice To Haves

  • Relevant certifications such as CISSP, CISA, CISM, CRISC, CIA, or cloud security credentials are preferred.

Responsibilities

  • Acts primarily as Officer in Charge (OIC) for assigned audits and may serve as Audit Principal (AP) for low- to medium-complexity audits, demonstrating accountability for audit quality, scope, timelines, resources, stakeholder engagement, and team performance.
  • Works with other audit teams as required.
  • Carries out specific projects.
  • As OIC/AP, oversees the execution, planning, and reporting. Obtains a thorough understanding of the end-to-end business/unit/process and associated risks, develops an appropriate risk-based audit approach and schedules timing and resources.
  • Ensures audit results are gathered and determines the root cause of the problem. Prepares and/or reviews audit results and findings for presentation to management. Follows-up for corrective action/progress against any reported issues. Ensures relevant information that impacts other audit function areas is shared.
  • Supports a client focused culture throughout their team to deepen client relationships and leverage broader Bank relationships, systems, and knowledge.
  • Understands how the Bank’s risk appetite and risk culture should be considered in day-to-day activities and decisions.
  • Plans, documents, and seeks agreement in advance to the project approach and confirms conclusions upon completion in writing.
  • Ensures Scotiabank standards and the Institute of Internal Auditors (IIA) Code of Ethics are maintained in completion of all assignments.
  • Builds and maintains strong relationships with internal and external stakeholders and regulators as required.
  • Interacts and coordinates with other groups involved. Completes timely review of workpapers, ensuring internal control weaknesses are clearly documented with recommendations addressing the root cause and are communicated timely to management.
  • Supports ongoing monitoring activities to stay abreast of changes (business/industry/regulatory), emerging risks, and themes or systemic issues that may impact the risk assessment of the audit universe and the audit plan.
  • Supports a high-performance environment and implements a people strategy that attracts, retains, develops, and motivates their team by fostering an inclusive work environment and using a coaching mindset and behaviours; communicating vison/values/business strategy; and managing succession and development planning for the team.
  • Meets Department training requirements.
  • Performs risk assessments of complex IT and cybersecurity environments, including identity and access management, network and endpoint security, cloud security, security operations, vulnerability management, data protection, application security, resilience, general IT controls, automated controls, and underlying infrastructure.
  • Evaluates the design and operating effectiveness of cybersecurity and technology controls using risk-based testing, data analytics, technical evidence, and recognized regulatory and industry frameworks; challenges control owners constructively and translates technical observations into clear business and risk implications.
  • Leads, coaches, and reviews the work of multidisciplinary audit teams; sets clear expectations, provides timely feedback, develops technical capability, resolves delivery issues, and promotes consistent, high-quality execution.
  • Communicates audit scope, status, findings, and risk implications with clarity and influence through concise workpapers, reports, presentations, and discussions tailored to technical teams, business leaders, senior executives, Audit Committees, and regulators.
  • Accountable for specific audit work in assigned audits.
  • Audit projects vary in complexity, involvement, and number.

Benefits

  • flexible benefit programs are designed to help support your unique family, financial, physical, mental, and social health needs.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service