AVP, Audit Services - Cybersecurity & Core Technology
2002 United Services Automobile Asn · Plano East, United States
About The Role
Why USAA?
At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military community and their families.
Embrace a fulfilling career at USAA, where our core values – honesty, integrity, loyalty and service – define how we treat each other and our members. Be part of what truly makes us special and impactful.
We are proud to support active-duty military spouses. USAA roles may offer remote or hybrid flexibility for active-duty military spouses consistent with applicable policy and business needs.
The Opportunity
Reporting directly to the Head of I.T. Audit, the AVP, Audit Services - Cybersecurity & Core Technology will lead audit assurance and advisory services across the Cybersecurity and Core Technology Audit portfolios, including technology infrastructure, security operations, resiliency, cloud, artificial intelligence, identity and access management, data protection, third-party technology risk, and other enterprise technology domains. This executive will also develop, coordinate, and oversee a comprehensive, risk-based audit strategy that provides independent and objective assurance over the effectiveness of governance, risk management, compliance, and control processes.
Moreover, this executive will be responsible for the long-term strategy, audit coverage model, talent strategy, and execution of the annual audit plan for assigned areas. He or she will need to partner with senior executives, business leaders, risk and control partners, regulators, and governance committees to provide credible challenge, identify emerging risks, and ensure audit coverage remains aligned with enterprise strategy, regulatory expectations, and the evolving technology and cyber threat landscape. He or she will also need to maintain strong knowledge of financial services regulations, technology risk management standards, internal audit professional practices, and heightened regulatory expectations.
Location
- USAA offers a flexible work environment that requires an individual to be in the office 4 days per week. This position can be based in one of the following locations: Plano, TX (strong preference); Charlotte, NC. Relocation assistance is available for this position.
What You'll Do
- Lead the design and execution of the enterprise risk-based audit strategy, annual audit plan, and audit universe for Cybersecurity and Core Technology, ensuring alignment with USAA’s business strategy, technology roadmap, regulatory expectations, and enterprise risk profile.
- Oversee all aspects of audit delivery for assigned portfolios, including risk assessment, audit scoping, execution, reporting, issue follow-up, continuous monitoring, quality, resource prioritization, and timely escalation of significant risks or control concerns.
- Provide independent, objective assurance and advisory insight on the effectiveness of technology and cyber governance, risk management, compliance, internal controls, operational resilience, third-party technology risk, and regulatory readiness.
- Serve as a senior Audit point of contact for technology, cyber security, infrastructure, and enterprise risk governance forums, ensuring insights from committee participation and continuous monitoring are communicated across Audit Services and incorporated into audit planning.
- Engage senior business, technology, cyber security, risk, compliance, and executive stakeholders to discuss risks and controls, provide credible challenge, influence risk-informed decisions, and promote appropriate balance between strategic objectives and control discipline.
- Monitor technology, cyber, regulatory, operational, and industry trends to identify emerging risks, adjust audit coverage, and ensure the audit approach remains responsive to changes in the business, threat environment, and regulatory landscape.
- Review and approve audit reports and key deliverables for assigned areas, ensuring conclusions are well supported, issues are clearly articulated, work complies with audit methodology, regulatory expectations, and IIA standards, and recommendations drive meaningful risk reduction.
- Build, develop, and retain a high-performing team of employees and third-party resources with deep technology, cyber security, infrastructure, risk management, and internal audit capabilities, including succession planning, skills assessment, coaching, and performance management.
- Support the Head of Technology Audit, Audit Executive leadership, CAE, and applicable Board or management committees through briefings, reporting, regulatory engagement support, special audits, strategic initiatives, and enterprise-wide audit practice evolution.
- Coordinate across Audit Services, other assurance leaders, external auditors, regulators, and the Insights and Delivery team to promote integrated coverage, consistent quality, effective use of data and analytics, and efficient sharing of risk intelligence across the enterprise.
What You Have
- Bachelors degree, or 4 additional years of related experience beyond the minimum required may be substituted in lieu of a degree.
- 10+ years of experience in internal audit, risk management, compliance, technology risk, cybersecurity, technology operations, or other control partner experience within a complex, matrixed environment.
- 6+ years of people leadership experience building, managing, and developing high-performing teams.
- 4+ years of experience accountable for developing and overseeing technology, cyber security, infrastructure, or related audit plans and execution.
