Jobs · Massachusetts

Senior Principal, Digital Governance

Schneider Electric · Boston, MA · Yesterday
HybridFull-time
About The Role Schneider Electric is seeking a senior-level Enterprise IT General Controls (ITGC) professional to help strengthen and mature our global IT controls and risk management program. In this highly visible individual contributor role, you will serve as a subject matter expert and trusted advisor, partnering across Digital, Finance, Internal Control, Audit, Cybersecurity, and Enterprise Architecture teams to ensure effective IT controls, audit readiness, and regulatory compliance. You will play a key role in supporting the design, execution, monitoring, and continuous improvement of IT General Controls across enterprise applications, infrastructure, cloud platforms, and third-party services that support business operations and financial reporting. This position offers the opportunity to influence a global control environment, drive meaningful improvements, and help shape a growing governance program within Schneider Electric. Job Summary The Enterprise IT General Controls Specialist is responsible for supporting the design, operation, monitoring, and continuous improvement of the Enterprise IT General Controls (ITGC) framework. This role helps ensure IT controls are appropriately defined, implemented, documented, monitored, and evidenced across in-scope applications, infrastructure, cloud services, third-party services, and digital platforms that support business operations, financial reporting, and regulatory compliance objectives. The specialist will help align ITGC, Internal Control over Financial Reporting (ICoFR), cybersecurity, resilience, audit, and risk management activities. Working closely with control owners, IT leaders, Internal Control, Internal Audit, external auditors, Cybersecurity, Enterprise Architecture, and operational teams, this position helps improve control execution, evidence quality, remediation management, and overall audit readiness. Key Responsibilities IT General Controls (ITGC) Framework & Operations Apply the Enterprise ITGC policy and control catalog across assigned systems, platforms, and control domains.Support control design and operating effectiveness activities for:User access managementPrivileged access managementJoiner-Mover-Leaver (JML) processesChange managementSoftware Development Lifecycle (SDLC)IT operationsBackup and recoverySegregation of dutiesData managementCloud controlsThird-party controlsMaintain practical control guidance, evidence expectations, and execution routines for control owners and IT stakeholders.Identify control gaps, recurring exceptions, ownership issues, and areas where policy requirements have not been implemented as intended. Internal Control Over Financial Reporting (ICoFR) Support the mapping of ITGCs to ICoFR risks and financial reporting dependencies, including applications, reports, interfaces, access rights, automated controls, and key technology dependencies.Collaborate with Internal Control and Finance stakeholders to confirm in-scope systems and control expectations for financial reporting and Corporate Sustainability Reporting Directive (CSRD)-related processes.Support the annual refresh of ITGC and ICoFR risk mappings, including control ownership, monitoring routines, and evidence requirements.Help translate technical control requirements into clear business impacts, financial reporting relevance, and audit-ready control descriptions. Audit & Governance Coordination Assist with the coordination of internal and external audits related to ITGC, ICoFR, cybersecurity, resilience, and digital governance.Prepare audit requests, walkthrough materials, control narratives, evidence packages, and responses in partnership with control owners and technology teams.Track findings, management action plans, due dates, remediation progress, ownership, and evidence of closure.Escalate issues when evidence is missing, action plans are unclear, deadlines are at risk, or additional leadership alignment is required. Evidence, Monitoring & Reporting Promote consistent, timely, and complete evidence submission for audit and control testing activities.Validate that remediation activities include clear ownership, target completion dates, supporting evidence, and sustainable preventive measures.Prepare concise status reports, dashboards, and executive-level summaries.Leverage available tools and structured repositories to improve visibility, traceability, evidence retrieval, and follow-up effectiveness. Stakeholder Engagement & Continuous Improvement Partner with IT leaders, process owners, Cybersecurity, Enterprise Architecture, Data teams, Internal Control, and Audit teams to improve control maturity.Provide practical guidance to stakeholders on control expectations, audit preparation, and remediation standards.Identify opportunities to simplify control execution, reduce manual effort, improve data quality, and increase automation where appropriate.Support awareness, training, and communication activities that strengthen accountability, ownership, and control culture throughout the organization. Application, Infrastructure & Third-Party Risk Support Support control alignment across ERP platforms, SaaS solutions, cloud environments, infrastructure services, and business-critical applications.Coordinate with application and infrastructure owners to ensure disaster recovery, backup, logging, monitoring, and access control expectations are reflected in control and audit evidence.Review third-party control