Skip to main content
Nebius

IT Risks & Control Manager

RemoteUnited States only
Published
Role
Finance
Experience
Lead
Company size
Enterprise
$120k–$180k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

IT risk and controls manager with 8+ years in IT risk, IT SOX, technology assurance, IT audit or related work. Must have in-house technology/corporate ownership experience, strong SOX 404/ITGC/control design knowledge, modern cloud/DevOps/IAM/CI/CD/Kubernetes understanding, strong English, and US work authorization.

Core skills

SOX 404ITGCsIT application controls

Required skills

Automated controlsCOSOCOBITCloud infrastructureIAMDevOpsCI/CDSDLCSoftware repositoriesKubernetes

Optional skills

CISACRISCCISMCIACPAWorkivaJiraServiceNow GRC

Required languages

English Strong written and verbal English mentioning no formal level.

What you'll do

  • Act as the risk and controls partner for an assigned technology organization or system portfolio, developing a detailed understanding of its architecture, operations, risks and financial-reporting dependencies.
  • Own and continuously improve the relevant IT risk and control framework, including system scoping, risk assessment, RCM and control-catalogue maintenance, documentation and control ownership.
  • Lead IT SOX readiness for assigned systems, including walkthrough preparation, evidence-quality review, testing coordination, issue evaluation and remediation oversight.
  • Partner with engineering, platform, infrastructure, security and corporate IT teams to design and implement scalable controls that address risk while supporting operational efficiency.
  • Design, assess and enhance ITGCs across areas such as user access, privileged access, segregation of duties, change management, SDLC, system operations, incident management and third-party services.
  • Assess IT application controls, automated controls and IT-dependent business controls, including the completeness and accuracy of system-generated information used in business-process controls.
  • Evaluate how business controls depend on systems, integrations, configurations, reports and underlying ITGCs, and work with both business and IT control owners to resolve gaps.
  • Apply risk and controls thinking to modern engineering practices, including cloud infrastructure, DevOps, CI/CD, repositories, deployment processes, containerized environments and audit logging.
  • Lead the assessment and remediation of control gaps arising from new systems, major technology transformations, platform changes, integrations and acquisitions.
  • Review third-party assurance reports and determine the impact of vendor controls and complementary user-entity controls on the Nebius control environment.
  • Maintain effective working relationships with external auditors and advisers, aligning on audit scope, evidence expectations, testing approaches, reliance opportunities, timelines and issue resolution.
  • Translate complex technical risks and auditor requirements into practical guidance for engineering and system owners.
  • Use data analytics, automation, continuous monitoring and AI-assisted tools to improve control coverage, evidence quality and the efficiency of the IT SOX program.
  • Contribute to the development of IT controls methodology, standards, tooling, training, reporting and the broader Risk Partner operating model.
  • Provide clear, concise updates on control health, audit readiness, deficiencies and remediation progress to senior technology and Finance stakeholders.

What they require

  • A degree in Information Systems, Computer Science, Engineering, Accounting, Finance or a related discipline, or equivalent professional experience.
  • At least eight years of progressive experience in IT risk, IT controls, IT SOX, technology assurance, IT audit or a closely related area.
  • Meaningful in-house technology or corporate ownership experience is required.
  • Big Four or consulting experience is valuable when combined with subsequent in-house responsibility, but an exclusively advisory or external-audit background will not be sufficient.
  • Experience working in a first-line technology, engineering, systems or IT operations role, or as an embedded in-house risk partner supporting a technology organization.
  • Hands-on experience in an engineering-led technology, cloud, SaaS, platform or digital-product environment.
  • Strong practical knowledge of SOX 404, ITGCs, IT application controls, automated controls, COSO and COBIT.
  • Demonstrated experience with control design, implementation, monitoring, evidence review, audit readiness, issue evaluation and remediation.
  • Practical understanding of modern technology environments, including cloud infrastructure, IAM, DevOps, CI/CD, SDLC, software repositories, deployment practices, system integrations and container orchestration such as Kubernetes.
  • Experience connecting business-process controls to supporting systems, automated controls, IPEs/IUCs and underlying IT dependencies.
  • The ability to communicate effectively with engineers, technical leaders, Finance stakeholders and external auditors.
  • Strong judgment and the confidence to challenge control owners while developing practical, scalable solutions.
  • A highly autonomous and hands-on approach, with the ability to operate effectively in an evolving environment with incomplete processes and competing priorities.
  • Strong written and verbal English.
  • The ability to work effectively across international time zones and travel when needed to build relationships with key technology and audit stakeholders.
  • Preferred: A professional certification such as CISA, CRISC, CISM, CIA, CPA or an equivalent qualification.
  • Preferred: Experience building or materially transforming an IT SOX or technology-controls framework in a listed or pre-IPO technology company.
  • Preferred: Experience in AI infrastructure, cloud platforms, large-scale SaaS, fintech, marketplaces or another engineering-intensive environment.
  • Preferred: Experience with GRC and audit-management tools or similar platforms.
  • Preferred: Experience with enterprise SaaS and financial systems.
  • Preferred: Experience onboarding acquired companies or newly implemented systems into SOX scope.
  • Preferred: Experience with control automation, continuous monitoring, data analytics or AI-assisted assurance.
  • Preferred: Exposure to AI governance, AI/ML control environments or controls supporting AI-enabled development and operations.
  • Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire.

Benefits

  • Competitive compensation
  • Career growth and learning opportunities
  • Flexibility and ownership
  • Collaborative and innovative culture
  • Opportunity to work on impactful AI projects
  • International environment and talented teams
  • Fast moving environment
  • Bold thinking
  • Constant growth
  • Meaningful impact
  • Trust and real ownership
  • Opportunity to shape the future of AI

Dutch company developing a portfolio of AI-related technology assets

🇳🇱 NetherlandsTechnology, Information And InternetMid-sizenebius.group/

Details

Apply routeDom
$120k–$180k/yr