Director, Internal Audit - Technology, Information Security and AI (6 month
Vaco by HighspringRole Overview
Vaco by Highspring is hiring a Director, Internal Audit - Technology, Information Security and AI (6 month. This is a contract role in CA. Part of Vaco by Highspring's Risk hiring, posted today. applications are still in the early window, before most candidates have applied. Full responsibilities, required qualifications, and the apply link are listed in the description below.
Resume Keywords to Include
Make sure these keywords appear in your resume to improve ATS scoring
Sign up free to auto-tailor your resume with all these keywords and get a higher ATS score
Job Description
This is a 6 month contract with permanent potential
The Director, Internal Audit – Technology, Information Security, and AI leads the planning and delivery of risk-based audits and advisory work across the Bank’s technology and digital risk domains. This role provides independence assurance over technology risks across ITGCs, cybersecurity governance, cloud governance, data management, AI, and technology operations. The Director is expected to exercise independent authority and credible challenge with senior technology leaders including the Chief Technology Officer (CTO) and their leadership team ensuring that technology risks, control gaps, and remediation commitments are appropriately identified, debated, and addressed.
The role requires sufficient technical knowledge and professional competence to engage in difficult, sometimes adversarial conversations with technology leadership, while maintaining a constructive, respected, and independent relationship. Co-sourced SMEs may support deep technical assessments; however, the Director must independently interpret results, synthesize risk implications, and challenge management where standards or practices are insufficient.
RESPONSIBILITIES
Risk Assessment & Strategy Planning (20%)
- Own and maintain the technology audit universe for core domains: Technology Strategy, Data, and AI, Technology Integration, Software Engineering, Digital Services, Technical Services & Performance, Technology Operations, and Information & Cyber Security.
- Maintain awareness of technological changes in both external and internal environments including trends in risk management practices and regulatory expectations, and changes in business activities to perform quarterly risk assessments for the technology audit entities within the Internal Audit Universe.
- Lead the annual technology risk assessment, identify appropriate audits to be included in the annual audit plan and help develop the Plan for the Audit Committee approval.
- Identify emerging risks within the Technology audit portfolio (e.g., cyber threats, cloud adoption, data privacy), monitor these risks to determine their impact, and assess changes needed for the annual audit plan or planned audits. Incorporate changes as appropriate.
Audit Plan Execution and Delivery (50%)
- Oversee execution and end to end delivery of all audit projects within the Technology audit universe, ensuring all documentation and audit reports are complete, and projects are appropriately and effectively staffed. Coordinate use of co-sourced technical experts for deep cyber/cloud/AI testing where needed.
- Lead opening and closing meetings, ensuring audit project planning is appropriately completed, reviewing audit working papers, and preparing/reviewing draft internal audit report for each project. Review control design and effectiveness using industry frameworks (NIST CSF, ISO 27001, COBIT).
- Deliver balanced and insightful reporting to the Chief Internal Auditor and Audit Committee on technology risk posture, themes, and systemic gaps.
- Oversee remediation/closure of IT audit findings, OSFI findings including tracking closure to due dates, the validation of findings with management, ensuring appropriate responses are received, and appropriate quality assurance practices are followed.
- Provide independent advice during major technology initiatives (policy& standards enhancements, modernization, cloud migration, data platform enhancements) from governance and risk lens and collaborate with stakeholders to embed controls early.
Leadership & Stakeholder Management (20%)
- Develop and maintain independent and influential relationships with senior technology stakeholders, including the CTO, CISO, Data & Privacy leadership, and enterprise risk partners (i.e., ERM, ORM, Compliance).
- Develop and maintain working relationships with the Bank’s external auditors to support their direct assistance and or audit reliance model.
- Demonstrate the authority, credibility, and technical understanding necessary to challenge technology decisions, risk acceptances, and control deficiencies especially in areas where management believes risks are mitigated.
- Facilitate difficult discussions with technology leadership by articulating risk impacts, regulatory expectations, and control considerations in a clear and authoritative manner.
