IT Compliance Manager ensures IT systems, processes, and controls comply with SOX requirements, CMMC, applicable laws, industry standards, and company policies across the global Astronics organization. This role leads IT SOX audit activities and CMMC readiness efforts, working closely with internal audit, external auditors, control owners, and business stakeholders to identify compliance risks, implement controls, and drive remediation.
In addition to a collaborative culture at a long-standing organization committed to continued growth, Astronics offers:
- Competitive base salary with quarterly bonus opportunities
- Hybrid role, work two days onsite in our East Aurora, NY office
- 9/80 schedule with every other Friday off
- 401(k) with company contribution and discounted Employee Stock Purchase Plan
- Comprehensive health, dental, vision, and life benefits
- Week-long Christmas shutdown and paid holidays
What You'll Do - Own the IT SOX compliance program, including ITGC scoping, control design, testing coordination, and remediation tracking across all in-scope systems and processes
- Act as primary point of contact for coordination of IT SOX audit activities with internal and external auditors, managing evidence requests, and facilitating walkthroughs and interim ITGC change testing
- Manage CMMC readiness efforts including POAM remediation, scoping, evidence gathering, and C3PAO coordination
- Develop, implement, and maintain comprehensive IT compliance programs to ensure adherence to relevant regulations, laws, and industry standards including SOX and CMMC/DFARS
- Lead a team of IT compliance analysts, supporting their independent ownership of individual control areas; providing mentorship through ongoing professional development
- Manage user access review (UAR) cycles, including scheduling, evidence coordination, remediation tracking, and follow-up with control owners on high-priority items
- Monitor IT change activity through tools such as Tripwire, coordinating scope decisions and managing reconciliation queues
- Draft and route IT policies and procedures for approval, engaging key stakeholders as needed
- Create IT compliance training programs, monitor delivery and ensure employee completion
- Review and approve exception and control reviews, ensuring remediation plans adequately mitigate identified risks
- Serve as subject matter expert on IT compliance matters, fielding questions from stakeholders and routing inquiries to appropriate compliance analysts based on expertise
- Coordinate with the Director of IT, Internal Audit, Finance, and other departments to ensure effective communication on IT compliance initiatives, including project charter reviews and new system implementations
- Proactively track IT compliance trends and anticipated regulatory modifications to support organizational compliance
What You'll Bring - 5+ years of experience leading IT audit or compliance functions, with significant hands-on SOX ITGC experience
- Expertise in managing IT SOX audits end-to-end, including coordination with external auditors
- Deep familiarity with ITGC domains: access management, change management, computer operations, and logical security
- Exposure to CMMC, DFARS, or NIST 800-171 compliance programs
- Strong interpersonal, analytical, and written communication skills; ability to translate complex compliance and technical requirements for finance, operations, and executive audiences
- Detail-oriented with the ability to manage competing priorities and tight audit deadlines
What Makes You Stand Out - CPA, CISA, CISSP, or equivalent certification
- Experience with IT compliance frameworks such as COBIT or NIST
- Experience with GRC tools (e.g., CrossComply) for control tracking and audit evidence management
- Experience with formal assessment preparation
- Familiarity with change monitoring tools and compliance training platforms
- Knowledge of additional regulatory requirements relevant to aerospace and defense (e.g., ITAR, GDPR)
Why You'll Enjoy Working Here: - Base salary: $122,000 to $147,000 annually, influenced by several factors including experience, skill set, education, certifications, market conditions, and business needs
- Generous Time Off: Starting with 120 hours of paid time off annually, plus 12 paid holidays per year
- Competitive rewards: Benefits start the first of the month after hire, quarterly bonus tied to company profitability, 401(k) with 3% company contribution, Employee Stock Purchase Plan, paid holidays (including a full Christmas week shutdown), and comprehensive health/vision/dental coverage
- Professional growth: Continuing education support, certifications, and exposure to data governance on a global scale
- A culture that values balance: Work with a high-performing, motivated team that also promotes positivity and collaboration
This position may involve access to items subject to U.S. export-control laws. Employment is contingent upon the employee's authorization to access such items under applicable law. The company does not guarantee and is under no obligation to seek such authorization if it would be necessary.
Position RequirementsFull-Time/Part-Time Full-Time