The Manager, IT Governance, Risk & Compliance is responsible for executing and governing the enterprise IT Governance, Risk, and Compliance (GRC) program, with primary focus on Sarbanes-Oxley (SOX) IT General Controls (ITGCs), IT Application Controls (ITACs), and internal control over financial reporting (ICFR).
This is a fully remote role, with the base compensation expected to be between $134,400 - $168,000 annually.
What You Will Work On
- Control Framework Management: Maintain the enterprise IT control framework supporting SOX 404. Approve IT control design and control narratives, perform annual ITGC and ITAC scoping and risk assessment, and recommend scope and control rationalization decisions across regions and delivery teams.
- SOX Program Execution: Manage the end-to-end SOX IT compliance calendar. Approve the annual testing approach, sampling methodology, and completed workpapers; oversee testing of design and operating effectiveness; and recommend deficiency classifications.
- ITGC Domain Governance and Execution Oversight: Coordinate and oversee control activities across Access Controls, Change Management, Computer Operations, and SDLC, including privileged access management, access certifications, CI/CD and emergency change governance, and backup and job scheduling controls. Provide technical direction and quality review for activities performed by internal, offshore, international, and co-source resources, while directly executing higher-risk or complex control activities as needed.
- ITAC and Key Report Testing: Approve test scripts and the completeness and accuracy validation procedures for automated application controls, interface controls, and Key Reports (IPE/IUC), and oversee their design, testing, and documentation.
- Audit Coordination: Serve as the day-to-day point of contact for internal audit and external audit teams. Approve PBC evidence packages for completeness and accuracy prior to release to auditors, and prepare IT control reporting materials for the Audit Committee.
- Remediation Execution: Perform root-cause analysis on identified deficiencies, approve remediation validation testing and evidence of closure, and recommend remediation plans, target dates, and residual risk positions.
- ICFR Sub-Certification Support: Prepare and maintain the control documentation and evidence supporting the sub-certification for quarterly Section 302 and annual Section 404 management assertions.
- Identity Governance: Approve the Segregation of Duties (SoD) ruleset design and the periodic access review methodology, administer the enterprise access governance model, and escalate access-related exceptions for risk-acceptance decisions.
- Policy, Standards and Procedures: Approve IT standards, procedures, and control narratives aligned to COBIT, COSO, NIST CSF, and ISO 27001, and draft enterprise IT security, access, change management, and computer operations policies.
- Third-Party Risk Assessment: Approve the vendor SOC review methodology and the conclusions of Complementary User Entity Controls (CUEC) and Complementary Subservice Organization Controls (CSOC) testing, and recommend vendor risk acceptance decisions.
- Global Delivery Oversight: Provide governance, technical direction, and quality review for IT SOX testing and compliance activities performed by offshore, international, and co-source resources, ensuring consistent application of the Company's control framework, testing methodology, evidence standards, and remediation practices across regions.
- Privacy and Awareness Program Support: Perform IT control testing and evidence collection supporting the enterprise data privacy program (GDPR, CCPA/CPRA, HIPAA) and the security awareness program, in partnership with appropriate Privacy, Information Security, Legal, and People/HR stakeholders.
- Technical Direction and Review: Provide technical direction and mentorship to analysts, offshore/international team members, and co-source resources, and approve the testing work they perform. Where this role performs testing directly, review and approval is provided by the VP of IT or a designated peer reviewer.
- Plan Development: Approve the detailed testing calendar and resource allocation within the approved plan, including allocation of work across domestic, offshore, international, and co-source resources, and recommend the annual IT compliance testing plan, sampling strategy, and budget to the VP of IT.
- Control Monitoring: Perform ongoing monitoring of the IT control environment and report control status, exceptions, and trends to IT leadership.
- Compliance Automation: Approve the design of compliance automation and continuous control monitoring rules, and implement automated evidence collection and audit logging across GRC platforms and native cloud tooling.
What You Will Bring
- Bachelor's degree in Management Information Systems, Computer Science, Information Security, Accounting, or a related field.
- 6+ years of progressive experience in IT Audit, IT GRC, or Information Security Compliance, including at least 2 years in a senior or lead capacity within a SOX compliance program.
- Demonstrated experience performing and reviewing ITGC and ITAC testing in a SOX 404 environment, including preparation of the evidence supporting ICFR management assertions.
- Experience preparing and presenting IT control status, deficiency summaries, and remediation progress to audit and disclosure audiences.
- Experience providing technical oversight or quality review for geographically distributed, offshore, international, and/or co-source compliance resources.
- Active professional certification required, with CRISC or CISM preferred; CISA, CIA, or CISSP also accepted.
- Hands-on experience testing controls across enterprise ERP and finance systems, cloud identity providers (e.g., Entra ID, Okta), Privileged Access Management (PAM) tools, relational databases (e.g., SQL Server, Oracle), and cloud deployment pipelines (CI/CD, Azure).
- Working fluency in SOX 404, COBIT, COSO, NIST CSF, and ISO 27001, and familiarity with global data privacy regulations including GDPR, CCPA/CPRA, and HIPAA.
- Familiarity with GRC platforms, Privacy Management software (e.g., OneTrust), and continuous control monitoring tooling.
- Proven ability to exercise sound professional judgment in evaluating control evidence, approving audit work product, and escalating risk decisions promptly to the accountable control owner.
What You Can Expect
- An inspirational place for you to do your best work, be engaged in meaningful ways, and continually develop the skills, competencies and qualities that set our team apart.
- Compensation commensurate with your qualifications, experience, and other factors, including geographic location, market and operational factors.
- Total Rewards based on eligibility include: Medical, Dental, Vision, Life Insurance, Disability Insurance, 401(k) Savings Plan, Employee Stock Purchase Plan, Professional Development Program, Paid Time Off, Paid Holidays and Paid Sick Time (in geographies where legally required).