About the role
Senior Manager - IT
Audit
to join our Internal Audit team in Chicago. This leadership role is responsible for managing complex IT and integrated audit engagements, partnering with business and technology leadership to assess risk, strengthen controls, and support Aon's continued digital transformation and innovation initiatives.
Aon is in the business of better decisions
At Aon, we shape decisions for the better to protect and enrich the lives of people around the world.
As an organization, we are united through trust as one inclusive team and we are passionate about helping our colleagues and clients succeed.
The Senior Manager - IT
Audit
is responsible for managing the completion of moderately to highly complex IT and integrated audits in accordance with professional and departmental standards. The role partners with Internal Audit Directors and Senior Directors to assess emerging technology risks and develop risk-based audit plans that address evolving business, cybersecurity, regulatory, and operational challenges.
This position requires a strong combination of technical IT audit expertise, leadership capabilities, stakeholder management skills, and strategic business acumen. The successful candidate will oversee audit teams, communicate key risks and recommendations to senior management, and help drive continuous improvement across Aon's global control environment.
What the day will look like
Audit Leadership & Execution
Lead and oversee complex IT assurance, advisory, integrated audit, special investigation, and risk assessment projects included in the annual audit plan.
Develop and execute risk-based audit approaches covering technology, cybersecurity, cloud, data, application, and operational risks.
Evaluate the design and operating effectiveness of IT controls and identify opportunities to strengthen the overall control environment.
Review and approve audit workpapers to ensure audit objectives are satisfied and documentation meets Internal Audit standards.
Prepare and present audit findings, risk assessments, recommendations, and executive-level reports to business and technology leadership.
Communicate technical control issues in a meaningful business context and articulate risks, impacts, and practical solutions.
Risk Assessment & Strategic Planning
Assist Internal Audit Directors and Senior Directors in developing risk-based audit plans responsive to strategic priorities and emerging risks.
Monitor changes in technology, cybersecurity, AI, cloud computing, automation, privacy, and regulatory requirements to identify new risk areas.
Participate in enterprise risk assessments and provide insight regarding technology and information security risks.
Evaluate the adequacy of management's remediation efforts and validate closure of technology-related audit findings.
Stakeholder Engagement
Build and maintain strong relationships with business, technology, cybersecurity, privacy, compliance, and risk management stakeholders.
Serve as a trusted advisor while maintaining Internal Audit's independence and objectivity.
Collaborate with management to drive sustainable control improvements and risk reduction initiatives.
Present audit results and risk themes to executive leadership and support Audit Committee reporting activities as required.
Team Leadership & Development
Lead, mentor, and develop Internal Audit staff assigned to audit engagements.
Supervise co-sourced audit resources and external professional service providers.
Provide coaching, performance feedback, and knowledge transfer to enhance team capabilities.
Support departmental initiatives, innovation efforts, methodology enhancements, and special projects.
How this opportunity is different
Opportunity to influence risk management across a global enterprise.
Exposure to senior business and technology leadership.
Participation in innovative audits involving cybersecurity, cloud, artificial intelligence, automation, and emerging technologies.
Collaborative and diverse global Internal Audit team.
Professional growth and leadership development opportunities.
Skills and experience that will lead to success
8+ years of IT audit, information security, technology risk, internal audit, external audit, or comparable experience within:
A large multinational organization,
Financial services organization,
Insurance industry organization, and/or
Big Four or comparable professional services firm.
Demonstrated experience leading complex IT and integrated audit engagements.
Experience supervising audit teams and managing stakeholder relationships at multiple organizational levels.
Technical Knowledge
The ideal candidate demonstrates expertise in:
IT General Controls (ITGCs)
Application controls
IT governance and risk management
Cybersecurity controls and assessments
Identity and access management
Infrastructure and network security reviews
Cloud computing environments
Technology resilience and disaster recovery
Data governance and privacy controls
Third-party technology risk management
Regulatory and compliance requirements
Additional Preferred Qualifications
Deep understanding of cybersecurity frameworks and regulatory requirements, including:
NIST Cybersecurity Framework
COBIT
ISO 27001
SOX
GDPR
Experience auditing cloud platforms such as:
Amazon Web Services (AWS)
Microsoft Azure
Google Cloud Platform (GCP)
Familiarity with containerized environments and modern technology architectures, including Docker and API-based integrations.
Experience using data analytics and visualization tools to enhance audit effectiveness, including:
Power BI
Tableau
SQL
Python
Experience with intelligent automation and robotic process automation technologies such as Microsoft Power Automate.
Understanding of artificial intelligence and machine learning governance concepts, including:
Model governance
AI risk management
Bias detection and mitigation
Explainability and transparency considerations
Experience applying agile methodologies within audit planning and execution.
Demonstrated ability to identify practical, technology-enabled solutions that strengthen controls and improve business processes.
Skills & Competencies
Excellent verbal and written communication skills.
Strong executive presence and presentation capabilities.
Ability to translate complex technical concepts into business-relevant insights.
Strong analytical, problem-solving, and critical-thinking skills.
Exceptional organizational and project management capabilities.
Ability to effectively influence and collaborate with stakeholders across all levels of the organization.
Proven leadership skills with a collaborative, team-oriented, and results-driven approach.
Curiosity, innovation mindset, and commitment to continuous improvement.
Education & Certifications
Required
Bachelor's degree in Information Technology, Information Systems, Cybersecurity, Computer Science, Accounting, Finance, or a related discipline.
Preferred Professional Certifications
Certified Information Systems Auditor (CISA)
Certified in Risk and Information Systems Control (CRISC)
Certified Internal Auditor (CIA)
Certified Public Accountant (CPA)
Certified Information Security Manager (CISM)
Certified Information Systems Security Professional (CISSP)
Other relevant audit, cybersecurity, cloud, or risk management certifications
For positions in San Francisco and Los Angeles, we will consider for employment qualified applicants with arrest and conviction record in accordance with local Fair Chance ordinances.
Aon is not accepting unsolicited resumes from search firms for this position. If you are a search firm, you will not be compensated in any way for your submission of a candidate, even if Aon hires that candidate.
Nothing in this job description restricts management's right to assign or reassign duties and responsibilities to this job at any time.
Pay Transparency Laws
The salary range for this position (intended for U.S. applicants) is $130,000 - $150,000 annually. The actual salary will vary based on applicant’s education, experience, skills, and abilities, as well as internal equity and alignment with market data. The salary may also be adjusted based on applicant’s geographic location.
Minimum requirements
- Bachelor’s degree in IT, Cybersecurity, Computer Science, Accounting, Finance, or related field with 8+ years in IT audit, information security, or technology risk.
- Proven experience leading complex IT and integrated audit engagements and supervising audit teams.
- Strong technical knowledge of IT controls, cybersecurity, cloud environments, and regulatory compliance.
This listing was parsed by AI and may not be complete. Check the official posting on Aon's site for the most accurate information.