866,360open jobs
54,486companies
146,147added this week
Browse all
Salary
$97k – $184k per year
Location
Hybrid (Chicago, United States)
Seniority
Middle · 5+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 27, 2026. First seen by Alion on Sep 25, 2026. AbbVie scores B on the Alion truth index.

Overview
Company
Impact
Profile match
AbbVie is an American biopharmaceutical company created in 2013 when Abbott Laboratories separated its research-based drug business into a standalone listed company. It was built around the immunology drug Humira, once the highest selling medicine in the world, and has since replaced that revenue with the successor immunology drugs Skyrizi and Rinvoq, an oncology portfolio led by Imbruvica and Venclexta, neuroscience products including Botox Therapeutic and Vraylar, and the aesthetics business acquired with Allergan. Headquartered in North Chicago and listed on the New York Stock Exchange, it is one of the largest pharmaceutical companies by revenue.

About AbbVie

AbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people's lives across several key therapeutic areas including immunology, oncology and neuroscience - and products and services in our Allergan Aesthetics portfolio. For more information about AbbVie, please visit us at www.abbvie.com. Follow @abbvie on LinkedIn, Facebook, Instagram, X and YouTube.

Summary

The Supervisor, Global Technology Audit serves as the Internal Audit subject matter expert for cybersecurity risk, security architecture, threat management, and technical security controls.

The incumbent is responsible for executing complex technology audit work with a high degree of technical independence and expert-level domain judgement. This role leads defined audit components as Functional Coordinator (FC) and may serve as Overall Coordinator (OC) for less complex engagements, applying threat-informed, risk-based thinking to assess control design and operating effectiveness across cybersecurity, infrastructure, cloud, identity, and emerging technology domains. The Supervisor functions as the technical subject matter resource on assigned engagements capable of independently evaluating security architecture and interpreting technical artifacts. This role coaches Senior Auditors on technical rigor and professional skepticism, and contributes to audit methodology development, technical testing procedure design, and continuous improvement of audit quality.

Candidates are expected to develop and sustain deep practitioner-level expertise in one or more high-risk technology domains, providing technical continuity, audit program ownership, and domain leadership over a longer tenure in the function. The incumbent partners with Cybersecurity, Infrastructure, Cloud Engineering, Digital Technology, Compliance, and Business stakeholders to assess cybersecurity risks, evaluate control effectiveness, and provide independent assurance over the organization's security posture.

Responsibilities

Audit Leadership:

  • Lead end-to-end execution of complex technology audit engagements as Functional Coordinator (FC), with full accountability for scoping, fieldwork, evidence assessment, and findings development in cybersecurity, infrastructure, cloud, and IT general controls domains.
  • Serve as the technical subject matter resource for assigned anchor domains, independently evaluating control design and operating effectiveness in areas including cloud security architecture, identity and access management, vulnerability and patch management, network security, endpoint detection and response, and privileged access governance.

Cybersecurity Assessments:

  • Lead complex cybersecurity audits, assessments, and advisory reviews across enterprise technology environments.
  • Develop risk assessments, audit programs, testing strategies, and report deliverables for cybersecurity-related engagements.
  • Independently evaluate the design and operating effectiveness of technical, administrative, and detective security controls.
  • Identify emerging cyber risks, control deficiencies, and opportunities to strengthen the organization's control environment.

Technical Security Assessments:

  • Review and assess:
    • Security architecture and infrastructure controls
    • Identity and Access Management (IAM)
    • Privileged Access Management (PAM)
    • Cloud security configurations and governance
    • Network security and segmentation
    • Endpoint protection controls
    • Vulnerability management programs
    • Security monitoring and threat detection capabilities
    • Incident response and cyber resilience processes
  • Assess technical evidence including architecture diagrams, firewall rules, IAM configurations, SIEM detections, vulnerability scan results, cloud security configurations, and security control implementations.

Threat-Informed Assurance:

  • Utilize MITRE ATT&CK and industry frameworks to evaluate preventive and detective control coverage against relevant threat tactics, techniques, and procedures (TTPs).
  • Assess the effectiveness of security controls against the enterprise threat landscape and risk profile.
  • Evaluate detection, response, and recovery capabilities across key cyber threat scenarios.

Governance & Risk Management:

  • Evaluate cybersecurity governance frameworks, policies, standards, and oversight mechanisms.
  • Assess enterprise cybersecurity risk management and third-party cybersecurity risk practices.
  • Evaluate alignment with industry frameworks and regulatory requirements.

Advisory & Strategic Support:

  • Provide cybersecurity expertise during technology transformation, cloud adoption, and emerging technology initiatives.
  • Monitor evolving cyber threats, attack techniques, regulatory developments, and industry best practices.
  • Support development of Internal Audit methodologies related to cybersecurity assurance and technical risk assessments.

Stakeholder Engagement & Leadership:

  • Present audit results, risk themes, and recommendations to management and senior leadership.
  • Serve as a trusted advisor while maintaining Internal Audit independence.
  • Mentor audit staff and contribute to development of technical cybersecurity audit capabilities across the Internal Audit function.

Required Qualifications

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Information Security, or related field from an accredited university.
  • 5+ years of experience in cybersecurity audits, technology risk, IT audit, or cloud audit.
  • CISSP, CISM, or CISA
  • Strong written and verbal communication skills with the ability to translate complex technical risks into business-focused recommendations.
  • Experience presenting findings and recommendations to senior management.

