The Opportunity:We're looking for a Senior Manager, IT SOX Audit to help stand up Grafana Labs' IT SOX program from the ground up as we scale our controls and governance for our next stage of growth. This is a hands-on, high-visibility role reporting to the Head of Internal Audit, with direct exposure to Finance, IT, Engineering, Security, and senior leadership.
This is a player-coach individual contributor role today. You'll architect and execute the IT SOX program yourself and with external consultant support, influencing through expertise rather than direct reports. As the function matures, you'll have the opportunity to broaden your scope into technology and IT audit and to build and lead a team over time.
Success here isn't measured by control test completion rates or a tally of audit projects. It's measured by whether Grafana is more risk-intelligent, better controlled, and able to continue to scale because of your work. This is ideal for someone who enjoys building from scratch, partnering closely with stakeholders, and leveraging modern tools, including AI, to deliver efficient, high-impact assurance.
What You'll Be Doing:- Partner with the Head of Internal Audit to build and operate Grafana's IT SOX program from the ground up: scoping, risk assessment, control design, and testing across IT general controls (ITGCs) and key application controls tied to financial reporting.
- Design and execute all phases of IT SOX activity: walkthroughs, design and operating effectiveness testing, documentation, status tracking, deficiency identification, and remediation validation.
- Assess ITGCs and application controls across key financial systems and Grafana's cloud/SaaS environment (e.g., NetSuite, Salesforce, Workday]).
- Own the IT SOX documentation library in partnership with the Business Process / Finance SOX lead (narratives, flowcharts, and IT risk-and-control matrices (RCMs), and keep it audit-ready at all times.
- Drive deficiency management conversations with control owners, advocating for automation-first, scalable remediation over manual, siloed patches.
- Own the relationship with external IT auditors, ensuring testing methodologies and documentation meet PCAOB standards and align with external auditor expectations to create the foundation for a future reliance strategy.
- Leverage AI and automation to enhance scoping, testing, and continuous monitoring, building capabilities and operationalizing insights, not just running checklists.
- Evaluate the IT control impact of new systems, tools, operations, and policies as Grafana scales.
- Manage co-source partner resources while maintaining quality and driving consistency across the program.
- Report on IT SOX status, risks, deficiencies, and remediation to the Head of Internal Audit and senior leadership.
- Over time, help extend the function beyond SOX into broader technology and IT audit, and build, mentor, and scale a team as the organization grows.
What Makes You a Great Fit:- 10+ years of progressive experience in IT SOX compliance, IT audit, or IT risk advisory in Big 4 (or similar) and/or an in-house audit, compliance, or risk management function.
- Proven hands-on expertise in COSO, SOX 404, ITGCs, ITACs, and PCAOB audit standards.
- Experience standing up, scaling, or transforming an IT SOX program, ideally in a pre-IPO or newly public, high-growth SaaS environment.
- Experience auditing cloud-native, SaaS environments and modern ERPs and business applications (e.g., NetSuite, Salesforce, Workday).
- Track record of implementing or optimizing AI and automated compliance and audit capabilities.
- Fluency in key frameworks such as COSO, COBIT, NIST CSF, and ISO 27001.
- Experience with GRC / audit tools, or building home-grown solutions.
- Strong project management and organizational skills with the ability to oversee complex programs and prioritize ruthlessly.
- Proven ability to inform and influence senior management stakeholders. You can influence without authority and make technical risk clear, urgent, and actionable.
- CISA, CPA, CIA, or CISSP strongly preferred.
- High integrity, ownership, curiosity, and a continuous-improvement mindset.
Bonus Points For:- A blend of both Big 4 (or similar) and in-house audit, compliance, or risk management leadership experience.
- Experience in a pre-IPO and/or newly public, high-growth, consumption/usage-based SaaS technology company.
- Additional certifications that signal breadth and depth: CPA, CISM, CRISC, or CGEIT.
- ISACA AAIA (Advanced in AI Audit), or a demonstrated track record of investing in AI governance and audit innovation.
- Experience broadening an audit function beyond SOX into technology, operational, or advisory assurance.
- Experience working in globally distributed organizations.
Compensation & Rewards:In the United States, the base compensation range for this role is $163,000 - $195,000. Actual compensation may vary based on level, experience, and skillset as assessed throughout the interview process. All of our roles include Restricted Stock Units (RSUs), giving every team member ownership in Grafana Labs' success. We believe in shared outcomes; RSUs help us stay aligned and invested as we scale globally.
#LI-Remote
Compensation ranges are country specific. If you are applying for this role from a different location than listed above, your recruiter will discuss your specific market's defined pay range & benefits at the beginning of the process.
*Compensation ranges are country specific. If you are applying for this role from a different location than listed above, your recruiter will discuss your specific market's defined pay range & benefits at the beginning of the process.
Why You'll Thrive at Grafana Labs:- 100% Remote, Global Culture - As a remote-only company, we bring together talent from around the world, united by a culture of collaboration and shared purpose.
- Scaling Organization - Tackle meaningful work in a high-growth, ever-evolving environment.
- Transparent Communication - Expect open decision-making and regular company-wide updates.
- Innovation-Driven - Autonomy and support to ship great work and try new things.
- Open Source Roots - Built on community-driven values that shape how we work.
- Empowered Teams - High trust, low ego culture that values outcomes over optics.
- Career Growth Pathways - Defined opportunities to grow and develop your career.
- Approachable Leadership - Transparent execs who are involved, visible, and human.
- Passionate People - Join a team of smart, supportive folks who care deeply about what they do.
- In-Person onboarding - We want you to thrive from day 1 with your fellow new 'Grafanistas' to learn all about what we do and how we do it.
- Balance is Key - We operate a global annual leave policy of 30 days per annum. 3 days of your annual leave entitlement are reserved for Grafana Shutdown Days to allow the team to really disconnect. *We will comply with local legislation where applicable.