JUMP TO CONTENT

Supervisor, Global Technology Audit

__jobinformationwidget.freetext.LocationText__

Chicago, IL

  1. Corporate
  2. Hybrid
  1. Full-time
R00150597

Company Description

About AbbVie

AbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people's lives across several key therapeutic areas including immunology, oncology and neuroscience - and products and services in our Allergan Aesthetics portfolio. For more information about AbbVie, please visit us at www.abbvie.com. Follow @abbvie on LinkedIn, Facebook, Instagram, X and YouTube.


Job Description

Summary

The Supervisor, Global Technology Audit serves as the Internal Audit subject matter expert for cybersecurity risk, security architecture, threat management, and technical security controls.

The incumbent is responsible for executing complex technology audit work with a high degree of technical independence and expert-level domain judgement. This role leads defined audit components as Functional Coordinator (FC) and may serve as Overall Coordinator (OC) for less complex engagements, applying threat-informed, risk-based thinking to assess control design and operating effectiveness across cybersecurity, infrastructure, cloud, identity, and emerging technology domains. The Supervisor functions as the technical subject matter resource on assigned engagements capable of independently evaluating security architecture and interpreting technical artifacts. This role coaches Senior Auditors on technical rigor and professional skepticism, and contributes to audit methodology development, technical testing procedure design, and continuous improvement of audit quality.

Candidates are expected to develop and sustain deep practitioner-level expertise in one or more high-risk technology domains, providing technical continuity, audit program ownership, and domain leadership over a longer tenure in the function.  The incumbent partners with Cybersecurity, Infrastructure, Cloud Engineering, Digital Technology, Compliance, and Business stakeholders to assess cybersecurity risks, evaluate control effectiveness, and provide independent assurance over the organization's security posture.

Responsibilities

Audit Leadership:

  • Lead end-to-end execution of complex technology audit engagements as Functional Coordinator (FC), with full accountability for scoping, fieldwork, evidence assessment, and findings development in cybersecurity, infrastructure, cloud, and IT general controls domains.
  • Serve as the technical subject matter resource for assigned anchor domains, independently evaluating control design and operating effectiveness in areas including cloud security architecture, identity and access management, vulnerability and patch management, network security, endpoint detection and response, and privileged access governance.

Cybersecurity Assessments:

  • Lead complex cybersecurity audits, assessments, and advisory reviews across enterprise technology environments.
  • Develop risk assessments, audit programs, testing strategies, and report deliverables for cybersecurity-related engagements.
  • Independently evaluate the design and operating effectiveness of technical, administrative, and detective security controls.
  • Identify emerging cyber risks, control deficiencies, and opportunities to strengthen the organization's control environment.

Technical Security Assessments:

  • Review and assess:
    • Security architecture and infrastructure controls
    • Identity and Access Management (IAM)
    • Privileged Access Management (PAM)
    • Cloud security configurations and governance
    • Network security and segmentation
    • Endpoint protection controls
    • Vulnerability management programs
    • Security monitoring and threat detection capabilities
    • Incident response and cyber resilience processes
  • Assess technical evidence including architecture diagrams, firewall rules, IAM configurations, SIEM detections, vulnerability scan results, cloud security configurations, and security control implementations.

Threat-Informed Assurance:

  • Utilize MITRE ATT&CK and industry frameworks to evaluate preventive and detective control coverage against relevant threat tactics, techniques, and procedures (TTPs).
  • Assess the effectiveness of security controls against the enterprise threat landscape and risk profile.
  • Evaluate detection, response, and recovery capabilities across key cyber threat scenarios.

Governance & Risk Management:

  • Evaluate cybersecurity governance frameworks, policies, standards, and oversight mechanisms.
  • Assess enterprise cybersecurity risk management and third-party cybersecurity risk practices.
  • Evaluate alignment with industry frameworks and regulatory requirements.

Advisory & Strategic Support:

  • Provide cybersecurity expertise during technology transformation, cloud adoption, and emerging technology initiatives.
  • Monitor evolving cyber threats, attack techniques, regulatory developments, and industry best practices.
  • Support development of Internal Audit methodologies related to cybersecurity assurance and technical risk assessments.

Stakeholder Engagement & Leadership:

  • Present audit results, risk themes, and recommendations to management and senior leadership.
  • Serve as a trusted advisor while maintaining Internal Audit independence.
  • Mentor audit staff and contribute to development of technical cybersecurity audit capabilities across the Internal Audit function.

Qualifications

Required Qualifications

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Information Security, or related field from an accredited university.
  • 5+ years of experience in cybersecurity audits, technology risk, IT audit, or cloud audit.
  • CISSP, CISM, or CISA
  • Strong written and verbal communication skills with the ability to translate complex technical risks into business-focused recommendations.
  • Experience presenting findings and recommendations to senior management.

Preferred Qualifications

  • CCSP, AWS Security Specialty, or CRISC with demonstrated technical specialization
  • Strong understanding of:
    • Security architecture and engineering
    • Network security
    • Cloud security
    • Identity and Access Management
    • Security monitoring and incident response
    • Vulnerability management
  • Ability to independently analyze technical security artifacts and determine control design and operating effectiveness without reliance on auditee interpretation.
  • Working knowledge of MITRE ATT&CK and threat-informed control assessments.
  • Experience leading audits, risk assessments, or technical security reviews involving multiple stakeholders.
  • Experience auditing cloud environments including Azure, AWS, or GCP.
  • Experience assessing security operations, threat detection, incident response, or cyber resilience programs.
  • Knowledge of NIST CSF, NIST 800-series publications, CIS Controls, ISO 27001, and other cybersecurity frameworks.
  • Experience supporting or leading assessments involving AI, cloud, third-party risk management, or emerging technology risks.

Additional Information

​Applicable only to applicants applying to a position in any location with pay disclosure requirements under state or local law: ​

  • The compensation range described below is the range of possible base pay compensation that the Company believes in good faith it will pay for this role at the time of this posting based on the job grade for this position. Individual compensation paid within this range will depend on many factors including geographic location, and we may ultimately pay more or less than the posted range. This range may be modified in the future. ​
  • We offer a comprehensive package of benefits including paid time off (vacation, holidays, sick), medical/dental/vision insurance and 401(k) to eligible employees.​
  • This job is eligible to participate in our short-term incentive programs. ​

Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of  any bonus, commission, incentive, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company's sole and absolute discretion unless and until paid and may be modified at the Company’s sole and absolute discretion, consistent with applicable law. ​

AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community.  Equal Opportunity Employer/Veterans/Disabled. 

US & Puerto Rico only - to learn more, visit https://www.abbvie.com/join-us/equal-employment-opportunity-employer.html

US & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more:

https://www.abbvie.com/join-us/reasonable-accommodations.html

Recruitment Fraud Alert

We have recently become aware of various recruitment phishing scams targeting job seekers. Please be advised:



  • AbbVie will never request sensitive personal information (such as bank account details, social security numbers, or payment of any kind) during the recruitment process.
  • If you suspect you have received a fraudulent offer or communication claiming to be from AbbVie, please do not respond, open any attachments, or click on any hyperlinks.


If you have any questions or concerns regarding the authenticity of a communication alleged to have been made by or on behalf of AbbVie, please contact us immediately.


Protect yourself by verifying job offers and communications. Your safety is important to us.

  1. Yes, 10% of the Time

Pay Range:

96500 - 183500 USD

__jobinformationwidget.dynamicfield.CompensationCurrency__

USD