Grant Thornton LLP (US) Logo

Grant Thornton LLP (US)

Risk Cyber Internal Audit Manager

Posted 2 Days Ago
Be an Early Applicant
Hybrid
2 Locations
138K-173K Annually
Senior level
Hybrid
2 Locations
138K-173K Annually
Senior level
Manage cybersecurity internal audit, risk assessment, control testing, and maturity assessment engagements for clients. Lead stakeholder interviews and workshops, evaluate security programs against frameworks and regulations, identify emerging technology and supply-chain risks, document findings, and develop remediation roadmaps. Deliver client presentations, mentor junior staff, support project management and business development, and maintain current knowledge of cybersecurity trends and regulatory requirements.
The summary above was generated by AI

As a member of Grant Thornton’s Cybersecurity Internal Audit (IA Cybersecurity) team, you will have the opportunity to collaborate with our clients and deliver consulting and advisory services across a broad spectrum of areas related to cybersecurity. You will support clients in evaluating and enhancing their Cybersecurity risk posture through internal audits, control testing, and maturity assessments. You’ll work closely with cross-functional across risk and compliance teams to assess risks, test controls, and provide actionable insights aligned with industry standards and regulatory frameworks.

As an IA Cybersecurity Risk Manager, you will get the opportunity to contribute to our clients' business needs and grow within our practice by applying a collection of Cybersecurity capabilities, including governance, risk assessments, control testing, and technology operations for the Cybersecurity practice, all with the resources, environment, and support to help you excel.
From day one, you’ll be empowered by the greater Cyber & Risk Advisory team to help clients make the moves that will help them achieve their vision and help you grow your Cybersecurity knowledge. 

Your day-to-day may include: 

  • Assist in planning and executing Cybersecurity internal audits, risk assessments, and control testing engagements.
  • Lead walkthroughs, interviews, and workshops with client stakeholders to understand security processes and technology environments.
  • Perform Cybersecurity control testing and Cybersecurity program capability assessments.
  • Conduct Cybersecurity maturity assessments using frameworks such as NIST CSF, CSA CCM, ISO/IEC 27001, COBIT, and HITRUST.
  • Support assessments for regulatory compliance including HIPAA, FedRAMP, GLBA, GDPR, and state-led data breach notification laws.
  • Document process, risk and control improvement considerations, develop risk-based recommendations, and develop client deliverables.
  • Identify emerging technology risks (i.e., AI, Cloud, Quantum-computing risks), deep-dive into AI model risks, supply-chain risks, document control deficiencies and develop risk mitigation strategies. 
  • Develop roadmaps to help clients mitigate Cyber risks and enhance overall Cybersecurity posture.
  • Stay current on Cybersecurity trends, threat landscapes, and regulatory developments. This includes technical familiarity with common Cybersecurity tools, cloud environment/architecture, and threat vectors. 
  • Provide mentorship and training to junior team members by reviewing their work, offering guidance on risk assessment methodologies, and supporting their professional development to enhance overall team capability.
  • Contribute to project management tasks such as scheduling, documentation, and status reporting to ensure smooth execution of projects.
  • Support client engagements from start to finish, which includes planning, fieldwork (including control testing), and reporting.
  • Participate in professional development activities and training sessions on regular basis.
  • Assist with business development initiatives, including proposal preparation, research, and developing client presentations.
  • Adhere to the highest degree of professional standards and strict client confidentiality.
  • Other job duties as assigned.

You have the following technical skills and qualifications: 

