Senior Audit Manager - Cyber Security


About RSAA

RSAA is a growing assurance, compliance, cybersecurity, and advisory firm helping organizations navigate complex security, compliance, and risk requirements.

We work across leading cybersecurity and assurance frameworks, helping clients achieve compliance, maintain certifications, strengthen their controls, and build sustainable security programs.

We are looking for an experienced Senior Audit Manager who can operate at the intersection of technical assurance, compliance, client leadership, business development, and service-line management.


Senior Audit Manager

Company: RSAA
Location: Dallas–Fort Worth, TX preferred; Remote considered for exceptional candidates
Employment Type: Full-Time, W-2
Compensation: 150,000–225,000 base salary + performance-based incentives
Travel: Approximately 10–25% per month
Career Path: Potential pathway to Partner

This is not a traditional 40-hour-per-week management position. The successful candidate will be expected to roll up their sleeves, perform testing, lead engagements, build processes, develop people, and own the growth and quality of their service lines.

This is a high-autonomy leadership role with the potential to grow into a Partner-level position at RSAA.




The Opportunity

The Senior Audit Manager will have ownership of RSAA's assurance and compliance service lines, including the development, delivery, quality, and growth of services across multiple frameworks.

The ideal candidate is a CPA and seasoned assurance professional who also possesses strong cybersecurity and information-security credentials.

You should be equally comfortable:

  • Leading a room full of executives
  • Performing hands-on testing
  • Reviewing workpapers
  • Building SOPs
  • Managing client relationships
  • Coaching and challenging team members
  • Discussing technical controls with security professionals
  • Discussing business risk with executives
  • Selling 500K–1M+ of professional services
  • Working independently with minimal supervision

You will be expected to bring an "own it" mentality to the role.




Key Responsibilities

Assurance & Peer Review Leadership

  • Own and maintain RSAA's internal SOC 2 peer-review and quality processes.
  • Oversee quality and consistency of assurance engagements.
  • Perform and review testing across multiple cybersecurity, compliance, and assurance frameworks.
  • Establish and maintain testing methodologies, workpaper standards, review procedures, and quality controls.
  • Ensure engagements are performed consistently, efficiently, and in accordance with applicable professional and industry standards.
  • Identify opportunities to "test once, certify twice" by leveraging common controls and evidence across multiple frameworks.
  • Continuously improve RSAA's approach to integrated testing and multi-framework assessments.

ISO & Compliance Service-Line Ownership

Take leadership responsibility for RSAA's ISO-related service offerings, including, as applicable:

  • ISO 9001 — Quality Management
  • ISO/IEC 27001 — Information Security Management
  • ISO/IEC 42001 — AI Management Systems
  • Other relevant ISO standards and assurance frameworks

Responsibilities include:

  • Developing and maintaining service-line methodologies.
  • Creating and maintaining SOPs.
  • Establishing testing procedures and templates.
  • Developing engagement approaches and delivery standards.
  • Training and mentoring consultants.
  • Reviewing engagement quality.
  • Identifying opportunities for service-line expansion.
  • Staying current on changes to applicable standards and certification requirements.

Hands-On Testing

This is a working leadership position.

You will be expected to personally participate in testing and assessments when necessary rather than simply managing from a distance.

You should be comfortable:

  • Reviewing evidence
  • Testing controls
  • Conducting interviews
  • Performing walkthroughs
  • Documenting findings
  • Challenging control owners
  • Writing assessment reports
  • Reviewing remediation
  • Performing quality reviews
  • Supporting complex client engagements

The successful candidate understands that strong leadership in assurance requires knowing how the work actually gets done.




Business Development & Revenue Ownership

The senior audit manager will have a meaningful role in growing RSAA's assurance and compliance practice.

Annual Sales Target: 500,000–1,000,000+

Responsibilities include:

  • Identifying opportunities within existing accounts.
  • Developing relationships with prospective clients.
  • Leading discovery and scoping conversations.
  • Presenting RSAA's capabilities to executive stakeholders.
  • Developing proposals and statements of work.
  • Supporting pricing and engagement strategy.
  • Expanding existing client relationships.
  • Partnering with RSAA leadership on strategic accounts.
  • Building a sustainable pipeline for the service lines you own.

You do not need to be a traditional salesperson.

You do need to be commercially minded, credible with executives, and capable of turning technical expertise into business opportunities.




Leadership & Client Presence

The successful candidate must have an exceptionally strong executive presence.

You will regularly interact with:

  • CEOs
  • CFOs
  • CIOs
  • CISOs
  • Compliance leaders
  • Boards and executive teams
  • Security and technology teams
  • External auditors and assessors

You must be able to command a room without dominating it.

