
IT Compliance Manager
Posted Aug 25

Posted Aug 25
This is a fully remote position, open to applicants in India.
• Support the implementation of the IT Compliance program and strategy alongside the Director of IT Compliance and Strategy, as well as SOX Compliance, and both internal and external auditors.
• Perform assessments of control designs and conduct periodic evaluations of control effectiveness across IT General Controls (ITGCs) and IT Application Controls (ITACs).
• Lead compliance outcomes at the domain level and manage multi-quarter initiatives, which include system onboarding, control rationalization, evidence automation, and continuous monitoring of controls.
• Supervise ITGC operations that encompass logical access management, change management, computer operations, and cloud configuration controls.
• Manage the ITAC portfolio, which covers automated controls, critical reports and Information Produced External (IPE), configuration controls, and interface/data-transfer controls.
• Keep an updated inventory of systems and tools that support financial reporting while applying a risk-based tiering approach.
• Direct internal and external IT audits, SOX reviews, and control assessments.
• Organize walkthroughs, Provide By Client (PBC) requests, testing, and status updates for leadership.
• Conduct root-cause analyses, design remediation strategies, validate fixes, and prevent the recurrence of findings.
• Integrate automated evidence collection, continuous monitoring of controls, analytics, and responsible AI technology into compliance workflows.
• Establish and communicate control architecture and requirements.
• Ensure that change management and Software Development Life Cycle (SDLC) controls enhance system stability and release quality within Continuous Integration/Continuous Deployment (CI/CD) pipelines, infrastructure-as-code, and automated access workflows.
• Prepare narratives, flowcharts, risk-and-control matrices, and test workpapers.
• Collaborate with Engineering, Product, Security, Finance, and Compliance teams; mentor control owners, and constructively resolve conflicts.
• Bachelor’s degree in Information Technology, Accounting, Management Information Systems (MIS), or Finance.
• 7–10 years of increasing responsibility in IT audit, internal controls, or technology risk management, including supervisory roles; experience with Big 4 firms is preferred.
• Professional certifications such as CISA, CRISC, CIA, or CPA are highly preferred.
• Extensive, practical knowledge of SOX 404 ITGCs and ITACs, including key reports/IPE, configuration controls, and interface controls.
• Strong understanding of internal control frameworks (COSO, COBIT) and risk assessment methodologies.
• Familiarity with cloud platforms, CI/CD pipelines, DevOps practices, and modern Software as a Service (SaaS) architectures.
• Knowledge of logical access, change management, least privilege principles, segregation of duties, computer operations, and vulnerability management.
• Capability to plan and execute audits and manage multi-quarter control initiatives within complex technology environments.
• Excellent communication, analytical, problem-solving, and program management abilities.
• Skill in translating technical details for executive and audit audiences.
• Proficiency in influencing stakeholders and maintaining standards without direct authority.
• Experience in the technology industry is strongly preferred.
• Global, remote-first organization.
• Equal Opportunity Employer.
• Voluntary demographic information; refusal does not affect application status.
• Privacy Policy review required before application.
RTX
EnergyHub
Johnson & Johnson
Johnson & Johnson
Get handpicked remote jobs straight to your inbox weekly.