Sedgwick

Director, IT Risk and Controls - Remote Position

Sedgwick$130K — $160K *
US-Anywhere
+ 49 other locationsRemote
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Advanced degree in Accounting, Finance, Information Systems, Business or related field preferred.
  • CISA certification strongly preferred; CPA, CRISC, CIA, CISSP beneficial.
  • 10 years of progressive experience in IT risk management, IT controls, or IT audit.
  • Proven experience in assessing technology risks and designing IT controls.
  • Advanced knowledge of SOX requirements, ITGCs, and governance frameworks like COSO and COBIT.

Responsibilities

  • Lead the IT risk and control governance program, focusing on SOX and ITGCs.
  • Direct governance operations including risk assessments and control documentation.
  • Act as the senior subject matter expert for IT SOX compliance and related controls.
  • Maintain risk and control governance documentation and frameworks.
  • Advise control owners on risk identification and control design.
  • Partner with IT Compliance to provide program context and documentation.
  • Monitor control effectiveness and report on trends and risk themes.

Benefits

  • Remote work opportunity with flexibility.
  • Supportive work culture fostering performance and professional growth.
  • Comprehensive onboarding and training programs.
  • Opportunity to lead and influence organizational risk strategies.
Full Job Description
Director, IT Risk and Controls - Remote Position PRIMARY PURPOSE OF THE ROLE: The Director IT Risk and Controls leads Sedgwick's IT risk and control governance activities, including SOX-related technology controls, IT General Controls (ITGCs), and broader technology risk and control processes. The role provides subject matter expertise, guidance, and oversight to support a consistent and sustainable control environment while partnering with Technology, Finance, Risk, Compliance, and Audit stakeholders to identify risks, strengthen controls, and support regulatory and governance requirements. ESSENTIAL RESPONSIBILITIES MAY INCLUDE • Leads the enterprise IT risk and control governance program, encompassing SOX, ITGCs, and broader technology risk and control activities, including IT risk assessments, control scoping and design, framework governance, and management reporting. • Directs governance operations, including risk assessments, control documentation, issue management processes, governance reporting, control inventories, repositories, and executive reporting to support effective program administration and leadership decision-making. • Serves as the senior subject matter expert for IT SOX compliance, ITGCs, automated controls, key reports, interfaces, end-user computing controls, third-party dependencies, and other technology controls supporting business and financial reporting objectives. • Owns and maintains risk and control governance documentation, including narratives, RCMs, control descriptions, policies, standards, evidence requirements, control-owner guidance, and system inventories. • Advises control owners and Technology leaders on risk identification, control design, segregation of duties, evidence requirements, compensating controls, and sustainable control execution. • Partners with the IT Compliance function by providing program context, documentation, reporting, and management input while maintaining appropriate separation from independent assurance, testing, and remediation oversight activities. • Monitors and reports on control effectiveness using attestations, operational metrics, continuous monitoring results, and assurance inputs; identifies trends, recurring risk themes, and matters requiring leadership attention. • Maintains governance visibility of control deficiencies, risk exposures, and related remediation activities for reporting and management awareness while independent oversight and validation remain the responsibility of the IT Compliance function. SUPERVISORY RESPONSIBILITIES • Provides support, guidance, leadership and motivation to promote maximum performance. • Administers company personnel policies in all areas and follows company staffing standards and training recommendations. • Interviews, hires and establishes colleague performance development plans; conducts colleague performance discussions. QUALIFICATIONS Advanced degree in Accounting, Finance, Information Systems, Business or a related field, from an accredited college or university preferred. CISA certification strongly preferred. Additional certifications such as CPA, CRISC, CIA, CISSP, or equivalent are beneficial. Ten (10) years of related, progressive experience in IT risk management, IT controls, IT SOX compliance, technology governance, or IT audit, including significant leadership of enterprise risk and control activities in a complex organization or equivalent combination of education and experience required. Demonstrated experience assessing technology risks; scoping systems and dependencies; and designing or advising on ITGCs, automated controls, key reports, interfaces, third-party controls, and other risk-mitigating controls highly preferred. Skills & Knowledge • Advanced knowledge of SOX requirements, IT General Controls, technology risk management practices, and governance frameworks, including COSO and COBIT. • Proven ability to evaluate control design and effectiveness information, identify risk themes, develop well-supported governance recommendations, and communicate implications to senior management and control stakeholders • Ability to partner effectively with IT Compliance, Internal Audit, External Audit, Enterprise Risk, Finance, Security, and Technology teams in complex, multi-system, and/or global operating environments Strong command of risk assessment, control design, control execution, evidence expectations, control-effectiveness reporting, issue classification, and sustainable control ownership • Ability to translate complex technical risks and control-effectiveness information into clear business, operational, and financial reporting implications • Executive-level written and verbal communication skills, including the ability to explain and support well-reasoned risk and control positions with senior leaders and assurance stakeholders • Ability to influence without direct authority, establish accountability, and drive cross-functional decisions across a broad technology risk and control environment • Advanced analytical, problem-solving, and professional judgment skills with a high degree of integrity, objectivity, and attention to detail • Working knowledge of governance, risk, and compliance platforms, control-management tools, workflow automation, and continuous monitoring solutions • Ability to manage multiple priorities and lead a year-round IT risk and control governance program in a fast-paced environment • Ability to work in a team environment • Ability to meet or exceed Performance Competencies WORK ENVIRONMENT When applicable and appropriate, consideration will be given to reasonable accommodations. Mental: Clear and conceptual thinking ability; excellent judgment, troubleshooting, problem solving, analysis, and discretion; ability to handle work-related stress; ability to handle multiple priorities simultaneously; and ability to meet deadlines Physical: Computer keyboarding, travel as required Auditory/Visual: Hearing, vision and talking The statements contained in this document are intended to describe the general nature and level of work being performed by a colleague assigned to this description. They are not intended to constitute a comprehensive list of functions, duties, or local variances. Management retains the discretion to add or to change the duties of the position at any time. #LI-TS1 #remote

About Sedgwick

Sedgwick is a global provider of insurance, risk management, and related services. The company was founded in 1969 and is headquartered in Boston, Massachusetts. Sedgwick offers a range of services to clients in various industries, including property and casualty insurance, workers' compensation, and disability management. The company has a team of experienced professionals who work closely with clients to develop customized solutions that meet their specific needs. Sedgwick has a reputation for delivering high-quality service and has been recognized for its excellence in the insurance industry.
Learn more about Sedgwick
Size
10,000 employees
Industry
Founded
1969

Similar Jobs

More Jobs at Sedgwick

More Information Technology Jobs

Find similar Director, IT Risk and Controls - Remote Position jobs: