Jobs · Finance

IT Risks & Control Manager

Nebius · United States · 4 wk ago
RemoteRemoteFinance$120k–$180k/yrFull-time

About the role

Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure. Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI. Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.

Responsibilities

  • Act as the risk and controls partner for an assigned technology organization or system portfolio, developing a detailed understanding of its architecture, operations, risks and financial-reporting dependencies.
  • Own and continuously improve the relevant IT risk and control framework, including system scoping, risk assessment, RCM and control-catalogue maintenance, documentation and control ownership.
  • Lead IT SOX readiness for assigned systems, including walkthrough preparation, evidence-quality review, testing coordination, issue evaluation and remediation oversight.
  • Partner with engineering, platform, infrastructure, security and corporate IT teams to design and implement scalable controls that address risk while supporting operational efficiency.
  • Design, assess and enhance ITGCs across areas such as user access, privileged access, segregation of duties, change management, SDLC, system operations, incident management and third-party services.
  • Assess IT application controls, automated controls and IT-dependent business controls, including the completeness and accuracy of system-generated information used in business-process controls.
  • Evaluate how business controls depend on systems, integrations, configurations, reports and underlying ITGCs, and work with both business and IT control owners to resolve gaps.
  • Apply risk and controls thinking to modern engineering practices, including cloud infrastructure, DevOps, CI/CD, repositories, deployment processes, containerized environments and audit logging.
  • Lead the assessment and remediation of control gaps arising from new systems, major technology transformations, platform changes, integrations and acquisitions.
  • Review third-party assurance reports and determine the impact of vendor controls and complementary user-entity controls on the Nebius control environment.
  • Maintain effective working relationships with external auditors and advisers, aligning on audit scope, evidence expectations, testing approaches, reliance opportunities, timelines and issue resolution.
  • Translate complex technical risks and auditor requirements into practical guidance for engineering and system owners.
  • Use data analytics, automation, continuous monitoring and AI-assisted tools to improve control coverage, evidence quality and the efficiency of the IT SOX program.
  • Contribute to the development of IT controls methodology, standards, tooling, training, reporting and the broader Risk Partner operating model.
  • Provide clear, concise updates on control health, audit readiness, deficiencies and remediation progress to senior technology and Finance stakeholders.

    Requirements

    • A degree in Information Systems, Computer Science, Engineering, Accounting, Finance or a related discipline, or equivalent professional experience.
    • At least eight years of progressive experience in IT risk, IT controls, IT SOX, technology assurance, IT audit or a closely related area.
    • Meaningful in-house technology or corporate ownership experience is required.
    • Big Four or consulting experience is valuable when combined with subsequent in-house responsibility, but an exclusively advisory or external-audit background will not be sufficient.
    • Experience working in a first-line technology, engineering, systems or IT operations role, or as an embedded in-house risk partner supporting a technology organization.
    • Hands-on experience in an engineering-led technology, cloud, SaaS, platform or digital-product environment.
    • Strong practical knowledge of SOX 404, ITGCs, IT application controls, automated controls, COSO and COBIT.
    • Demonstrated experience with control design, implementation, monitoring, evidence review, audit readiness, issue evaluation and remediation.
    • Practical understanding of modern technology environments, including cloud infrastructure, IAM, DevOps, CI/CD, SDLC, software repositories, deployment practices, system integrations and container orchestration such as Kubernetes.
    • Experience connecting business-process controls to supporting systems, automated controls, IPEs/IUCs and underlying IT dependencies.
    • The ability to communicate effectively with engineers, technical leaders, Finance stakeholders and external auditors.
    • Strong judgment and the confidence to challenge control owners while developing practical, scalable solutions.
    • A highly autonomous and hands-on approach, with the ability to operate effectively in an evolving environment with incomplete processes and competing priorities.
    • Strong written and verbal English.
    • The ability to work effectively across international time zones and travel when needed to build relationships with key technology and audit stakeholders.

      Qualifications

      • A professional certification such as CISA, CRISC, CISM, CIA, CPA or an equivalent qualification.
      • Experience building or materially transforming an IT SOX or technology-controls framework in a listed or pre-IPO technology company.
      • Experience in AI infrastructure, cloud platforms, large-scale SaaS, fintech, marketplaces or another engineering-intensive environment.
      • Experience with GRC and audit-management tools such as Workiva, Jira, ServiceNow GRC or similar platforms.
      • Experience with enterprise SaaS and financial systems such as NetSuite, HR platforms, billing systems, procurement tools or treasury systems.
      • Experience onboarding acquired companies or newly implemented systems into SOX scope.
      • Experience with control automation, continuous monitoring, data analytics or AI-assisted assurance.
      • Exposure to AI governance, AI/ML control environments or controls supporting AI-enabled development and operations.

      Skills

      • Deep IT risk and controls expertise.
      • Significant in-house technology or corporate ownership experience.
      • Proven ability to work directly with engineering leaders, system owners, Finance, Internal Controls and external auditors.
      • Strong practical knowledge of SOX 404, ITGCs, IT application controls, automated controls, COSO and COBIT.
      • Ability to connect business-process controls to supporting systems, automated controls, IPEs/IUCs and underlying IT dependencies.
      • Effective communication skills, both written and verbal.
      • Strong judgment and the confidence to challenge control owners while developing practical, scalable solutions.
      • A highly autonomous and hands-on approach, with the ability to operate effectively in an evolving environment with incomplete processes and competing priorities.

      Benefits

      Competitive compensation and benefits packages. Actual compensation will be determined based on job-related factors, including experience, skills, qualifications, the level at which the candidate is hired, and geographic location, consistent with applicable law.

      Pay

      Base Compensation Range $120,000—$180,000 USD

      Schedule

      Flexible schedule to accommodate international time zones and travel needs.

Similar jobs

IT Risk Manager

Early WarningScottsdale, AZ· 2 mo ago
Information Technology$104k–$130k/yrapply on earlywarning.wd5.myworkdayjobs.com

IT risk manager

Inherent TechnologiesCalifornia, United States· 1 mo ago
Information Technology

IT Risk Manager

Early WarningChicago, IL· 1 mo ago
Information Technology$104k–$130k/yrapply on earlywarning.wd5.myworkdayjobs.com

IT Risk Manager

Early WarningSan Francisco, CA· 1 mo ago
Information Technology$104k–$130k/yrapply on earlywarning.wd5.myworkdayjobs.com