Jobs · Information Technology · New York

Governance, Risk, and Compliance Senior Associate, IT Controls & Assurance

Weaver · New York, NY · 1 wk ago
Information Technology$82k–$100k/yrFull-time

About the Firm

Weaver is a full-service national accounting, advisory, and consulting firm that brings a human element to the world of accounting. We foster a diverse, collaborative, and entrepreneurial workplace culture where leaders care about the well-being of all employees and encourage them to pursue their ambitions. Our success is built on people, and we commit to supporting professional growth and balanced, integrated lives through our core values, which empower our team to deliver extraordinary service and be their best selves.

About the Role

Weaver is seeking a Senior Associate to join our Governance, Risk, and Compliance (GRC) practice with a primary focus on IT controls and technology assurance. This role supports a balanced portfolio of System and Organization Controls (SOC) 1 and SOC 2 examinations, IT-related Sarbanes-Oxley (SOX) compliance engagements, and other information security and compliance projects. The GRC IT team collaborates with technology, information security, finance, internal audit, and business stakeholders to evaluate controls, communicate practical recommendations, and deliver high-quality client service.

Team members gain exposure to a variety of industries, technologies, control environments, and regulatory expectations while developing both technical and engagement-management skills. The Senior Associate leads assigned workstreams and supports the planning, execution, supervision, and completion of engagements.

Responsibilities

  • Execute and help manage SOC 1 and SOC 2 Type 1 and Type 2 examinations, including planning, walkthroughs, risk assessment, control evaluation, testing, documentation, issue evaluation, and report support.
  • Perform IT SOX work over in-scope systems and processes, including IT general controls, automated controls, key reports, interfaces, and other technology-dependent controls relevant to internal control over financial reporting.
  • Develop and maintain risk and control matrices (RCMs) during engagement planning, including documenting processes, identifying relevant risks, mapping controls to risks and engagement objectives, and defining appropriate control testing procedures.
  • Evaluate control design and operating effectiveness across logical access, change management, computer operations, cybersecurity, incident management, business continuity, vendor management, and related domains.
  • Develop and review process narratives, system descriptions, risk and control matrices, test plans, workpapers, evidence requests, and client-ready deliverables.
  • Identify exceptions and control gaps, assess their significance, and communicate clear, practical recommendations to engagement leadership and client stakeholders.
  • Coordinate day-to-day client requests, monitor engagement status and budgets, escalate risks promptly, and help keep concurrent projects on schedule.
  • Supervise and coach Associates by reviewing workpapers, providing timely feedback, and reinforcing firm methodology and quality expectations.
  • Support other technology risk, information security, and compliance engagements as business needs arise, which may include readiness assessments, internal audit, regulatory compliance, or controls advisory projects.
  • Contribute to practice development through methodology improvements, knowledge sharing, proposal support, and participation in recruiting and team initiatives.

Requirements

  • Bachelor’s degree in Accounting, Management Information Systems, Computer Science, or related field.
  • 2+ years of experience in professional services or a similar field.
  • Working knowledge of SOC reporting concepts and applicable attestation standards, including experience supporting SOC 1 and/or SOC 2 engagements.
  • Understanding of SOX Section 404, internal control over financial reporting, and how technology risks and controls affect financial reporting.
  • Ability to understand business and financial reporting processes, identify relevant technology risks, and connect IT controls to business, reporting, and security objectives.
  • Experience reviewing workpapers and supervising, coaching, or informally leading junior team members.
  • Strong written and verbal communication skills, including the ability to explain technical control matters to both technical and nontechnical stakeholders.
  • Strong organization, attention to detail, professional skepticism, and the ability to manage multiple priorities and deadlines.
  • Ability to appropriately use firm-approved AI and automation tools to improve engagement efficiency, research, documentation, and data analysis while maintaining confidentiality, professional judgment, quality-control requirements, and compliance with firm policies.
  • Ability to travel to client locations or Weaver offices as engagement needs require.

Preferred Qualifications

  • CISA, CPA, CIA, CISSP, CISM, or another relevant certification, or demonstrated progress toward certification.
  • Awareness or exposure to relevant frameworks and criteria such as NIST, ISO/IEC 27001, HITRUST, PCI DSS, and other security or compliance standards.
  • Experience with audit and GRC platforms such as Fieldguide, AuditBoard, Workiva, Drata, Vanta, or similar tools.
  • Experience serving clients in financial services, technology, insurance, healthcare, or other regulated industries.

Benefits

  • Competitive health benefits, including medical, dental, vision, disability, and life insurance.
  • 401(k) plan.
  • Flexible scheduled time off (STO), minimum of 56 hours of sick and safe leave, 11 holidays, and 2 scheduled recharge days.
  • In-house CPE and learning opportunities through our internal Learning & Development department, including technical improvement, practice development, management/leadership training, and whole-life growth.

Pay

A reasonable estimate of the compensation range for this position is $82,000 to $100,000. Actual compensation will be based on factors including but not limited to experience, skills, certifications, and geographical location.

Similar jobs