Preferred Qualifications

  • CCSP, AWS Security Specialty, or CRISC with demonstrated technical specialization
  • Strong understanding of:
    • Security architecture and engineering
    • Network security
    • Cloud security
    • Identity and Access Management
    • Security monitoring and incident response
    • Vulnerability management
  • Ability to independently analyze technical security artifacts and determine control design and operating effectiveness without reliance on auditee interpretation.
  • Working knowledge of MITRE ATT&CK and threat-informed control assessments.
  • Experience leading audits, risk assessments, or technical security reviews involving multiple stakeholders.
  • Experience auditing cloud environments including Azure, AWS, or GCP.
  • Experience assessing security operations, threat detection, incident response, or cyber resilience programs.
  • Knowledge of NIST CSF, NIST 800-series publications, CIS Controls, ISO 27001, and other cybersecurity frameworks.
  • Experience supporting or leading assessments involving AI, cloud, third-party risk management, or emerging technology risks.

Applicable only to applicants applying to a position in any location with pay disclosure requirements under state or local law:

  • The compensation range described below is the range of possible base pay compensation that the Company believes in good faith it will pay for this role at the time of this posting based on the job grade for this position. Individual compensation paid within this range will depend on many factors including geographic location, and we may ultimately pay more or less than the posted range. This range may be modified in the future.
  • We offer a comprehensive package of benefits including paid time off (vacation, holidays, sick), medical/dental/vision insurance and 401(k) to eligible employees.
  • This job is eligible to participate in our short-term incentive programs.

Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, incentive, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company's sole and absolute discretion unless and until paid and may be modified at the Company’s sole and absolute discretion, consistent with applicable law.

AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community. Equal Opportunity Employer/Veterans/Disabled.

US & Puerto Rico only - to learn more, visit https://www.abbvie.com/join-us/equal-employment-opportunity-employer.html

US & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more:

https://www.abbvie.com/join-us/reasonable-accommodations.html

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
866,360 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Industrial Engineering
Similar stack
Same company
Chicago
$56k – $86k per year • In office • 5+ years exp • Bachelor's Degree • Memphis
Apply
Technical Engineer 11 min ago
$95k – $105k per year • In office • 3+ years exp • San Francisco
PHP
PHP
Livewire
Apply
Staff Engineer 11 min ago
≈ $108k – $209k per year (Estimated) • In office • 5+ years exp • Associate's Degree • Houston
Apply
≈ $87k – $165k per year (Estimated) • In office • Full-Time • 4+ years exp • Bachelor's Degree • Portland
Apply
≈ $78k – $148k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Portland
Management
Outlook
Microsoft Office
Apply
≈ $52k – $100k per year (Estimated) • Remote (likely Poland) • Full-Time • Warsaw
Python
PowerShell
DevOps
Splunk
GCP
Prometheus
Azure
AWS
Cortex
TCP/IP
Cybersecurity
Crowdstrike
Darktrace
Microsoft Sentinel
Elastic SIEM
SentinelOne
Microsoft Defender
Cortex XDR
MITRE ATT&CK
IBM QRadar
Cortex XSOAR
Tines
SIEM
Apply
IT Architect 1 day ago
$59k – $69k per year • Remote (likely Poland) • Full-Time • Warsaw
Python
JavaScript
TypeScript
SQL
Python
FastAPI
Django
Django REST Framework
Databases
PostgreSQL
PostGIS
Frontend
Angular
React.js
DevOps
Rest API
OpenShift
CI/CD
AWS
Docker
Kubernetes
IAM
Apply
$62k – $70k per year • In office • 3+ years exp • Warsaw
Cybersecurity
MITRE ATT&CK
Apply
≈ $20k – $53k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Moscow
Cybersecurity
SIEM
DLP
Management
Microsoft Office
Apply
≈ $64k – $107k per year (Estimated) • Hybrid • Full-Time • Warsaw
DevOps
Terraform
GCP
Azure
CI/CD
Git
AWS
Docker
Kubernetes
Google GKE
FinOps
IAM
Linux
DNS
VPN
Apply
$125k – $237k per year • Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Irvine
Management
Microsoft Office
Apply
$97k – $184k per year • In office • Full-Time • 6+ years exp • Bachelor's Degree • Tempe
DevOps
Windows Server
TCP/IP
DNS
DHCP
Cybersecurity
Active Directory
Apply
$97k – $184k per year • In office • Full-Time • 6+ years exp • Bachelor's Degree • Chicago
Analytics
Power BI
Microsoft Excel
Apply
$85k – $162k per year • In office • Full-Time • 6+ years exp • Bachelor's Degree • Chicago
Apply
$79k – $141k per year • In office • Full-Time • 6+ years exp • Bachelor's Degree • Chicago
Apply
≈ $137k – $248k per year (Estimated) • In office • High School Diploma • Chicago
Apply
$60k – $140k per year • In office • 4+ years exp • Associate's Degree • Chicago
Apply
$100k – $200k per year • In office • 5+ years exp • Chicago
Apply
SEO Content Writer 1 day ago
$34k – $48k per year • Remote (United States) • Full-Time • Chicago
Marketing
Semrush
Ahrefs
Apply
$55k – $60k per year • In office • Full-Time • Chicago
Apply
See all jobs
This is one of many
866,360 more open roles from verified company boards, updated every day.