When: June 3, 2026
Where: Building 800 Frontier RTP (800 Park Offices Drive, RTP NC 27713)
CPEs: Up to 4
Registration: Teams Registration
Session 0 - Professional Development: Mock Interviews (1200-1300, in person only)
ISACA RTC is conducting mock interviews for those who are interested in practicing their interview skills.
Each interview will be 15 minutes long: 5 minutes with a recruiter for a resume review, 8 minutes with a hiring manager or technical expert, and 2 minutes for feedback.
If you would like to be an interviewee, please fill out the ISACA RTC Mock Interview Application
If you would like to assist as an interviewer, please fill out the ISACA RTC June 2026 Mock Interviewer Applications
We are planning on a total of 8 interviews.
Session 1 - Bridging the Gap Between InfoSec and IT Audit: From Misalignment to Measurable Assurance (1300-1430)
Information Security and IT Audit teams often share objectives but use very different languages, priorities, and success metrics. This disconnect can lead to friction, duplicated effort, and audit results that fail to improve security outcomes meaningfully. This session is designed for internal auditors and information security professionals seeking to close that gap.
The course explores how InfoSec functions actually manage risk in modern environments and how auditors can evaluate those activities using a risk-based approach. Participants will learn how to translate security practices into audit-ready evidence, align audit procedures with real-world threat models, and build more productive working relationships between audit and security teams.
The session emphasizes shared accountability, clearer communication, and risk-based assurance that resonates with both technical and governance stakeholders.
Learning Objectives
By the end of this session, participants will be able to:
- Differentiate the core objectives, incentives, and risk perspectives of InfoSec and IT Audit functions.
- Identify common points of breakdown between security operations and audit activities that reduce assurance value.
- Translate cybersecurity activities such as monitoring, incident response, and vulnerability management into auditable control evidence.
- Evaluate cybersecurity controls based on effectiveness and outcomes rather than documentation alone.
- Strengthen collaboration between auditors and security leaders to improve governance, reporting, and risk transparency.
Speaker: Toby DeRoche
Toby DeRoche is a bestselling business writer, governance professional, and entrepreneur with an academic foundation in English Literature, an MBA, and more than two decades of audit, risk, and compliance experience.
As a practicing auditor, Toby brings real-world experiences to every presentation. His approach always incorporates both theory and practical application, so your group leaves with actionable information. Toby has delivered well over 1,000 hours of professional development to internal audit, risk management, and fraud practitioners in corporate, government, and non-profit organizations.
As a writer, he has produced more than 250 thought-leadership articles for industry leaders across the United States, Canada, and Europe. Toby has authored 16 whitepapers and four books, among them Agile Audit: Transformation and Beyond, Only Audit What Matters (an Amazon bestseller), Modernize Your Audit Department, and Not Yet: A Warming Tale About My Neighborhood. He also contributed two chapters to the 28th edition of ISACA’s CISA Review Manual as an IT subject matter expert. His forthcoming book, Cybersecurity by Design, is scheduled for release in December 2026.
Session 2 - Chapter AGM & Chapter Officer Elections (1430-1500)
Restricted to chapter members; in-person attendance is required for members to vote.
Nominations can be from the floor or submitted online via the ISACA Research Triangle Chapter Leadership nomination form
Our Chapter President will also be providing his annual president's report to membership.
Session 3 - Software Security: From Antagonist to Ally (1515-1645)
Speaker: Eric Haugen, Founder & Principal, Voloaude
Eric is a seasoned software leader who has held executive roles as Vice President of Product, Vice President of Customer Success, and Engineering Director and led teams across SaaS, professional services, and government sectors. This multidisciplinary background allows Eric to bridge the product, revenue, and engineering sides of software and solve complex challenges by connecting insights others might miss. Eric currently helps growth stage software startups overcome scaling challenges and achieve their revenue goals.