2

Full Time Internal Audit Risk Management Jobs in Boston, MA

Internal Audit exists to protect the trust SharkNinja earns every day, providing independent ... Our what is concrete: we facilitate the enterprise risk management program, execute risk-based ...

Senior Manager, IT Internal Audit

Needham, MA · On-site

$98K - $134K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Internal Audit exists to protect the trust SharkNinja earns every day, providing independent ... Our what is concrete: we facilitate the enterprise risk management program, execute risk-based ...

IT Internal Auditor

Wilmington, MA · Hybrid

  • Medical

  • Life

  • Retirement

  • PTO

... risk management practices, and helps enhance the overall control environment. Working closely with Internal Audit leadership, business stakeholders, technology teams, and external auditors, the ...

IT Internal Auditor

Wilmington, MA · Hybrid

  • Medical

  • Life

  • Retirement

  • PTO

... risk management practices, and helps enhance the overall control environment. Working closely with Internal Audit leadership, business stakeholders, technology teams, and external auditors, the ...

Internal Auditor

Cambridge, MA · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Business Partnership and Risk Assessment * Support Internal Audit Managers in fostering and maintaining business partnerships with relevant functions at working level to enhance collaborated risk ...

Internal Auditor

Cambridge, MA

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Business Partnership and Risk Assessment * Support Internal Audit Managers in fostering and maintaining business partnerships with relevant functions at working level to enhance collaborated risk ...

Staff Auditor

Westwood, MA · On-site

$73K - $97K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

... Internal Audit team as a Staff Auditor supporting the execution of Capital Markets audit activities. This role offers broad exposure to how a large financial institution manages risk, evaluates ...

Staff Auditor

Westwood, MA · On-site

$73K - $97K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

... Internal Audit team as a Staff Auditor supporting the execution of Capital Markets audit activities. This role offers broad exposure to how a large financial institution manages risk, evaluates ...

Technology Risk Director- CyberSecurity

Westwood, MA · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Partner with Internal Audit, and second line stakeholders, leading exam preparation, responses, and ... Collaboration & Stakeholder Management * Build and maintain strong, trusted relationships with ...

Showing results 41-60

Full Time Internal Audit Risk Management information

See Boston, MA salary details

$66.3K

$125.2K

$164.6K

How much do full time internal audit risk management jobs pay per year?

As of Aug 14, 2026, the average yearly pay for full time internal audit risk management in Boston, MA is $125,151.00, according to ZipRecruiter salary data. Most workers in this role earn between $109,700.00 and $145,600.00 per year, depending on experience, location, and employer.

What is the difference between Full Time Internal Audit Risk Management vs Internal Control Analyst?

AspectFull Time Internal Audit Risk ManagementInternal Control Analyst
CertificationsCPA, CIA, CRMACPA, CIA, CRMA
Work EnvironmentCorporate offices, audit departmentsCorporate offices, compliance teams
Employer & IndustryFinancial, manufacturing, healthcareFinancial, manufacturing, healthcare
Primary FocusAssessing and managing overall risk and audit processesEvaluating and testing internal controls

Full Time Internal Audit Risk Management professionals focus on evaluating organizational risks and conducting audits to ensure compliance and operational efficiency. Internal Control Analysts primarily assess and test internal controls to prevent fraud and errors. While both roles require similar certifications and work in similar environments, Internal Audit Risk Management has a broader scope involving risk assessment and audit planning, whereas Internal Control Analysts concentrate on internal control effectiveness.

Infographic showing various Full Time Internal Audit Risk Management job openings in Boston, MA as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $125,151 per year, or $60.2 per hour.

Senior Manager, IT Internal Audit

SharkNinja

Needham, MA

$98K - $134K/yr

Full-time

Posted 24 days ago


SharkNinja rating

8.2

Company rating: 8.2 out of 10

Based on 5 frontline employees who took The Breakroom Quiz

45th of 157 rated electronics manufacturers


Job description

About the Role

SharkNinja's why is extreme consumer delight and unwavering trust. Internal Audit exists to protect the trust SharkNinja earns every day, providing independent, objective assurance and insight that helps the Company create, protect, and sustain value as it grows.

Our what is concrete: we facilitate the enterprise risk management program, execute risk-based business reviews (advisory and assurance), assess internal control over financial reporting (ICFR / SOX), and deliver rapid insights when the business needs them.

Our how sets us apart: behaviors rooted in trust, value, and grit; visible and accessible wherever the work happens; and every engagement framed through why, what, and how, qualified against the three lines so we complement the teams already on the risk instead of duplicating or conflicting. We're business partners and we operate on a simple promise: no surprises.

As Senior Manager, IT Internal Audit, you'll work that full mandate and carry its technical depth. SharkNinja runs on a fast-evolving stack, you'll lead the technology dimension of everything IA does, from ITGC assessment to risk sensing to how we govern and audit AI itself, as part of a small senior human core, amplified by agentic AI teammates and on-demand co-source depth.

This is a builder's role. The blueprint isn't finished, and you'll help draw it.

Here are some of the EXCITING things you'll get to do:

Facilitate the ERM program: build the smoke detectors

  • Engineer the technical side of risk sensing: continuous monitoring, anomaly detection, and analytics that surface emerging risk signals across systems and data, elevating the risk instincts already in SharkNinja's DNA into faster, better, more confident decisions.
  • Own the technology, cybersecurity, data privacy, and third-party dimensions of the enterprise risk assessment, including for connected and IoT products, and translate technical exposure into business-relevant insight.
  • Feed what the data shows into the risk-based plan, so IA's effort reflects where risk actually lives, not where it lived last year.

Execute risk-based business reviews: advisory and assurance

  • Lead technology-focused business reviews driven by the risk assessment, including cyber, data privacy, system implementations, and third-party technology, and embed data analytics across the function's reviews, testing full populations, not samples.
  • Run every engagement through our why/what/how lens and the three-lines qualifier: partner with IT and InfoSec as allies, coordinate without duplicating, and engage exactly where IA adds unique value.
  • Help define how SharkNinja audits AI: shape the governance and assurance approach for AI-enabled processes and tools. Frontier work, done here first.
  • Lead pre- and post-implementation reviews for major system deployments and enhancements.

Assess ICFR (SOX): own the technology control environment assessment

  • Lead the ITGC dimension of IA's assessment of the effectiveness of internal control over financial reporting, including access management, change management, computer operations, and program development, from scoping input through testing and deficiency management.
  • Support ITGC remediation that matters: tackle high-priority gaps including privileged and service account access, segregation of duties, and access governance, and see them through to sustained, evidenced remediation.
  • Assess automated controls, key reports, and IPE assurance, ensuring the system-driven controls and data the assessment relies on are actually reliable.
  • Coordinate across the three lines and with external audit so reliance is maximized and duplication eliminated.

Deliver rapid insights

  • Be the technical trusted resource: fast, risk-based answers on technology, security, and AI initiatives before risk gets built in.

Across everything

  • Work alongside agentic AI teammates that produce first drafts at machine speed, including risk assessments, testing, documentation, and reporting, while you own the judgment and sign-off. You'll be central to building, training, and improving these teammates. Then teach the rest of the team your cheat codes.
  • Develop people: coach team members and co-source resources, raise the technical bar, and build IT audit capability the business respects.
  • Communicate for impact: make technical risk land with non-technical leaders, plainly and without drama. No surprises: issues reach leadership when we see them, not after.

Attributes & Skills

  • 8+ years of progressive IT audit, IT risk, or technology risk advisory experience; Big 4 / national firm foundation plus in-house experience strongly preferred.
  • Strong command of risk-based auditing: technology risk assessment, planning driven by risk, and reporting that connects technical findings to business impact.
  • Deep ITGC and SOX 404 expertise across ERP environments, with Oracle Cloud/EBS experience strongly preferred and Coupa or other procure-to-pay platforms a plus, including experience coordinating across the three lines and positioning work for external auditor reliance.
  • Strong command of access management and segregation of duties concepts, including privileged and service account risk, and experience with GRC/access governance tools (e.g., Oracle Risk Management Cloud or similar).
  • Experience testing automated controls, interfaces, key reports, and IPE.
  • Data analytics capability, including SQL, Python, Alteryx, or similar, with a track record of building monitoring or full-population testing that stuck.
  • CISA required or strongly preferred; CISSP, CRISC, CIA, or cloud certifications a plus.
  • Working knowledge of cybersecurity frameworks (NIST, ISO 27001) and data privacy fundamentals; exposure to IoT/connected product environments a plus.
  • Versatility across the mandate, anchored in technology but comfortable contributing to ERM facilitation, business reviews, and compliance work.
  • AI fluency, or a genuine drive to build it. You'll work with agentic AI teammates daily and help build them. You're already using AI to accelerate testing and analysis, or you're determined to be. Bonus points if you have a point of view on how AI systems themselves should be governed and audited.
  • Executive presence with translation skills: you make technical risk land with non-technical leaders, plainly and without drama.
  • A builder's mindset. You bring structure to ambiguity, own outcomes without waiting to be told, and treat "that's how it's always been done" as an invitation.

YOUR ROLE in leading our SUCCESS DRIVERS & our UNSTOPPABLE culture

  • Rarely Satisfied: a control that works today isn't the finish line; you push for sustainable, scalable design.
  • Progress Over Perfection: you sequence remediation pragmatically and keep the program moving.
  • Details Make the Difference: in ITGC, one shared credential is the difference. You find it.
  • Winning Is a Team Sport: you partner with IT and InfoSec as allies, complementing the teams already on the risk.
  • Communicating for Impact: you turn technical findings into decisions leaders can act on today. No surprises.

What SharkNinja employees say

Workplace

Get the full story on Breakroom