About this role
Job title: Audit and Risk Manager (IT)
About the Role Lead and oversee IT audit and regulatory compliance activities across ContiTech IT environments. Serve as the liaison between ContiTech IT teams and external auditors/regulatory authorities, driving compliance programs and risk management oversight through ICS/RMS.
What You'll Do
- Assist and consult on all IT audit and regulatory compliance at all IT levels within ContiTech.
- Provide project management to implement complex compliance strategies.
- Act as a liaison between internal ContiTech IT teams and external audit/regulatory authorities.
- Develop strategies for regulatory topics including IATF, TISAX, PWC, DPO (IT Data Protection), and Internal Audit.
- Coordinate all regulatory certification efforts related to ContiTech Group Sector with link to IT.
- Maintain managed document requirements in IT Library related to IT audits.
- Provide a knowledge base platform for audit topics including: audit focus areas, deficiency listing with tracking and reporting, and IT Audit Calendar.
- Provide independent review processes for any control needs related to applications in Internal Control System ICS/RMS.
- Provide RMS coordination and risk reporting process.
What We're Looking For
- Education: Degree (Bachelor, Master) in Finance, Business Administration, Quality, Engineering or alike, preferably with enhanced knowledge in regulations, auditing.
- Working experience: minimum 5 years in the field/industry (B2B with OEM quality audits, TISAX, IATF ISO 16949, ISO 27001).
- Experience with external audit teams is a big part of the job, so comfort with dealing with regulatory differences and how to overcome those is needed.
- Languages: English C1; German optional
- Knowledge: The position requires a knowledge of basic security, ITGC, ITAC, privacy, financial, and other regulatory related laws to perform the tasks. These laws change and differ from continent, country, and functional area and the ability to research and interpret laws quickly is a must. It is best if an audit background exists to quickly interpret and understand best practice guidance. SOX or NIST background is a must. Understanding of risk analysis and assessment is a must.
Nice to Have
- Audit background is a plus.
- Experience with external audit teams is a plus.
- Familiarity with cross-border regulatory differences is beneficial.