MANAGER OF AUDIT II-IT/CYBERSECURITY
WHAT IS THE OPPORTUNITY?
The Audit Manager II (AM II) of Cybersecurity and Infrastructure will support the Director IA, CNB Cybsercurity and Infrastructure, and the MD IA, US Technology in providing independent, objective assurance over the design and operation of CNB’s IT risk management practices, governance processes and the system of internal controls. The position will facilitate audit execution relating to Cybersecurity and Infrastructure. This includes leading and executing audit activities with an IT audit scope where there is an impact to CNB and its subsidiaries / management affiliates. Examples of audit subject matter includes cybersecurity operations, data protection and data privacy, identity and access management, IT risk management, security architecture and engineering, cloud computing, data center operations, data communications and networks, server virtualization, data storage and database technologies. Will also provide support in responding to external auditors and US regulators (FRBNY, OCC) and to meet the evolving demands of the US regulatory environment and heightened expectations of internal audit. This includes the coordination of IT related regulatory continuous monitoring, coordination of IA responses to US regulatory examinations, and the verification of CNB IT regulatory issues.
Internal Audit and CRR
The Internal Audit and CRR team provides objective and independent assurance services to support the bank in its mission and to help achieve its objectives through proactive risk management. The focus is on ensuring business activities remain safe, compliant and well-positioned for future opportunity and sustainable growth.
WHAT WILL YOU DO?
- Executes on the annual Audit Plan for CNB IT Cybersecurity and Infrastructure audit universe, ensuring that audits conform to local and global regulatory and internal audit requirements.
- Perform Vulnerability assessment and penetration testing methodologies and processes for the web, thick client, and mobile applications
- Implement the execution of the audit plan and ensure effective audit practices for traditional and continuous audits. Collaborate with broader Global RBC and CUSO IT teams and departments to achieve the plan (where needed).
- Make recommendations to clients on control deficiencies and follows up to ensure significant deficiencies are corrected. Assist business management to develop appropriate action plans to address identified deficiencies, and ensure corrective actions are implemented in a timely manner to effectively address the issues.
- Plan and execute on moderate to complex and confidential/special audit projects enterprise wide as requested by senior management of the Bank.
- Communicate trends in risk and control issues to senior management on the results of ongoing reviews of the businesses that are key relationships, or any other business as requested.
- Provide support for CNB IT and US-wide regulatory requests, responses and meetings.
- Raise the technical knowledge of the group through various courses, seminars and in-house training in the areas of Information Technology for existing and emerging technologies, and related risk management framework, compliance and audit techniques.
- Raise the technical and business knowledge of the group through IT and business auditor cross integration and allocation. Identify new opportunities that would result in cross-team collaboration, develop talent for future roles and create a mutually beneficial situation that allows business and IT auditors to cross pollinate experience and knowledge.
- Build, direct, counsel, and instruct staff assigned to an engagement and review audit plan, findings and reports for sufficient scope and for accuracy.
WHAT DO YOU NEED TO SUCCEED
Must-Have*
- Bachelor’s Degree accounting, finance, business, social science or related field
- Minimum 5 years banking / audit experience within Information Technology, with Cybersecurity and Infrastructure audit experience.
- Minimum 3 years of business experience in a financial institution or technology company, dealing with multiple business platforms, business processes, geographies, and legal entities
- CISA – Certified Information Systems Auditor
- CISM – Certified Information Security Manager
- CIA – Certified Internal Auditor
- CEH-Certified Ethical Hacker
Skills and Knowledge
- Understanding of network, desktop and server technologies, including experience with network intrusion methods, network containment, segregation techniques, and technologies such as Intrusion Detection Systems (IDS) and Intrusion Protection Systems (IPS)
- Experience with Windows Active Directory and related exploits / Misconfigurations
- Experience with SIEM technologies, log management tools, security analytics platforms.
- Security with the software development lifecycle
- Data Loss Prevention (DLP)
- Familiarity with Microsoft SQL database functionality and exploitation
- Knowledge of cloud architecture designs and patterns in multi-cloud and hybrid cloud environments
- Understanding insider threat detection, network security, and traffic analysis hunting for malicious activity and initiating response actions.
- Experience with open-source security tools including Wireshark, Nmap, burp, and Kali.
- Demonstrable Threat hunting experience
- Understanding of advanced persistent threat (APT)
Compensation
Starting base salary: $101,231 – $172,355 per year. Exact compensation may vary based on skills, experience, and location. This job is eligible for bonus and/or commissions.
*To be considered for this position you must meet at least these basic qualifications
The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job.
Benefits and Perks
At City National, we strive to be the best at whatever we do, including the benefits and perks we offer our colleagues. Get an inside look at our Benefits and Perks.
INCLUSION AND EQUAL OPPORTUNITY EMPLOYMENT
City National Bank is an equal opportunity employer committed to diversity and inclusion. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status or any other basis protected by law.
ABOUT CITY NATIONAL
We start with a basic premise: Business is personal. Since day one we’ve always gone further than the competition to help our clients, colleagues and community flourish. City National Bank was founded in 1954 by entrepreneurs for entrepreneurs and that legacy of integrity, community and unparalleled client relationships continues to drive phenomenal growth today. City National is a subsidiary of Royal Bank of Canada, one of North America’s leading diversified financial services companies.
Equal Opportunity Employer Minorities/Women/Protected Veterans/Disabled