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field is required.
  • Master’s degree in Cybersecurity related field preferred 
  • 5+ years of experience in Cybersecurity, internal audit, or IT risk.
  • CISA, CISSP or similar professional certifications (CISA, and CISSP) required.
  • Experience as a client serving professional for a consulting firm desired.
  • Familiarity with Cybersecurity frameworks and standards including (but not limited to):
    • NIST CSF, NIST 800-53, NIST 800-171
    • NIST AI RMF
    • CSA CCM
    • ISO/IEC 27001, ISO/IEC 27002
    • HIPAA, FedRAMP, GLBA, CCM
    • COBIT, HITRUST, PCI DSS
  • Functional understanding of IT, Cybersecurity, AI, cloud security, data protection, vulnerability management, and incident response.
  • Strong understanding of the cloud shared responsibility model and how that may impact clients. 
  • Ability to communicate clearly and effectively (oral and written) with all internal and external stakeholders.
  • Ability to deliver presentations to clients on Cybersecurity risk assessments, findings, and recommendations
  • Strong project management skills and the ability to execute multiple engagements and competing priorities in a rapidly growing, fast-paced, interactive, results-based team environment.
  • Ability to travel to client locations (as needed).

The base salary range for this position is between $138,000 and $172,500. Placement within the pay range is at Grant Thornton’s discretion, and it is based on multiple factors, including but not limited to, job -related knowledge/skills, experience, business needs, progression within the role, geographic location, and internal equity. At Grant Thornton, compensation decisions are dependent upon the facts and circumstances of each position and candidate. 

#Hybrid 

#LI-LG1

About UsAt Grant Thornton, we believe in making business more personal and building trust into every result – for our clients and you. Here, we go beyond your expectations of a career in professional services by offering a career path with more: more opportunity, more flexibility, and more support. It’s what makes us different, and we think being different makes us better. 

In the U.S., Grant Thornton delivers professional services through two specialized entities: Grant Thornton LLP, a licensed, certified public accounting (CPA) firm that provides audit and assurance services ― and Grant Thornton Advisors LLC (not a licensed CPA firm), which exclusively provides non-attest offerings, including tax and advisory services.

In 2025, Grant Thornton formed a multinational, multidisciplinary platform with Grant Thornton Ireland. The platform offers a premier Trans-Atlantic advisory and tax practice, as well as independent American and Irish audit practices. With $2.7 billion in revenues and more than 50 offices spanning the U.S., Ireland and other territories, the platform delivers a singular client experience that includes enhanced solutions and capabilities, backed by powerful technologies and a roster of 12,000 quality-driven professionals enjoying exceptional career-growth opportunities and a distinctive cross-border culture.

Grant Thornton is part of the Grant Thornton International Limited network, which provides access to its member firms in more than 150 global markets. About the TeamThe team you’re about to join is ready to help you thrive. Here’s how:
• Whether it's your work location, weekly schedule, or flex time off, we empower you with the options to work the way that it best serves your clients and your life. Consistent with the firm's hybrid work model, this position will require in-person attendance at least three days per week, either at a GT office or client site.   
• Here, you are supported to prioritize your overall well-being through work-life integration options that work best for you and those in your household. 
• We understand that your needs, responsibilities and experiences are different — and we think that’s a good thing. That’s why we support you with personalized and comprehensive benefits that recognize and empower all the identities, roles and aspirations that make you, well, you. See how at  www.gt.com/careers
• When it comes to inclusion, we are committed to doing more than checking boxes. Explore all the ways we’re taking action for diversity, equity & inclusion at  www.gt.com/careers

Here’s what you can expect next: 
If you apply and are selected to interview, a Grant Thornton team member will reach out to you to schedule a time to connect. We encourage you to also check out other roles that may be a good fit for you or get to know us a little bit better at   www.gt.com/careers

Benefits:
We understand that your needs, responsibilities and experiences are different, and we think that’s a good thing. That’s why we support you with personalized and comprehensive benefits that recognize and empower all the identities, roles and aspirations that make you, well, you. For an overview of our benefit offerings, please visit: https://www.grantthornton.com/careers/rewards-and-benefits
  • Benefits for internship positions: Grant Thornton interns are eligible to participate in the firm’s medical, dental and vision insurance programs and the firm’s employee assistance program. Interns also receive a minimum of 72 hours of paid sick leave, and are paid for firm holidays that fall within their internship period.
  • Benefits for seasonal employee positions: Grant Thornton seasonal employees are eligible to participate in the firm’s medical, dental and vision insurance programs and the firm’s employee assistance program. Seasonal employees may also be eligible to participate in the firm’s 401(k) savings plan and employee retirement plan in accordance with applicable plan terms and eligibility requirements. Seasonal employees receive a minimum of 72 hours of paid sick leave. 
Grant Thornton employees may be eligible for a discretionary, annual bonus based on individual and firm performance, subject to the terms, conditions and eligibility criteria of the applicable bonus plan or program. Interns and seasonal employees are not eligible for bonus compensation.

