Skip to content
DiscordDiscord

Technology Risk Audit Manager

Leads technology risk audits spanning IT SOX/ITGC, financial-reporting systems, and consumer trust domains such as security and privacy. The role partners with Engineering, manages audit projects and remediation, and applies AI automation to strengthen testing and monitoring.

About the job

Responsibilities

  • Lead IT SOX/ITGC strategy and continuous improvement across financial-reporting-relevant systems.
  • Extend risk and controls assessment and assurance into consumer trust domains such as privacy, security, and trust and safety.
  • Partner with Engineering to ensure appropriate access controls, segregation of duties, change management, and CI/CD integrity.
  • Guide control design through system implementations, migrations, and platform changes.
  • Manage teams and projects related to IT controls and technical audits, including external contractors and internal teammates.
  • Apply AI and automation tools to improve audit testing efficiency, anomaly detection, and control monitoring.
  • Track remediation, coordinate with external auditors, and report to senior leadership.

Requirements

  • Bachelor's degree in Information Systems, Computer Science, Accounting, or a related field, or equivalent practical experience.
  • 8+ years of experience in IT audit, risk management, or controls spanning financial SOX/ITGC and consumer trust domains such as security, privacy, or trust and safety.
  • Deep ITGC knowledge, including access management, change management, computer operations, and SDLC controls.
  • SOX/ICFR knowledge and independent risk assessment methodology, including audit scoping, risk identification, and test-procedure design.
  • Fluency with COSO, COBIT, and NIST CSF frameworks.
  • External audit or co-source coordination experience and a record of driving remediation plans to closure.
  • Hands-on experience applying AI or automation tools to audit processes.
  • Strong communication skills for translating technical risk to non-technical stakeholders.

Nice-to-haves

  • Consumer-facing platform technology risk experience.
  • Subscription or ad tech experience.
  • Experience auditing homegrown systems or tools.
  • AI governance experience.
  • Third-party or vendor risk expertise.
  • Data privacy regulatory knowledge.
  • DevSecOps or CI/CD pipeline controls experience.
  • CISA, CISSP, or CPA credential.

Compensation and Benefits

  • US base salary range: $180,000–$202,500, plus equity and benefits.
  • Relocation assistance may be available.
  • The role is expected to be performed in the office 1–2 days per week.

Skills

It Sox, Itgc, Access Management, Change Management, Sdlc Controls, Sox/Icfr, Coso, Cobit, Nist Csf, AI Automation, CI/CD, DevSecOps, Data Privacy, Vendor Risk, Cisa

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

Valon

Valon

United States

Senior Security Engineer, Threat & Offensive Security
$180k+/yrRemote5+ YOESecurity Engineering

Leads offensive security, threat intelligence, security testing, and incident response across applications, infrastructure, and networks. The role requires at least five years of relevant experience, cloud security expertise, AI and automation experience, and a bachelor's degree.

Anyscale

Anyscale

India
Senior Product Security Engineer
$180k+/yrOn-site8+ YOESecurity Engineering

Own Anyscale’s secure software development lifecycle, partner with engineering on secure architecture and features, and lead vulnerability management and remediation. The role requires 8+ years of product or application security experience and strong hands-on secure-development expertise.

Anyscale

Anyscale

San Francisco, CA

Compliance Manager
$180k+/yrOn-site7+ YOESecurity Engineering

Own Anyscale’s compliance function end to end, leading SOC 2 and ISO 27001 programs, audit readiness, customer security diligence, and enterprise risk management. The role requires 7+ years in governance, risk, and compliance plus strong cloud and SaaS security-controls expertise.

Siftstack

Siftstack

Marina Del Rey, CA

Senior Application Security Engineer
$180k+/yrHybrid5+ YOESecurity Engineering

The Senior Application Security Engineer will build secure-by-default software patterns, supply-chain controls, and developer-facing security tooling across a distributed systems platform. The role requires 5+ years of production software experience, strong application security expertise, and depth in Go or Rust.