Senior Staff IT Controls, Enterprise Applications
Own and scale IT general controls, access governance, segregation of duties, and audit readiness across enterprise applications. The role combines SOX expertise with AI-enabled continuous controls monitoring and requires 10+ years of controls, audit, or enterprise governance experience.
About the job
Responsibilities
- Own IT General Controls (ITGCs) design and operation across enterprise applications, including logical access, change management, SDLC, computer operations, and segregation of duties (SoD).
- Lead the first-line control environment for in-scope applications, embedding controls into operational workflows.
- Drive SoD strategy across ERP, HRIS, and CRM systems, including role reviews, conflict remediation, mitigating controls, and ongoing monitoring.
- Manage the audit lifecycle with Internal Audit, External Audit, and the SOX PMO, including walkthroughs, evidence collection, deficiency remediation, and management responses.
- Build AI-enabled continuous controls monitoring through LLM-based evidence review, agentic control testing, and automated anomaly detection.
- Own the controls posture for internal AI and automation use cases, including risk classification, evidence trails, and validation.
- Lead access governance, including provisioning and deprovisioning, user access reviews, privileged access management, and IGA integration.
- Govern application change management, including approvals, developer/production segregation, emergency changes, and release evidence.
- Mature the controls program through rationalization, control consolidation, and adoption of automated or preventive controls.
- Partner with Security/GRC, Legal, Finance/Accounting, People Operations, Revenue Operations, application owners, engineering, and auditors.
Requirements
- 10+ years of experience in IT controls, audit, or enterprise applications governance.
- Hands-on first-line control ownership across NetSuite, Workday, and/or Salesforce.
- Deep expertise in SOX 404, COSO, COBIT, ITGC, and SoD frameworks.
- Experience leading external audit engagements as the management-side owner.
- Experience with public companies or IPO readiness preferred.
- Experience building AI-augmented controls using agents, LLM-based reviewers, or automated anomaly detection.
- Knowledge of AI risks including model risk, prompt injection, output validation, and audit trail design.
- Familiarity with agentic tools such as Claude Code, MCPs, or LLM-based evidence pipelines.
- Strong communication skills for working with executives, auditors, and engineers.
- Experience with continuous controls monitoring and data-driven assurance.
Nice-to-haves
- CISA, CISSP, CIA, CPA, or equivalent certification.
- Familiarity with SOC 1, SOC 2, ISO 27001, NIST CSF, and PCI DSS.
Skills
It General Controls, Sox 404, Coso, Cobit, Segregation Of Duties, NetSuite, Workday, Salesforce, Continuous Controls Monitoring, LLMs, AI Agents, Claude Code, Mcp, Sailpoint, Saviynt
Similar jobs
Security Engineering jobsStaff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.
Design and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.
Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.
Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.
Build and scale container security capabilities that orchestrate Zero Trust Segmentation at the application and pod level. The role requires 8+ years developing distributed systems, proficiency in a higher-level language, and strong Kubernetes, networking, and Linux expertise.