Additional Details:         
It is the policy of Grant Thornton to promote equal employment opportunities. All personnel decisions (including, but not limited to, recruiting, hiring, training, working conditions, promotion, transfer, compensation, benefits, evaluations, and termination) are made without regard to race, color, religion, national origin, sex, age, marital or civil union status, pregnancy or pregnancy-related condition, sexual orientation, gender identity or expression, citizenship status, veteran status, disability, handicap, genetic predisposition or any other characteristic protected by applicable federal, state, or local law.
 
Consistent with the Americans with Disabilities Act (ADA) and applicable state and local laws, it is the policy of Grant Thornton LLP to provide reasonable accommodation when requested by a qualified applicant or employee with a disability, unless such accommodation would cause an undue hardship. The policy regarding requests for reasonable accommodation applies to all aspects of employment, including the application process. To make an accommodation request, please contact [email protected]

For Los Angeles Applicants only: We will consider for employment all qualified Applicants, including those with Criminal Histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance.

For Massachusetts Applicants only: It is unlawful in Massachusetts to require or administer a lie detector test as condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability. Gran Thornton does not require or administer lie detector tests as a condition of employments or continued employment.   

Grant Thornton LLP (US) Iselin, New Jersey, USA Office

186 S Wood Ave, 4th Floor, Iselin, United States, 08830

Grant Thornton LLP (US) New York, New York, USA Office

757 Third Avenue, 9th Floor, New York, NY 10017, New York, United States, 10017

Similar Jobs

5 Hours Ago
Hybrid
Jersey City, NJ, USA
Mid level
Mid level
Financial Services
Designs, develops, tests, troubleshoots, and maintains secure, scalable cloud-native software solutions. Creates architecture and design artifacts, develops Python and data-intensive applications on AWS and Databricks, builds AWS Glue jobs, and improves system reliability through data analysis, automation, and responsible AI-assisted development. Collaborates within an agile environment while supporting software delivery, security, resiliency, and operational stability.
Top Skills: AgileAirflowSparkAWSAws ComputeAws GlueAws NetworkingAws ObservabilityAws StorageCi/CdDatabase Query LanguagesDatabricksIamPython
6 Hours Ago
Hybrid
Iselin, NJ, USA
87K-168K Annually
Junior
87K-168K Annually
Junior
Fintech • Financial Services
Supports cybersecurity Identity and Access Management through data engineering, analytics, and machine learning. Responsibilities include building and operating data pipelines, models, dashboards, and API integrations; developing, testing, deploying, and monitoring ML-enabled solutions; evaluating model performance and drift; ensuring compliance with security, privacy, regulatory, and ethical requirements; using AI-assisted development tools; and communicating technical recommendations to IAM stakeholders and business partners.
Top Skills: AlteryxAPIsClaude CodeCursorDevinGitGithub CopilotGoogle Cloud PlatformLlmsNumpyPandasPower BIPythonPyTorchRagScikit-LearnSQLTableauTensorFlowVertex Ai
6 Hours Ago
Hybrid
Iselin, NJ, USA
159K-305K Annually
Senior level
159K-305K Annually
Senior level
Fintech • Financial Services
Leads technology control modernization by redesigning controls, aligning definitions with RCSA, and embedding governance, security, and automation across the technology lifecycle. Advises senior leaders on complex and emerging risks, evaluates control environments, monitors effectiveness and compliance data, supports remediation, reports risk outcomes, and mentors control management teams. Collaborates across business lines to implement risk mitigation strategies, address regulatory requirements, and improve automated configuration monitoring.
Top Skills: AIAutomationConfiguration MonitoringIt Systems SecurityRcsa

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account