Skip to content

Open nowPosted 11 hours agoWe saw it 12 min after it went up

Senior IT Audit Manager

OpenLoop62 open roles

Where
United States - Remote
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior IT Audit ManagerOpenLoop · United States - Remote
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on OpenLoop's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. OpenLoop postings stay open a median of 36 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 34.0%30 days
This job: posted 11 hours ago

OpenLoop median: 36 days open

The posting

ABOUT OPENLOOP

OpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian Williams, with the vision to bring care anywhere. Our telehealth support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states.

About The Role

OpenLoop’s mission is to bring care anywhere by powering telehealth solutions at scale. OpenLoop is looking for a Senior IT Audit Manager to join its Internal Audit function and own the IT controls audit program. Reporting to the Head of Internal Audit, you will assess and validate the design and effectiveness of IT general controls, cybersecurity, data privacy, and emerging technology controls across a cloud-based infrastructure, EHR and EMR systems, and a broad ecosystem of third-party SaaS integrations. The work spans the full IT risk landscape, from SOX ITGC readiness to HIPAA security, AI governance, and data security, in a multi-entity, heavily regulated telehealth environment that is scaling rapidly and preparing for a significant next step in its growth trajectory. This role partners directly with technology and business leadership to design, remediate, and validate controls, ensuring systems and data are secure, reliable, and compliant.

WHAT YOU’LL DO

- Develop and maintain a risk-based IT audit plan, conducting periodic IT risk assessments across systems, applications, infrastructure, and emerging technology domains to establish audit priorities

- Lead end-to-end IT audit engagements, from planning and scoping through fieldwork, reporting, and issue closure

- Facilitate kickoff, status update, and closing meetings with IT process owners, system owners, and senior management

- Design and execute IT control testing procedures independently, including ITGC testing across access management, change management, computer operations, and system development life cycle (SDLC)

- Assess and validate cybersecurity controls, including network security, identity and access management, vulnerability management, and incident response

- Evaluate cloud infrastructure controls (including AWS environments) for security, reliability, and compliance with applicable frameworks and regulatory requirements

- Conduct audits of EHR and EMR systems and clinical application controls, and assess data privacy controls for compliance with HIPAA Security Rule, CCPA, and applicable state-level regulations

- Support the governance of AI governance frameworks and controls, including model governance, data quality, bias risk, and compliance with emerging AI regulations

- Prepare and maintain IT audit documentation including process narratives, system flowcharts, risk and control matrices (RCMs), testing workpapers, and audit reports

- Partner with management to design, remediate, and validate IT controls, providing practical and prioritized recommendations to address identified gaps and process weaknesses

- Track open IT audit issues and remediation plans through closure, validating the effectiveness of corrective actions

- Monitor the evolving IT risk, cybersecurity, and regulatory landscape to keep the IT audit plan current and relevant

WHO YOU ARE

REQUIRED

- Bachelor's degree in Information Systems, Information Technology, Computer Science, or equivalent technical field and active Certified Information Systems Auditor (CISA) designation

- 7+ years of progressive IT audit experience in business risk advisory consulting or internal audit IT specialization

- Demonstrated hands-on experience with IT general controls (ITGC) testing, including access management, change management, computer operations, and SDLC

- Strong knowledge of IT governance and control frameworks (COBIT, COSO, NIST 800-53, ISO 27001) and ISACA IT audit standards and professional practices

- Demonstrated experience auditing cybersecurity and cloud infrastructure controls, including network security, identity and access management, vulnerability management, incident response, and cloud environments such as AWS, Azure, or GCP

- Familiarity with HIPAA Security Rule requirements, including technical safeguards, risk analysis, and security incident procedures

- Experience auditing application controls across SaaS platforms and regulated healthcare technology environments, including EHR and EMR systems, with hands-on testing of input, processing, and output controls, data integrity, and access controls

- Demonstrated use of AI tools to enhance audit execution, accelerate control testing, and improve efficiency across the audit lifecycle

- Ability to execute IT audit engagements independently, manage multiple concurrent engagements, and deliver on time without close supervision

- Clear, concise written and verbal communication skills; able to translate complex technical findings into practical, actionable recommendations for both IT and non-IT audiences

PREFERRED

- Public accounting background (Big 4 or regional firm) with an IT audit or technology risk advisory focus

- Additional certifications such as CRISC, CISSP, CISM, or CIA

- Prior experience supporting SOX ITGC compliance in a pre-IPO, newly public, or high-growth company environment

- Experience auditing or assessing AI governance frameworks, including model governance, data quality controls, and compliance with emerging AI regulations

- Familiarity with data privacy frameworks beyond HIPAA, including CCPA or other applicable state-level regulations

- Knowledge of DevOps practices and SDLC security controls relevant to software development and deployment pipelines

- Proficiency with GRC platforms (e.g., AuditBoard, Workiva, or Vanta) for IT audit management and evidence collection

- Experience in digital health, telehealth, or multi-state healthcare services environments, including familiarity with pharmacy management systems, dispensing technology, or regulated pharmaceutical IT environments

WHAT WE OFFER

- Competitive compensation

- Medical, Dental & Vision

- Flexible Spending / Health Savings Accounts

- Generous PTO and hybrid-work flexibility

- 401(k) with Company Match

- Life Insurance, Pet Insurance, and more

OUR COMPANY

We have a relatively flat organizational structure here at OpenLoop. Everyone is encouraged to bring ideas to the table and make things happen. This fits in well with our core values of Autonomy, Competence and Belonging, as we want everyone to feel empowered and supported to do their best work.

Sound like a good fit? We’d love to meet you.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against OpenLoop's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on OpenLoop's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    OpenLoop's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.