Senior Director, IT Governance, Risk and Compliance
TKO Group Holdings, Inc. (NYSE: TKO) is a premium sports and entertainment company owning iconic properties including UFC, WWE, and PBR. Together, these properties reach 1 billion households across 210 countries and territories, organizing over 500 live events annually.
About the role
The Senior Director, IT Governance, Risk and Compliance, leads and executes core elements of TKO’s IT compliance program, focusing on SOX, IT General Controls, audit readiness, governance documentation, security frameworks, third-party assurance, and technical data reconciliation. Reporting to the SVP of IT Business Systems, this role partners with Legal, IT, Security, Internal Audit, Finance, and business stakeholders to strengthen TKO’s control environment, support compliance obligations, and drive consistent execution across systems and processes. The role requires strategic oversight and hands-on execution in a complex environment with disparate systems and evolving business needs.
Responsibilities
- IT Compliance Planning and Program Execution
- Establish an overall compliance strategy and roadmap, including selecting and implementing an enterprise Governance, Risk, and Compliance platform to automate RCM authoring and evidence collection workflows.
- Own prioritization, tracking, and delivery of key compliance initiatives, providing executive status updates on program health.
- Provide subject matter expertise and guidance on compliance expectations, control execution, documentation standards, and system implementation lifecycle considerations.
- Advise and ensure PCI compliance is sustained by in-scope business units.
- Oversee internal resources or cross-functional contributors for audit preparation, SOC reporting, PCI compliance adherence, and compliance execution.
- Governance, Risk, and Documentation Management
- Coordinate with risk management stakeholders (Legal, Finance, Internal Audit, Corporate IT, BU-level IT) to:
- Support and evolve the IT Risk Management Program to address Technology, Cybersecurity, Data, Resiliency/Recovery, and Emerging (AI, etc.) risks.
- Establish IT compliance requirements and eliminate redundant risk management processes/controls.
- Align with the risk management objectives of other functions.
- Maintain inventories of in-scope systems/applications supporting key regulatory requirements (e.g., ICFR), in-flight IT projects, and stakeholders.
- Develop frameworks and standards for core IT compliance documentation (Risk and Control Matrices, process flows, system interface documentation, remediation plans).
- Determine review criteria and cadence for assessing documentation quality, completeness, and compliance alignment.
- Establish policies, procedures, and governance practices for sustainable compliance execution.
- Coordinate with risk management stakeholders (Legal, Finance, Internal Audit, Corporate IT, BU-level IT) to:
- SOX, IT General Controls, and Audit Support
- Serve as primary point of contact for IT compliance during internal/external audits, including SOX and IT General Controls testing.
- Organize, collect, and maintain evidence for audit requests and management review.
- Liaise with stakeholders and auditors to ensure timely, accurate delivery of materials.
- Create repeatable processes for identifying, tracking, and remediating control gaps, deficiencies, and action plans.
- Support IT risk assessments, control reviews, and compliance evaluations.
- SOC Reporting and Third-Party Assurance
- Manage the lifecycle of Service Organization Control reporting.
- Ensure completion of management evaluation documentation for third-party controls and reliance.
- Support assessment of third-party compliance risks in access management, vendor management, and change management.
- Technical Data Reconciliation and Compliance Operations
- Partner with IT and Finance to monitor adherence to internal policies and key control environment metrics (e.g., reconciliation activities, data analysis, data hygiene).
- Collaborate with infrastructure and application system owners to ensure timely user terminations; conduct look-back analyses for missed terminations and provide confirmation to Internal Audit.
- Establish continuous monitoring processes.
- Monitoring, Reporting, and Training
- Monitor changes in compliance, privacy, and security requirements; translate them into practical business processes.
- Prepare management reports on compliance status, risks, remediation efforts, and control effectiveness.
- Collaborate with Internal Audit and IT to develop training materials on IT compliance, data privacy, and security practices.
- Support awareness efforts to promote a culture of accountability and compliance.
Supervisory Responsibilities
This role may oversee internal resources, project-based support, or cross-functional contributors for audit preparation, SOC reporting, PCI compliance adherence, and compliance execution.
Requirements
- Bachelor’s degree in Computer Science, Information Systems, Information Security, Accounting, Finance, or a related field.
- 10+ years of progressive experience in IT compliance, IT audit, risk management, cybersecurity compliance, or a related governance function.
- Demonstrated experience supporting SOX and IT General Controls in a complex environment.
- Experience developing and enhancing Risk and Control Matrices, process flows, remediation plans, system inventories, and compliance documentation.
- Strong cross-functional partnership experience with Legal, IT, Security, Internal Audit, Finance, and business stakeholders.
Preferred Qualifications
- Experience supporting compliance activities during mergers and acquisitions.
- Experience managing third-party assurance processes, including SOC report review and evaluation.
- Familiarity with enterprise control frameworks such as NIST and ISO 27001.
- Experience in a public company or similarly regulated environment.
- Knowledge of SAP (S/4), TKO’s Enterprise Finance and Accounting ERP.
Skills
- Strong knowledge of SOX, ITGC, and general compliance frameworks.
- Advanced proficiency in Excel; working knowledge of PowerQuery, SQL, or similar tools preferred.
- Understanding of access management, vendor management, change management, and audit evidence requirements.
- Strong analytical and problem-solving skills with exceptional attention to detail.
- Excellent written and verbal communication, including ability to explain technical concepts to non-technical stakeholders.
- Strong organizational, project management, and documentation skills.
- High degree of integrity, discretion, and professional judgment.
- Ability to balance strategic priorities with hands-on execution.
Preferred Certifications
- Certified Information Systems Auditor (CISA)
- Certified Information Systems Security Professional (CISSP)
- Certified in Risk and Information Systems Control (CRISC)
Pay
Hiring rate range: $157,500 – $210,000 annually (minimum will not fall below applicable State/local minimum salary thresholds). The company offers a locally competitive rewards package, including base rate, short- and long-term incentives, growth opportunities, and robust benefits such as healthcare, retirement, vacation, and other paid time off.