Cloud Technology Audit - Executive Director
As a Audit Director within our Cloud Audit Team, you will play a pivotal role in assessing the adequacy of the control environments for our firm's cloud and AI environments. Your responsibilities will include supporting the subject matter expert program for Cloud audit capabilities within the department, conducting end-to-end cloud and product audits in a risk-focused manner, and ensuring high standards in accordance with department and professional standards. Additionally, you will also provide subject matter expertise on critical AI and cyber risks on cloud as the firm increases adoption of AI products and solutions.
Job responsibilities
- Support the subject matter expert program for Cloud and AI audit capabilities within the department
- Drive end-to-end cloud audits in a risk focused manner and to a high standard in accordance with department and professional standards
- Support integrated reviews of AI and cyber related risks for the firms technology products and business applications.
- Provide industry perspectives on emerging cloud, AI, and agentic technology and cyber risks relevant to the firms technology environment.
- Engage in clear communication with stakeholders relating to the audit scope, risks and issues
- Evaluate, test and report on the adequacy and effectiveness of the cloud control environment
- Analyze Risks and proactively identify the root-cause of issues with a view to providing recommendations for improvement where weaknesses are identified
- Finalize Audit findings and use judgment to provide an overall opinion on the control environment
- Drive communication of audit results and issues in a clear and concise manner, both verbally and in writing to Audit management and senior stakeholders
- Build and maintain key relationships with stakeholders and colleagues, establishing a culture of engagement while adding value, effective teamwork and innovative thinking
Required qualifications capabilities and skills
- Extensive combined cloud and AI experience
- Bachelor's degree (or relevant financial services experience)
- Good deep understanding of Generative AI and Agentic security risks such as prompt injection, data poisoning etc.
- Experience working with either threat modeling, risk assessing or auditing cloud technologies (AWS, Google and Azure), Generative AI/agentic systems and tool integrations (A2A, MCP)
- Recognized cloud security certification (CCSP, CCSK, AWS certifications etc.)
- Solid understanding of internal control concepts with the ability to evaluate and determine the adequacy of controls by considering business and technology risks in an integrated manner.
- Knowledge of system development life cycle concepts with an ability to quickly learn a complex, distributed computing environment.
- Excellent verbal and written communication skills. Also, good interpersonal skills with the ability to present complex and sensitive issues to senior management, and influence change.
Preferred qualifications capabilities and skills
- Degree and background in Technology
- Related professional certification such as CISA or CISSP