
Senior Director, IT Governance, Risk and Compliance
Posted 20 hours ago

Posted 20 hours ago
This is a fully remote position, open to applicants in Connecticut, +3 more states.
• Develop a comprehensive IT compliance strategy and roadmap, which includes the selection and implementation of an enterprise Governance, Risk, and Compliance platform.
• Take ownership of prioritizing, tracking, and delivering essential compliance initiatives while providing executive updates on their status.
• Guide system leads and business partners on compliance expectations, control execution, documentation, and considerations throughout the system implementation lifecycle.
• Maintain PCI compliance across relevant business units.
• Supervise resources and contributors involved in audit preparation, SOC reporting, PCI compliance, and execution of compliance activities.
• Enhance and support the IT Risk Management Program, addressing technology, cybersecurity, data, resiliency/recovery, and emerging risks.
• Define IT compliance requirements and streamline risk management processes or controls to eliminate redundancy.
• Keep detailed inventories of relevant systems, applications, projects, and stakeholders.
• Create frameworks, standards, templates, Risk and Control Matrices, process flows, interface documentation, and remediation plans.
• Serve as the primary IT compliance liaison for both internal and external audits, including SOX and IT General Controls testing.
• Organize audit evidence and coordinate timely submission with stakeholders and auditors.
• Monitor and address control gaps, deficiencies, and action plans.
• Oversee the Service Organization Control reporting lifecycle and evaluations of third-party assurances.
• Track control-environment metrics, reconciliation activities, data analysis, and data hygiene.
• Manage user-termination compliance reviews and confirmation materials for Internal Audit.
• Implement continuous monitoring processes.
• Stay updated on changes in compliance, privacy, and security requirements, translating these into business processes.
• Prepare management reports detailing compliance status, risks, remediation efforts, and control effectiveness.
• Collaborate on IT compliance, data privacy, and security training materials and awareness initiatives.
• A Bachelor’s degree in Computer Science, Information Systems, Information Security, Accounting, Finance, or a related discipline.
• Over 10 years of progressive experience in IT compliance, IT audit, risk management, cybersecurity compliance, or related governance roles.
• Proven experience supporting SOX and IT General Controls in a complex setting.
• Experience in developing Risk and Control Matrices, process flows, remediation plans, system inventories, and compliance documentation.
• Strong experience in cross-functional partnerships with Legal, IT, Security, Internal Audit, Finance, and business stakeholders.
• Preferred experience in compliance activities associated with mergers and acquisitions.
• Preferred experience in managing third-party assurance processes, including SOC report review and evaluation.
• Familiarity with NIST and ISO 27001 is preferred.
• Experience in a public company or similarly regulated environment is preferred.
• Knowledge of SAP S/4 is a plus.
• Comprehensive understanding of SOX, ITGC, and general compliance frameworks.
• Advanced proficiency in Excel and working knowledge of PowerQuery, SQL, or similar software is preferred.
• Understanding of access management, vendor management, change management, and audit evidence requirements.
• Strong analytical and problem-solving skills with exceptional attention to detail.
• Excellent written and verbal communication skills, including the ability to convey technical concepts to non-technical audiences.
• Strong organizational, project management, and documentation capabilities.
• High level of integrity, discretion, and professional judgment.
• Ability to balance strategic priorities with hands-on execution.
• Preferred certifications include CISA, CISSP, and CRISC.
• Competitive base salary along with, where applicable, short- and long-term incentives.
• Opportunities for growth and professional development.
• Comprehensive healthcare benefits.
• Retirement plans.
• Vacation and additional paid time off.
• Additional offerings to enhance employee well-being.
• Reasonable accommodations for qualified individuals with disabilities, in accordance with the ADA and applicable state or local laws.
ICON plc
US Anesthesia Partners
MultiplyMii
Paychex
Get handpicked remote jobs straight to your inbox weekly.