Skip to content

IT Compliance Manager

The IT Compliance Manager will lead SOX ITGC and ITAC design, testing, audit coordination, and remediation across complex cloud and SaaS environments. The role requires 7–10 years of IT audit or technology risk experience, strong control-framework expertise, and the ability to influence engineering and finance stakeholders.

About the job

Responsibilities

  • Drive the IT Compliance program and strategy with the Director of IT Compliance, SOX Compliance, and internal and external auditors.
  • Scope, assess risk, document, and prepare testing for SOX ITGC and ITAC programs.
  • Conduct control design assessments and periodic operating-effectiveness testing across ITGCs and ITACs.
  • Lead domain-level initiatives including system onboarding, control rationalization, evidence automation, and continuous controls monitoring.
  • Oversee logical access, change management, computer operations, backup and recovery, job scheduling, logging, and cloud configuration controls.
  • Own the ITAC portfolio, including automated controls, key reports, IPE, configuration controls, and interface/data-transfer controls.
  • Maintain the financial-reporting systems inventory and risk-based control tiering.
  • Lead IT audits, SOX reviews, and control assessments, including walkthroughs, PBC coordination, testing support, and status reporting.
  • Drive root-cause analysis, remediation design, fix validation, and prevention of repeat findings.
  • Embed automated evidence collection, continuous controls monitoring, analytics, and responsible AI-enabled compliance practices.
  • Define sustainable control architecture and requirements across CI/CD pipelines, infrastructure-as-code, and automated access workflows.
  • Prepare narratives, flowcharts, risk-and-control matrices, and test workpapers.
  • Partner with Engineering, Product, Security, Finance, and Compliance; coach control owners and resolve conflicts.

Requirements

  • Bachelor’s degree in Information Technology, Accounting, Management Information Systems, or Finance.
  • 7–10 years of progressive experience in IT audit, internal controls, or technology risk management, including supervisory experience.
  • Deep hands-on expertise in SOX 404 ITGCs and ITACs, including key reports/IPE, configuration controls, and interface controls.
  • Strong knowledge of COSO, COBIT, and risk assessment methodologies.
  • Working knowledge of cloud platforms, CI/CD pipelines, DevOps practices, and modern SaaS architectures.
  • Understanding of logical access, change management, least privilege, segregation of duties, computer operations, and vulnerability management.
  • Experience delivering audits and multi-quarter control initiatives in complex technology environments.
  • Strong communication, analytical, problem-solving, and program management skills.
  • Ability to influence stakeholders without direct authority and translate technical detail for executive and audit audiences.

Nice to Have

  • Big Four experience.
  • CISA, CRISC, CIA, or CPA certification.
  • Technology industry experience.

Compensation and Benefits

  • No compensation information provided.

Skills

Sox 404, Itgcs, Itacs, Coso, Cobit, Risk Assessment, Cloud Platforms, Ci/Cd Pipelines, DevOps, Saas Architecture, Logical Access Management, Change Management, Vulnerability Management, Continuous Controls Monitoring, Infrastructure As Code

Greenlight

Greenlight

Bengaluru, India

Senior Security Engineer
No salary listedHybrid5+ YOESecurity Engineering

Senior product security engineer responsible for embedding security across the SDLC, building security automation, conducting reviews and penetration testing, and leading vulnerability response. Requires 5+ years of security experience, strong web and mobile security expertise, and hands-on AWS, CI/CD, and security tooling knowledge.

GoHighLevel

GoHighLevel

India

Lead Security Engineer - Penetration Testing & AI Security
No salary listedRemote8+ YOESecurity Engineering

Leads application and AI security assessments across web, API, cloud-native, and LLM-based systems. Requires 8+ years of cybersecurity experience, hands-on penetration testing and secure SDLC expertise, and experience adversarially testing AI applications.

Rippling

Rippling

Bengaluru, India

Senior Security Engineer - DART
No salary listedOn-site7+ YOESecurity Engineering

The Senior Security Engineer will build and operate detection and incident-response capabilities across cloud production and corporate environments. The role requires 7+ years of security engineering experience, AWS expertise, threat hunting, investigations, automation, and SIEM/SOAR proficiency.

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

Anyscale

Anyscale

India
Senior Detection and Response Engineer
$200k+/yrOn-site6+ YOESecurity Engineering

Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.