
IT Risks & Control Manager
Posted Aug 5

Posted Aug 5
This is a fully remote position, open to applicants in United States.
• Serve as the risk and controls partner for a designated technology organization or system portfolio, fostering a comprehensive understanding of its architecture, operations, risks, and financial-reporting dependencies.
• Take ownership and continually enhance the relevant IT risk and control framework, encompassing system scoping, risk assessment, RCM and control-catalogue maintenance, documentation, and control ownership.
• Lead IT SOX readiness for the assigned systems, which includes walkthrough preparation, evidence-quality review, testing coordination, issue evaluation, and remediation oversight.
• Collaborate with engineering, platform, infrastructure, security, and corporate IT teams to design and implement scalable controls.
• Design, evaluate, and improve ITGCs related to user access, privileged access, segregation of duties, change management, SDLC, system operations, incident management, and third-party services.
• Assess IT application controls, automated controls, and IT-dependent business controls.
• Analyze system dependencies and coordinate with business and IT control owners to address any gaps.
• Employ risk and controls thinking to cloud infrastructure, DevOps, CI/CD, repositories, deployment processes, containerized environments, and audit logging.
• Oversee the assessment and remediation of control gaps arising from new systems, technology transformations, platform changes, integrations, and acquisitions.
• Review third-party assurance reports to assess their impact on the Nebius control environment.
• Maintain relationships with external auditors and advisors, ensuring alignment on scope, evidence, testing, timelines, and issue resolution.
• Convert technical risks and auditor requirements into actionable guidance.
• Utilize data analytics, automation, continuous monitoring, and AI-assisted tools to enhance the IT SOX program.
• Contribute to the development of IT controls methodology, standards, tooling, training, reporting, and the Risk Partner operating model.
• Provide updates regarding control health, audit readiness, deficiencies, and remediation progress to senior technology and Finance stakeholders.
• A degree in Information Systems, Computer Science, Engineering, Accounting, Finance, or a related field, or equivalent professional experience.
• A minimum of eight years of progressive experience in IT risk, IT controls, IT SOX, technology assurance, IT audit, or a closely related field.
• Significant in-house technology or corporate ownership experience is essential.
• Experience in a first-line technology, engineering, systems, or IT operations role, or as an embedded in-house risk partner supporting a technology organization.
• Practical experience in an engineering-led technology, cloud, SaaS, platform, or digital product environment.
• Strong practical knowledge of SOX 404, ITGCs, IT application controls, automated controls, COSO, and COBIT.
• Proven expertise in control design, implementation, monitoring, evidence review, audit readiness, issue evaluation, and remediation.
• Solid understanding of cloud infrastructure, IAM, DevOps, CI/CD, SDLC, software repositories, deployment practices, system integrations, and Kubernetes.
• Experience connecting business-process controls to supporting systems, automated controls, IPEs/IUCs, and underlying IT dependencies.
• Ability to communicate effectively with engineers, technical leaders, Finance stakeholders, and external auditors.
• Strong judgment and confidence to challenge control owners while developing practical, scalable solutions.
• Highly autonomous and hands-on approach in a dynamic environment with incomplete processes and competing priorities.
• Proficient written and verbal communication skills in English.
• Capability to work effectively across international time zones and willingness to travel when necessary.
• Professional certifications such as CISA, CRISC, CISM, CIA, CPA, or equivalent qualifications are a bonus but not mandatory.
• Experience with GRC and audit-management tools like Workiva, Jira, ServiceNow GRC, or similar platforms is an added advantage.
• Familiarity with enterprise SaaS and financial systems such as NetSuite, HR platforms, billing systems, procurement tools, or treasury systems is a plus.
• Competitive compensation.
• Career growth and learning opportunities.
• Flexibility and ownership.
• Collaborative and innovative culture.
• Opportunity to work on impactful AI projects.
• International environment and talented teams.
Super.com
L3Harris Technologies
phData
Get handpicked remote jobs straight to your inbox weekly.