- Experience interacting with regulators regarding audits, controls, regulatory readiness, supervisory matters, or examination activities.
- Expert knowledge of internal auditing standards, audit methodologies, risk assessment practices, and techniques required to perform complex audits.
- Strong understanding of technology risk management, cyber security, infrastructure operations, information security, resilience, third-party risk, cloud, data protection, and related control frameworks.
- Knowledge of financial services operations, including banking, insurance, investment operations, and associated regulatory expectations.
- Demonstrated ability to collaborate with senior leaders, influence audit and risk decisions, provide credible challenge, and drive work to achieve strategic objectives.
- Working knowledge of applicable regulatory guidance and supervisory expectations, including FFIEC, OCC, Federal Reserve, CFPB, SEC, state insurance regulations, Dodd-Frank, Heightened Standards, UDAAP, and other relevant requirements.
What Sets You Apart
- Deep subject matter expertise across both Cybersecurity Audit and Core Technology Audit , including cyber operations, infrastructure, cloud, identity and access management, data protection, technology resilience, vulnerability management, third-party technology risk, and emerging technology risk.
- Experience leading an integrated technology and cyber audit portfolio, which reflects industry practice as organizations increasingly assess cyber risk as part of broader digital, infrastructure, resilience, third-party, and enterprise technology risk management rather than as a standalone compliance activity. Internal audit guidance and industry perspectives emphasize evaluating cyber security within the broader technology governance, risk, control, resilience, and business strategy context.
- Proven ability to develop integrated cyber and technology audit coverage that connects risks across IT governance, security operations, cloud, data, infrastructure, operational resilience, and third-party ecosystems, consistent with emerging internal audit focus areas around cyber, cloud, resilience, AI, interconnected systems, and supply chain risk.
- Current knowledge of technology and cyber regulatory expectations for large financial institutions, including experience supporting regulatory examinations, issue remediation, and executive or Board-level reporting.
- Track record of leading transformational change through innovative audit strategies, continuous monitoring, data-driven insights, automation, and proactive identification of emerging risks.
- Deep experience with OCC Heightened Standards, risk governance frameworks, risk culture, roles and responsibilities, policies, procedures, and processes to identify, measure, monitor, control, and report risks.
- Experience in second line of defense functions, such as Enterprise Risk Management, Operational Risk Management, Technology Risk, or Cyber Risk, with demonstrated ability to assess risk culture across people, processes, and technology.
- Strong accomplishments auditing or leading Third Party Risk Management, technology resiliency, business continuation, disaster recovery, or operational resilience programs.
- Working knowledge of additional risk categories, including fraud, credit risk, market risk, liquidity risk, interest rate risk, compliance risk, reputation risk, and operational risk.
- CISA, CIA, CISSP, CRISC, CISM, or other relevant audit, cyber security, technology risk, or risk management certifications.
Visa Sponsorship
- USAA does not provide visa sponsorship for this position. Please do not apply for this position if at any time (now or in the future) you will need immigration support (i.e., H-1B, TN, STEM OPT Training Plans, etc.).
Compensation
- The salary range for this position is $195,230 to $351,410.
Compensation: USAA has an effective process for assessing market data and establishing ranges to ensure we remain competitive. You are paid within the salary range based on your experience and market data of the position.
Employees may be eligible for pay incentives based on overall corporate and individual performance and at the discretion of the USAA Board of Directors.
The above description reflects the details considered necessary to describe the principal functions of the job and should not be construed as a detailed description of all the work requirements that may be performed in the job.
Long Term Incentive Plan: Cash payment for Executive level roles only, representing a cash payment which is both time and performance based.
Benefits: At USAA our employees enjoy best-in-class benefits to support their physical, financial, and emotional wellness. These benefits include comprehensive medical, dental and vision plans, 401(k), pension, life insurance, parental benefits, adoption assistance, paid time off program with paid holidays plus 16 paid volunteer hours, and various wellness programs. Additionally, our career path planning and continuing education assists employees with their professional goals.
For more details on our outstanding benefits, visit our benefits page on USAAjobs.com.
Applications for this position are accepted on an ongoing basis, this posting will remain open until the position is filled. Thus, interested candidates are encouraged to apply the same day they view this posting.
USAA is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