You should be an engaging, confident communicator who can explain complicated cybersecurity, compliance, and assurance concepts clearly to both technical and non-technical audiences.

Communication is critical.

Excellent:

  • Written communication
  • Verbal communication
  • Presentation skills
  • Executive communication
  • Report writing
  • Client-facing communication

are required.




Service-Line Development

You will be responsible for building the infrastructure necessary to scale your service lines.

This includes:

  • Creating SOPs
  • Developing standardized methodologies
  • Building engagement templates
  • Creating testing programs
  • Developing quality-control procedures
  • Establishing training materials
  • Creating repeatable delivery processes
  • Identifying opportunities for automation
  • Improving engagement margins
  • Building scalable service offerings

The expectation is that you will build the playbook rather than wait for someone else to give you one.




AI & Emerging Technology

RSAA is increasingly focused on the intersection of cybersecurity, compliance, assurance, and artificial intelligence.

Candidates should have meaningful knowledge of AI and emerging technology, including an understanding of how organizations should approach:

  • AI governance
  • AI risk management
  • AI controls
  • Responsible AI
  • AI security
  • AI-related compliance requirements
  • ISO/IEC 42001
  • The impact of AI on assurance and cybersecurity

Hands-on experience implementing or assessing AI governance programs is strongly preferred.




Required Qualifications

Professional Experience

  • 7+ years of relevant professional experience in assurance, audit, compliance, cybersecurity, risk, or a closely related field.
  • Significant experience leading client-facing assurance or compliance engagements.
  • Demonstrated experience managing complex projects and client relationships.
  • Experience working across multiple cybersecurity or compliance frameworks.

Required Credentials

CPA is required.

Candidates should also possess multiple relevant professional certifications, with a strong preference for combinations such as:

  • CPA
  • CISA
  • CISSP
  • ISO 27001 Lead Auditor / Lead Implementer
  • ISO 9001 Lead Auditor / Lead Implementer
  • ISO 42001 credentials
  • Other recognized cybersecurity, audit, or compliance certifications

The ideal candidate will demonstrate breadth across accounting, audit, cybersecurity, information security, and ISO standards.




Required Personal Characteristics

We are looking for someone who:

  • Takes ownership.
  • Works independently.
  • Does not need to be micromanaged.
  • Is comfortable making decisions.
  • Has a strong sense of urgency.
  • Can manage competing priorities.
  • Is willing to get into the details.
  • Will roll up their sleeves when an engagement requires it.
  • Is comfortable being accountable for results.
  • Can lead experienced professionals.
  • Is comfortable challenging clients when necessary.
  • Enjoys building things from the ground up.
  • Has an entrepreneurial mindset.
  • Wants to build something larger than their individual role.

This position is not for someone who wants to simply manage a team, attend meetings, and delegate the technical work.




Workload & Availability

This is a demanding leadership position.

The role is expected to require approximately 50–60 hours per week during periods of significant client and business activity, rather than being structured as a traditional 40-hour role.

The successful candidate must be comfortable with:

  • Client deadlines
  • Multiple concurrent engagements
  • Business-development responsibilities
  • Travel
  • Quality reviews
  • Occasional extended workdays
  • High levels of accountability




Travel

Approximately 10–25% travel per month, depending on client requirements and business-development activities.

Travel may include:

  • Client sites
  • Executive meetings
  • Conferences
  • Industry events
  • Internal RSAA meetings
  • Business-development opportunities




Compensation & Career Opportunity

Base Salary: 175,000–225,000

Additional performance-based compensation may be available based on:

  • Revenue generated
  • Service-line growth
  • Engagement performance
  • Client retention
  • Business development
  • Leadership objectives

Potential Path to Partner

This role is designed for an individual who wants to build a long-term career with RSAA.

For the right person, demonstrated success in:

  • Growing revenue
  • Building service lines
  • Developing people
  • Maintaining exceptional quality
  • Building client relationships
  • Creating scalable methodologies
  • Demonstrating leadership
  • Contributing to RSAA's overall growth

could create a pathway toward Partner-level responsibilities and economics.




What Success Looks Like

Within the first 12–24 months, the successful candidate should be able to:

  • Establish strong ownership of RSAA's assurance service lines.
  • Improve and standardize testing methodologies.
  • Strengthen SOC 2 peer-review processes.
  • Build and document service-line SOPs.
  • Expand RSAA's ISO capabilities.
  • Improve the ability to leverage common controls across multiple frameworks.
  • Develop new client relationships.
  • Generate meaningful new revenue.
  • Build a scalable delivery


Service Delivery

Southlake, TX

Compartir en:

Términos de servicioPrivacidadCookiesPatrocinado por Rippling