Please mention DailyRemote when applying
See how much of this job your resume covers, and what’s missing.
Want a recruiter to go through it line by line?
Get professional reviewQuestions interviewers often ask for this role, with sample answers.
Upload your resume and we draft a letter for this exact role, tailored to what it asks for.
The Senior IT Audit Manager will own the IT controls audit program, assessing and validating IT general controls, cybersecurity, and data privacy across the company's infrastructure. This role involves developing risk-based audit plans, executing control testing, and partnering with leadership to remediate identified gaps.
OpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian Williams, with the vision to bring care anywhere. Our telehealth support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states.
About The Role
OpenLoop’s mission is to bring care anywhere by powering telehealth solutions at scale. OpenLoop is looking for a Senior IT Audit Manager to join its Internal Audit function and own the IT controls audit program. Reporting to the Head of Internal Audit, you will assess and validate the design and effectiveness of IT general controls, cybersecurity, data privacy, and emerging technology controls across a cloud-based infrastructure, EHR and EMR systems, and a broad ecosystem of third-party SaaS integrations. The work spans the full IT risk landscape, from SOX ITGC readiness to HIPAA security, AI governance, and data security, in a multi-entity, heavily regulated telehealth environment that is scaling rapidly and preparing for a significant next step in its growth trajectory. This role partners directly with technology and business leadership to design, remediate, and validate controls, ensuring systems and data are secure, reliable, and compliant.
Develop and maintain a risk-based IT audit plan, conducting periodic IT risk assessments across systems, applications, infrastructure, and emerging technology domains to establish audit priorities
Lead end-to-end IT audit engagements, from planning and scoping through fieldwork, reporting, and issue closure
Facilitate kickoff, status update, and closing meetings with IT process owners, system owners, and senior management
Design and execute IT control testing procedures independently, including ITGC testing across access management, change management, computer operations, and system development life cycle (SDLC)
Assess and validate cybersecurity controls, including network security, identity and access management, vulnerability management, and incident response
Evaluate cloud infrastructure controls (including AWS environments) for security, reliability, and compliance with applicable frameworks and regulatory requirements
Conduct audits of EHR and EMR systems and clinical application controls, and assess data privacy controls for compliance with HIPAA Security Rule, CCPA, and applicable state-level regulations
Support the governance of AI governance frameworks and controls, including model governance, data quality, bias risk, and compliance with emerging AI regulations
Prepare and maintain IT audit documentation including process narratives, system flowcharts, risk and control matrices (RCMs), testing workpapers, and audit reports
Partner with management to design, remediate, and validate IT controls, providing practical and prioritized recommendations to address identified gaps and process weaknesses
Track open IT audit issues and remediation plans through closure, validating the effectiveness of corrective actions
Monitor the evolving IT risk, cybersecurity, and regulatory landscape to keep the IT audit plan current and relevant
Bachelor's degree in Information Systems, Information Technology, Computer Science, or equivalent technical field and active Certified Information Systems Auditor (CISA) designation
7+ years of progressive IT audit experience in business risk advisory consulting or internal audit IT specialization
Demonstrated hands-on experience with IT general controls (ITGC) testing, including access management, change management, computer operations, and SDLC
Strong knowledge of IT governance and control frameworks (COBIT, COSO, NIST 800-53, ISO 27001) and ISACA IT audit standards and professional practices
Demonstrated experience auditing cybersecurity and cloud infrastructure controls, including network security, identity and access management, vulnerability management, incident response, and cloud environments such as AWS, Azure, or GCP
Familiarity with HIPAA Security Rule requirements, including technical safeguards, risk analysis, and security incident procedures
Experience auditing application controls across SaaS platforms and regulated healthcare technology environments, including EHR and EMR systems, with hands-on testing of input, processing, and output controls, data integrity, and access controls
Demonstrated use of AI tools to enhance audit execution, accelerate control testing, and improve efficiency across the audit lifecycle
Ability to execute IT audit engagements independently, manage multiple concurrent engagements, and deliver on time without close supervision
Clear, concise written and verbal communication skills; able to translate complex technical findings into practical, actionable recommendations for both IT and non-IT audiences
Public accounting background (Big 4 or regional firm) with an IT audit or technology risk advisory focus
Additional certifications such as CRISC, CISSP, CISM, or CIA
Prior experience supporting SOX ITGC compliance in a pre-IPO, newly public, or high-growth company environment
Experience auditing or assessing AI governance frameworks, including model governance, data quality controls, and compliance with emerging AI regulations
Familiarity with data privacy frameworks beyond HIPAA, including CCPA or other applicable state-level regulations
Knowledge of DevOps practices and SDLC security controls relevant to software development and deployment pipelines
Proficiency with GRC platforms (e.g., AuditBoard, Workiva, or Vanta) for IT audit management and evidence collection
Experience in digital health, telehealth, or multi-state healthcare services environments, including familiarity with pharmacy management systems, dispensing technology, or regulated pharmaceutical IT environments
Competitive compensation
Medical, Dental & Vision
Flexible Spending / Health Savings Accounts
Generous PTO and hybrid-work flexibility
401(k) with Company Match
Life Insurance, Pet Insurance, and more
We have a relatively flat organizational structure here at OpenLoop. Everyone is encouraged to bring ideas to the table and make things happen. This fits in well with our core values of Autonomy, Competence and Belonging, as we want everyone to feel empowered and supported to do their best work.
Sound like a good fit? We’d love to meet you.
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Featuring 218,885+ Jobs in Audit Manager
Answer easy questions
218,885+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”