IT Risks & Control Manager
About the role
Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure. Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI. Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.
Responsibilities
- Act as the risk and controls partner for an assigned technology organization or system portfolio, developing a detailed understanding of its architecture, operations, risks and financial-reporting dependencies.
- Own and continuously improve the relevant IT risk and control framework, including system scoping, risk assessment, RCM and control-catalogue maintenance, documentation and control ownership.
- Lead IT SOX readiness for assigned systems, including walkthrough preparation, evidence-quality review, testing coordination, issue evaluation and remediation oversight.
- Partner with engineering, platform, infrastructure, security and corporate IT teams to design and implement scalable controls that address risk while supporting operational efficiency.
- Design, assess and enhance ITGCs across areas such as user access, privileged access, segregation of duties, change management, SDLC, system operations, incident management and third-party services.
- Assess IT application controls, automated controls and IT-dependent business controls, including the completeness and accuracy of system-generated information used in business-process controls.
- Evaluate how business controls depend on systems, integrations, configurations, reports and underlying ITGCs, and work with both business and IT control owners to resolve gaps.
- Apply risk and controls thinking to modern engineering practices, including cloud infrastructure, DevOps, CI/CD, repositories, deployment processes, containerized environments and audit logging.
- Lead the assessment and remediation of control gaps arising from new systems, major technology transformations, platform changes, integrations and acquisitions.
- Review third-party assurance reports and determine the impact of vendor controls and complementary user-entity controls on the Nebius control environment.
- Maintain effective working relationships with external auditors and advisers, aligning on audit scope, evidence expectations, testing approaches, reliance opportunities, timelines and issue resolution.
- Translate complex technical risks and auditor requirements into practical guidance for engineering and system owners.
- Use data analytics, automation, continuous monitoring and AI-assisted tools to improve control coverage, evidence quality and the efficiency of the IT SOX program.
- Contribute to the development of IT controls methodology, standards, tooling, training, reporting and the broader Risk Partner operating model.
- Provide clear, concise updates on control health, audit readiness, deficiencies and remediation progress to senior technology and Finance stakeholders.
Requirements
- A degree in Information Systems, Computer Science, Engineering, Accounting, Finance or a related discipline, or equivalent professional experience.
- At least eight years of progressive experience in IT risk, IT controls, IT SOX, technology assurance, IT audit or a closely related area.
- Meaningful in-house technology or corporate ownership experience is required.
- Big Four or consulting experience is valuable when combined with subsequent in-house responsibility, but an exclusively advisory or external-audit background will not be sufficient.
- Experience working in a first-line technology, engineering, systems or IT operations role, or as an embedded in-house risk partner supporting a technology organization.
- Hands-on experience in an engineering-led technology, cloud, SaaS, platform or digital-product environment.
- Strong practical knowledge of SOX 404, ITGCs, IT application controls, automated controls, COSO and COBIT.
- Demonstrated experience with control design, implementation, monitoring, evidence review, audit readiness, issue evaluation and remediation.
- Practical understanding of modern technology environments, including cloud infrastructure, IAM, DevOps, CI/CD, SDLC, software repositories, deployment practices, system integrations and container orchestration such as Kubernetes.
- Experience connecting business-process controls to supporting systems, automated controls, IPEs/IUCs and underlying IT dependencies.
- The ability to communicate effectively with engineers, technical leaders, Finance stakeholders and external auditors.
- Strong judgment and the confidence to challenge control owners while developing practical, scalable solutions.
- A highly autonomous and hands-on approach, with the ability to operate effectively in an evolving environment with incomplete processes and competing priorities.
- Strong written and verbal English.
- The ability to work effectively across international time zones and travel when needed to build relationships with key technology and audit stakeholders.
Qualifications
- A professional certification such as CISA, CRISC, CISM, CIA, CPA or an equivalent qualification.
- Experience building or materially transforming an IT SOX or technology-controls framework in a listed or pre-IPO technology company.
- Experience in AI infrastructure, cloud platforms, large-scale SaaS, fintech, marketplaces or another engineering-intensive environment.
- Experience with GRC and audit-management tools such as Workiva, Jira, ServiceNow GRC or similar platforms.
- Experience with enterprise SaaS and financial systems such as NetSuite, HR platforms, billing systems, procurement tools or treasury systems.
- Experience onboarding acquired companies or newly implemented systems into SOX scope.
- Experience with control automation, continuous monitoring, data analytics or AI-assisted assurance.
- Exposure to AI governance, AI/ML control environments or controls supporting AI-enabled development and operations.
Skills
- Deep IT risk and controls expertise.
- Significant in-house technology or corporate ownership experience.
- Proven ability to work directly with engineering leaders, system owners, Finance, Internal Controls and external auditors.
- Strong practical knowledge of SOX 404, ITGCs, IT application controls, automated controls, COSO and COBIT.
- Ability to connect business-process controls to supporting systems, automated controls, IPEs/IUCs and underlying IT dependencies.
- Effective communication skills, both written and verbal.
- Strong judgment and the confidence to challenge control owners while developing practical, scalable solutions.
- A highly autonomous and hands-on approach, with the ability to operate effectively in an evolving environment with incomplete processes and competing priorities.
Benefits
Competitive compensation and benefits packages. Actual compensation will be determined based on job-related factors, including experience, skills, qualifications, the level at which the candidate is hired, and geographic location, consistent with applicable law.
Pay
Base Compensation Range $120,000—$180,000 USD
Schedule
Flexible schedule to accommodate international time zones and travel needs.