- Lead a team of IT audit professionals with a mix of internal capabilities and co-sourced specialists.
- Mentor team members to deepen expertise in ITGCs, cyber governance, and foundational cloud/data risks.
Standards, Methodology & Tools (10%)
- Ensure all technology audit work adheres to the Global Internal Audit Standards (GIAS) and Internal Audit methodology. Contribute to annual review of audit practices and methodology against relevant benchmarks.
- Map controls to recognized frameworks as appropriate: NIST CSF/800-53, ISO 27001/27701, COBIT, CIS Controls, CSA CCM, PCI DSS (if applicable), and applicable privacy regulations. Recommend changes to audit processes, methodology and reporting to improve effectiveness.
- Champion continuous improvement, agile auditing methods, and data-driven audit techniques (CAATs, automation, scripts, and continuous monitoring).
- Promote tooling: GRC, ticketing/ITSM (e.g., ServiceNow), CI/CD, CSP native security tooling, CSPM/CWPP, SIEM/SOAR, data lineage/governance tools, and model monitoring platforms.
REQUIREMENTS
- University degree in information systems, Computer Science, Engineering, Accounting, or related field.
- Certified Information Security Audit designation.
- Certifications in the following are preferred:
- Audit: CIA, Risk: CRISC, CGEIT, Security: CISSP, CISM, CCSP, ISO 27001
- Cloud: AWS/Azure/GCP security or architecture certifications
- Data/Privacy: CDMP, CIPT/CIPM/CIPP, ISO 27701
- 10+ years of progressive experience within the Financial Services Industry.
- Solid Information Technology (IT)/Information Security (IS) audit and/or similar management experience in a regulated financial institution.
- Strong experience leading audits of information technology, information security, data management, and project management, in conformance with IIA Standards.
- Excellent understanding of risk management and related governance concepts, tools, techniques and best practices gained from practical financial services experience.
- Strong command of at least three of the following: ITGCs, cybersecurity operations, cloud security/ governance, data governance/quality/privacy, SDLC/DevSecOps, AI/ML governance/model risk.
- Strong understanding of the Bank’s risk tolerance, risk management, & risk assessment activities.
- Technical auditing proficiency in a regulated financial services environment, including strong analytical risk assessment and problem-solving skills.
- Ability to counsel and advise on complex risk situations affecting the organization, within the context of audit assignments, including recommendations on related risk management.
- Excellent communication, decision making, time management, negotiation, and influencing skills.
- Leads and demonstrates knowledge, teamwork, cross-unit cooperation and information and consistently demonstrates and reinforces organizational values.
- Solution-focused and takes initiative ensuring self and team work effectively and efficiently within established guidelines.
- Ability to lead a strategic and progressive approach to provide value-added recommendations to leaders across the Bank.
Frequently Asked Questions
How do I apply for the Director, Internal Audit - Technology, Information Security and AI (6 month position at Vaco by Highspring?
Use the Apply button above to submit your application directly to Vaco by Highspring. Most applications take less than 5 minutes if your resume and contact details are ready, and you'll be routed to the employer's official application system to finish.
Where is the Director, Internal Audit - Technology, Information Security and AI (6 month position at Vaco by Highspring located?
This position is based in CA. Vaco by Highspring has not indicated remote or hybrid options for this role, so candidates should plan for on-site work.
What does a Director, Internal Audit - Technology, Information Security and AI (6 month at Vaco by Highspring earn?
Vaco by Highspring has not disclosed a salary range in this posting. Many employers share specifics later in the interview process; you can also ask during a recruiter screen if compensation transparency is important to you.
When was the Director, Internal Audit - Technology, Information Security and AI (6 month role at Vaco by Highspring posted?
This role was posted on June 9, 2026 (today). It's still listed as actively hiring; we re-confirm openings against the source system multiple times per day and remove closed roles.
AI-powered job search
Get every job scored to your resume
Upload your resume and get jobs ranked, your resume tailored, and employee contacts found automatically.
Get Started FreeNo credit card to start