Manager, IT Risk and Compliance

Equity Trust Company

$108K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years in IT audit, risk, and compliance.
  • Bachelor's degree in IT, Computer Science, or related field; advanced degrees and certifications preferred.
  • Experience leading SOX compliance and operational info security audits.
  • In-depth knowledge of IT compliance industry standards and regulations.
  • Strong problem-solving abilities under pressure.
  • Excellent communication skills for interacting with technical and non-technical teams.

Responsibilities

  • Ensure IT operations comply with industry standards and legal regulations, focusing on SOX compliance.
  • Conduct risk assessments and manage risk mitigation for IT infrastructure.
  • Oversee application access controls to ensure authorized data access.
  • Develop and maintain internal controls in collaboration with Executive Director.
  • Create and update IT policies and procedures for compliance support.
  • Perform regular reviews to identify weaknesses in IT controls.
  • Guide and mentor IT risk staff as team responsibilities grow.
  • Monitor regulatory changes to keep practices compliant and report findings to leadership.
  • Evaluate new technologies for improved compliance and risk processes.
  • Support compliance awareness programs to enhance the Company's compliance initiatives.

Benefits

  • Comprehensive healthcare plan options for employees and families.
  • Generous paid time off policy including vacation and sick days.
  • Retirement savings plan with employer matching.
  • Career development opportunities and continuing education programs.
  • Flexible work arrangements including remote work options.
Full Job Description
JOB OVERVIEW

The Manager - IT Risk and Compliance reports to the Executive Director - IT Risk & Compliance, and ensures that all IT operations, processes, and systems are compliant with industry standards and legal regulations. Utilizes a strong background in IT audit, risk, and compliance, with a focus on SOX compliance and operational information security audits. Conducts risk assessments, manages access to applications, and develops internal controls in coordination with the Executive Director, IT Risk & Compliance. May lead or mentor IT professionals as the team structure evolves. Leverages a deep understanding of IT governance frameworks, data privacy laws, network security architecture, and business continuity planning.

RESPONSIBILITIES & DUTIES
  • Ensure that all IT operations, processes, and systems comply with industry standards and legal regulations, including a focus on SOX compliance and operational information security audits.
  • Conduct comprehensive risk assessments and manage the mitigation of identified risks to maintain the integrity and security of company IT infrastructure.
  • Oversee access to all applications, ensuring that only authorized individuals have access to relevant data and systems.
  • Develop and maintain robust internal controls, in coordination with the Executive Director, to safeguard the company's digital assets and data.
  • Develop and maintain IT policies and procedures, subject to Executive Director review and approval, to support the company's operations and regulatory compliance.
  • Conduct regular reviews of system access and IT controls to identify potential weaknesses and areas for improvement.
  • May provide guidance and mentorship to IT risk and compliance staff as team responsibilities expand.
  • Monitor regulatory changes and developments to ensure company practices remain in compliance, escalating findings and recommendations to the Executive Director, IT Risk & Compliance.
  • Evaluate and recommend new technologies to improve compliance and risk management processes.
  • Support and help implement programs/initiatives to enhance compliance awareness, contributing to continuous improvement of the Company's Compliance and Risk Management programs under the direction of the Executive Director.
  • Travel to various locations, both within our organization and externally, may be required depending on your role and responsibilities.
  • Follows assigned work schedule with regular and predictable attendance.
  • Performs other duties as assigned.


QUALIFICATIONS
  • Over 6 years of experience in IT audit, risk, and compliance.
  • Bachelor's degree in Information Technology, Computer Science, or a related field required. Advanced degrees or certifications in IT compliance or risk management are preferred.
  • Proven experience in leading IT SOX compliance and operational information security audits.
  • Strong understanding of industry standards and legal regulations related to IT and data compliance.
  • Excellent problem-solving skills and the ability to work under pressure.
  • Strong communication skills and the ability to work effectively with both technical and non-technical staff.


PROFESSIONAL CERTIFICATIONS
  • Relevant certifications such as CISA, CRISC, CDPSE, and CISM from ISACA.
  • SIE Certification
  • Series 99
  • Series 7 preferred
  • If you do not already have a Securities license relevant to your role at Innovayte, you may be required to take and pass the Securities Industries Essentials exam provided by FINRA. In addition, based on your role responsibilities, you may also be required to pass additional Securities Industry exams to allow you to operate in your role and be compliant with FINRA and the SEC requirements. These licenses, when required, need to be obtained within certain specific time frames, typically 120 calendar days.


TECHNICAL SKILLS

To be successful in this role, you should have experience with and an understanding of the following:
  • Experience with cloud-based data compliance, including familiarity with platforms like Microsoft Azure.
  • Knowledge of IT governance frameworks such as COBIT, ITIL, and ISO 27001.
  • Proficiency in using GRC (Governance, Risk, and Compliance) tools for risk assessments and compliance management.
  • Experience with data privacy laws such as GDPR, CCPA, and HIPAA.
  • Understanding of network security architecture and security system design.
  • Experience with incident response planning and security breach drills.
  • Proficiency in conducting internal and external audits for IT compliance.
  • Experience with business continuity planning and disaster recovery strategies.


PHYSICAL DEMANDS/WORK ENVIRONMENT

This job operates in a professional office environment, which may include a corporate office setting or a remote/home office environment, and routinely uses standard office equipment and technology such as computers, phones, printers, and video conferencing tools. While performing the duties of this job, the associate is regularly required to communicate effectively, including speaking, hearing, and participating in virtual meetings on camera. The associate is frequently required to sit for extended periods of time, as well as occasionally stand, walk, use hands and fingers, and reach with hands and arms. This job may require the ability to lift files or office materials, open filing cabinets, and bend or stand on a stool as necessary. Remote associates are expected to maintain a safe, secure, and productive work environment with reliable internet access.

DISCLAIMER/ASSOCIATE ACKNOWLEDGEMENT

The above statements describe the general nature and level of work only. They are not an exhaustive list of all required responsibilities, duties, and skills. Other duties may be added, or this description amended at any time.

Similar Jobs

More Jobs at Equity Trust Company

More Information Technology Jobs

Find similar Manager, IT Risk and Compliance jobs: