Jobs · Information Technology

Senior Director, IT Governance, Risk and Compliance

TKO · New York, United States · 3 days ago
RemoteRemoteInformation Technology$158k/yrFull-time

TKO Group Holdings, Inc. (NYSE: TKO) is a premium sports and entertainment company, owning iconic properties including UFC, WWE, and PBR. Together, these properties reach 1 billion households across 210 countries and territories, organizing over 500 live events annually. TKO also partners with major sports rights holders through IMG and On Location.

About the role

The Senior Director, IT Governance, Risk and Compliance, leads and executes core elements of TKO’s IT compliance program, focusing on SOX, IT General Controls, audit readiness, governance documentation, security frameworks, third-party assurance, and technical data reconciliation. Reporting to the SVP of IT Business Systems, this role partners with Legal, IT, Security, Internal Audit, Finance, and business stakeholders to strengthen TKO’s control environment, support compliance obligations, and drive consistent execution across systems and processes. The role requires strategic oversight and hands-on execution in a complex environment with disparate systems and evolving business needs.

Responsibilities

  • IT Compliance Planning and Program Execution
    • Establish an overall compliance strategy and roadmap, including selecting and implementing an enterprise Governance, Risk, and Compliance platform to automate RCM authoring and evidence collection workflows.
    • Own prioritization, tracking, and delivery of key compliance initiatives, including executive status updates on program health.
    • Provide subject matter expertise and guidance to system leads and business partners on compliance expectations, control execution, documentation standards, and system implementation lifecycle considerations.
    • Advise and ensure PCI compliance is sustained by in-scope business units.
    • Oversee internal resources, project-based support, or cross-functional contributors for audit preparation, SOC reporting, PCI compliance adherence, and compliance execution.
  • Governance, Risk, and Documentation Management
    • Coordinate across risk management stakeholder functions (e.g., Legal, Finance, Internal Audit, Corporate IT, BU-level IT) to:
      • Support and evolve the IT Risk Management Program to address Technology, Cybersecurity, Data, Resiliency/Recovery, and Emerging (AI, etc.) risks.
      • Establish IT compliance requirements.
      • Identify and eliminate redundant risk management processes and/or controls.
      • Support the risk management objectives of other functions.
    • Maintain inventories of in-scope systems and applications supporting key regulatory requirements (e.g., ICFR), in-flight IT projects, and relevant stakeholders.
    • Develop frameworks and standards for core IT compliance documentation, including Risk and Control Matrices, process flows, system interface documentation, and remediation plans.
    • Determine review criteria and cadence for assessing documentation prepared by system leads and control owners for quality, completeness, and alignment with compliance requirements.
    • Establish policies, procedures, and governance practices supporting effective and sustainable compliance execution.
  • SOX, IT General Controls, and Audit Support
    • Act as the primary point of contact for IT compliance supporting internal and external audits, including SOX and IT General Controls testing.
    • Organize, collect, and maintain evidence required for audit requests and management review.
    • Liaise with internal stakeholders and auditors to ensure timely and accurate delivery of required materials.
    • Create repeatable processes for identifying, tracking, and remediating control gaps, deficiencies, and related action plans.
    • Support IT risk assessments, control reviews, and compliance evaluations.
  • SOC Reporting and Third-Party Assurance
    • Manage the lifecycle of Service Organization Control reporting.
    • Ensure completion of management evaluation documentation related to third-party controls and reliance.
    • Support assessment of third-party compliance risk in areas such as access management, vendor management, and change management.
  • Technical Data Reconciliation and Compliance Operations
    • Partner with IT and Finance colleagues to monitor adherence to internal policies and key metrics regarding control environment activities (e.g., reconciliation, data analysis, data hygiene).
    • Work closely with infrastructure and application system owners to ensure timely user terminations; conduct look-back analysis for missed terminations and send confirmation materials to Internal Audit.
    • Establish continuous monitoring processes.
  • Monitoring, Reporting, and Training
    • Monitor changes in relevant compliance, privacy, and security requirements and translate them into practical business processes.
    • Prepare reporting for management on compliance status, risks, remediation efforts, and control effectiveness.
    • Collaborate with Internal Audit, financial controls, and IT to develop training materials related to IT compliance, data privacy, and security practices.
    • Support awareness efforts for IT teams and business stakeholders to promote a culture of accountability and compliance.

Supervisory Responsibilities

This role may oversee internal resources, project-based support, or cross-functional contributors in connection with audit preparation, SOC reporting, PCI compliance adherence, and compliance execution.

Requirements

  • Bachelor’s degree in Computer Science, Information Systems, Information Security, Accounting, Finance, or a related field.
  • 10+ years of progressive experience in IT compliance, IT audit, risk management, cybersecurity compliance, or a related governance function.
  • Demonstrated experience supporting SOX and IT General Controls in a complex environment.
  • Experience developing and enhancing Risk and Control Matrices, process flows, remediation plans, system inventories, and related compliance documentation.
  • Strong cross-functional partnership experience with Legal, IT, Security, Internal Audit, Finance, and business stakeholders.

Qualifications

  • Experience supporting compliance activities in connection with mergers and acquisitions.
  • Experience managing third-party assurance processes, including SOC report review and evaluation.
  • Familiarity with enterprise control frameworks such as NIST and ISO 27001.
  • Experience in a public company or similarly regulated environment.
  • Knowledge of SAP (S/4) is a plus, as it is TKO’s Enterprise Finance and Accounting ERP.

Skills

  • Strong knowledge of SOX, ITGC, and general compliance frameworks.
  • Advanced proficiency in Excel; strong working knowledge of PowerQuery, SQL, or similar tools preferred.
  • Understanding of access management, vendor management, change management, and audit evidence requirements.
  • Strong analytical and problem-solving skills with exceptional attention to detail.
  • Excellent written and verbal communication skills, including the ability to communicate technical concepts to non-technical stakeholders.
  • Strong organizational, project management, and documentation skills.
  • High degree of integrity, discretion, and professional judgment.
  • Ability to balance strategic priorities with hands-on execution.

Certifications

Preferred certifications include:

  • Certified Information Systems Auditor (CISA)
  • Certified Information Systems Security Professional (CISSP)
  • Certified in Risk and Information Systems Control (CRISC)

Pay

Hiring rate range: $157,500 – $210,000 annually (minimum will not fall below applicable State/local minimum salary thresholds). The company strives to provide locally competitive rewards packages, including base rate, short- and long-term incentives, growth opportunities, and robust benefits.

Similar jobs