Manager, Internal Audit
Job description
Manager, Internal Audit at Openloop Health.
About the role
OpenLoop is seeking an Internal Audit Manager to help build its newly established audit function within a fast-growing, multi-state regulated business. In this role, you will report directly to the Head of Internal Audit and own the design, execution, and follow-through of risk-based audit activities across financial, operational, and compliance domains. You will develop and maintain a dynamic risk-based audit plan, conducting periodic risk assessments to establish clear audit priorities and work schedules. You will lead end-to-end audit engagements, coordinating planning, fieldwork, reporting, and issue closure with stakeholders at all levels. This position offers meaningful ownership, broad exposure, and visibility into how telehealth operations scale across diverse state regulatory environments. You will act as a strategic partner, strengthening controls and mitigating risk while helping the organization navigate evolving compliance expectations.
Key facts
What you'll do
- Develop and maintain a risk-based audit plan, conducting periodic risk assessments across business processes, entities, and emerging risk areas to establish audit priorities.
- Lead end-to-end audit engagements, from planning through fieldwork, reporting, and issue closure while ensuring alignment with timelines and stakeholder expectations.
- Design and execute control testing procedures independently, including performing walkthroughs, conducting inquiry, inspecting documentation, and executing reperformance activities.
- Prepare and maintain comprehensive audit documentation, including process narratives, flowcharts, risk and control matrices (RCMs), testing workpapers, and structured audit reports.
- Facilitate kickoff meetings, status update sessions, and closing meetings with process owners and senior management to ensure clarity and alignment.
- Identify control deficiencies and communicate findings clearly, offering practical and prioritized remediation recommendations that support timely resolution.
- Support management in designing and implementing controls to address identified gaps and process weaknesses, collaborating closely on control enhancements.
- Track open audit issues and remediation plans through closure, validating the effectiveness of corrective actions and confirming control improvements.
- Support readiness for regulatory and compliance audits, including HIPAA, data privacy requirements, and applicable state licensing processes.
- Collaborate cross-functionally with Finance, Legal, Compliance, IT, and Operations to support control assessments and continuous process improvements.
- Contribute to developing and refining IA methodology, workpaper templates, and audit tooling as the internal audit function matures and scales.
- Monitor the evolving regulatory and risk landscape relevant to telehealth and healthcare services to keep the audit plan current, relevant, and forward-looking.
Requirements
- Hold a Bachelor's degree in Accounting, Finance, Healthcare Administration, or a related field and maintain an active Certified Internal Auditor (CIA) designation.
- Bring 5+ years of progressive experience in internal audit, external audit, business risk advisory, or healthcare regulatory roles.
- Demonstrate hands-on experience across the full audit lifecycle, including risk assessment, control design and testing, workpaper documentation, and audit report writing.
- Execute audit activities independently with the ability to manage assignments without close supervision and exercise sound professional judgment.
- Deeply understand COSO frameworks and internal control principles, applying them consistently across diverse audit engagements.
- Manage multiple concurrent audit engagements, prioritize effectively under competing deadlines, and deliver high-quality results on schedule.
- Work directly with process owners at all organizational levels within a fluid environment where formal controls are still being built and refined.
- Build control awareness across the organization, educating process owners and non-finance stakeholders on internal audit's role and foundational control concepts.
- Apply critical thinking to distinguish material risks from noise and communicate findings with precision, tact, and clarity.
- Communicate concisely and clearly in both written and verbal formats, translating technical control concepts for non-audit audiences.
- Show strong proficiency with AI tools and data analytics platforms such as ACL, Galvanize, IDEA, Power BI, or Tableau for control testing and exception analysis.
Nice to have
- Bring a public accounting background from Big 4 or regional firms with a focus on SOX or advisory engagements.
- Hold a Certified Public Accountant (CPA) or additional relevant certifications such as CISA or CFE.
- Contribute experience supporting an organization through an IPO readiness process or M&A integration.
- Demonstrate proficiency with GRC platforms including AuditBoard, Workiva, or Vanta.
- Offer prior experience in digital health, telehealth, or multi-state healthcare services environments, including familiarity with HIPAA, state medical board licensing, and clinician credentialing compliance.
- Show familiarity with data privacy frameworks beyond HIPAA, such as CCPA or other applicable state-level regulations.
- Bring exposure to healthcare revenue cycle operations, compounding pharmacy, or pharmaceutical regulatory environments, including claims, billing integrity, and payer compliance.
Practical notes
This engagement is full time. The role is remote within the United States.
Output the page only.