Back to job search
QC
Quarry ConsultingVerified Job Source

Information Technology Risk Manager

Lead complex IT audit engagements from planning through reporting, focusing on various technology risks. Prepare and present executive-level reports to senior management and the Audit Committee.

  • Hybrid
  • Ontario
  • Posted Jul 10, 2026
  • Apply by Aug 9, 2026
  • 1 position

Job summary

Title: IT Risk Manager - Internal Audit Location: Hybrid ( 1-2 days per week) Duration: TBD Clearance: Must have a valid or be eligible for Reliability Clearance. ( Candidates must have resided in Canada for a minimum of five consecutive years.) Objective Provide independent IT Audit Services to support the Internal Audit function by assessing technology risks, controls, and governance practices. Key Responsibilities Lead complex IT audit engagements from planning through reporting, focusing on cybersecurity, cloud, data/privacy, IAM, AI, third-party technology, and emerging risks. Perform risk assessments, control evaluations, testing, and evidence-based analysis. Review and challenge audit work to ensure quality, consistency, and sound conclusions. Develop clear audit findings outlining root causes, risks, and improvement opportunities. Prepare and present executive-level reports to senior management and the Audit Committee. Engage with Director- and VP-level stakeholders on audit objectives, issues, and findings. Identify systemic risk themes and support improvements to IT audit practices. Use data analytics and Generative AI to improve risk sensing, testing coverage, efficiency, and reporting. Top Skills Required Strong knowledge of cloud, cybersecurity, identity, networks, endpoint security, data platforms, and Agile delivery. Experience with frameworks such as NIST, CIS Controls, COBIT, ISO 2700x, and IIA Standards. Expertise in technology risk areas such as cybersecurity, cloud/IAM security, data governance, third-party risk, and technology resilience. Experience using analytics tools such as Power BI, ACL/HighBond, IDEA, Python, or SQL for audit and risk analysis. Strong executive communication and stakeholder management skills. Professional certification such as CISA, CISSP, CISM, CRISC, or CGEIT.

What you’ll do

Lead complex IT audit engagements from planning through reporting, focusing on various technology risks. Prepare and present executive-level reports to senior management and the Audit Committee.

Requirements

Candidates should have strong knowledge of technology risk areas and experience with relevant frameworks. Professional certifications such as CISA, CISSP, or similar are preferred.

Other relevant skills

Identified from the job description. Confirm important requirements above.

  • Cloud
  • Cybersecurity
  • Identity
  • Networks
  • Endpoint Security
  • Data Platforms
  • Agile Delivery
  • NIST
  • CIS Controls
  • COBIT
  • ISO 2700x
  • IIA Standards
  • Data Governance
  • Third-Party Risk
  • Technology Resilience
  • Power BI

Job areas

  • Technology
  • Consulting
  • Data & Analytics
  • Management & Leadership
  • Security & Safety

Additional details

Minimum experience
5+ years
Apply by
Aug 9, 2026
Posting language
English
Working hours
40 hours per week
Office presence
2 days per week
Seniority
Mid-Senior level
Application method
Direct apply is available