dependencies, including SOC reports and service provider control evidence, where they support financial reporting or operational resilience objectives.Help identify risks resulting from fragmented ownership, system changes, tooling gaps, manual reconciliations, or incomplete control documentation. Qualifications Education & Certifications Bachelor's degree in Information Technology, Cybersecurity, Accounting Information Systems, Risk Management, Business, Finance, or a related field required; Master's degree preferred.Professional certification such as CISA, CRISC, CISM, CISSP, CGEIT, ITIL, PMP, or equivalent preferred.Working knowledge of ITGC, ICoFR, IT Application Controls (ITAC), SOX-style control environments, and the Three Lines of Defense model. Experience 7+ years of experience in IT risk, IT audit, internal controls, cybersecurity governance, digital governance, enterprise applications, or a related discipline.Experience supporting internal or external audits, including walkthroughs, evidence collection, issue management, remediation tracking, and management responses.Experience operating within global, matrixed organizations and collaborating across diverse stakeholder groups.Experience with ERP platforms, SaaS solutions, cloud technologies, identity and access management, change management, IT operations, and audit management platforms. Skills Strong understanding of IT control domains, including:Access managementChange managementBackup and recoverySDLCIT operationsSegregation of dutiesLogging and monitoringThird-party controlsAbility to translate technical control concepts into clear business, audit, and financial reporting impacts.Strong organizational skills, follow-through, and attention to detail, with a practical approach to evidence quality and audit readiness.Excellent written and verbal communication skills, including the ability to prepare executive summaries and leadership updates.Ability to manage multiple priorities, work effectively under pressure, and build alignment among technical and non-technical stakeholders.Experience using tools such as ServiceNow, Resolver, AuditBoard, SAP GRC, SailPoint, Microsoft 365, and reporting/dashboard solutions. Preferred Qualifications Experience within a Big Four consulting firm, external audit, internal audit, corporate governance, or enterprise risk environment.Experience supporting financial reporting systems, ERP transformation initiatives, or global controls harmonization programs.Familiarity with ICoFR self-assessments, management action plan governance, control owner processes, and audit committee reporting.Knowledge of frameworks and standards such as COBIT, ISO 27001, NIST, ITIL, COSO, and SOX-related audit practices. At Schneider, we believe that every employee is a talent who deserves equal opportunities. This means you matter. Every individual needs to feel valued, supported, and treated fairly to do their best work. Our Total Rewards is our way of saying: “We see you. We value you”. It’s more than just pay and benefits- it’s a meaningful investment in you. It is designed for you to perform, grow, feel safe, and elevate your potential to shine as an impact maker. For this U.S. based position, the expected pay range is USD 168,800 - USD 253,200 per year. This pay range includes base pay and short-term incentives. The compensation range for this full-time position applies to candidates located within the United States. Our pay ranges are determined by reviewing roles of similar responsibility and level. Within the pay range, individual pay is determined by several factors including performance, knowledge, job-related skills, experience, and relevant education or training. Schneider Electric is there when it matters most to you Our Total Rewards package outlines all the benefits and support you’ll enjoy as part of the Schneider Electric team: Care for Yourself and Your Family. We ensure you feel secure with benefits that help you and your family thrive: medical (with member reward points), dental, vision, and basic life insurance, Benefit Bucks (credits to apply towards your benefits), flexible work arrangements, paid family leaves, well-being programs, 12 holidays per year, 20 days of paid time off per year (pro-rated in the first year of employment based on start date). Invest and Plan Your Future. We help you plan and invest for the future with competitive pay and programs: your base salary, short-term incentives or sales incentives, opportunities to own company shares (eligibility depends on start date), and 401(k) + match. Grow Your Skills and Career. We commit to helping you grow with ongoing performance and development conversations, Senior Talent Program, global career opportunities, access to our Schneider Career Hub for new positions, projects, and mentors, and learning platforms like Coursera to equip you with the skills for today and tomorrow. Team Up in the Workplace. We encourage teaming up through project opportunities on the Schneider Career Hub, smart ways to collaborate, celebrating contributions via a recognition program (including service anniversary), sharing your voice in our engagement survey, and fostering an inclusive, caring workplace. Support Your Community. We make a difference in your community with volunteer leave, programs through the Schneider Electric Foundation, initiatives that support youth education, and military leave benefits. Looking to make an IMPACT with your career? When you are thinking about joining a new team, culture matters. At Schneider Electric, our values and behaviors are the foundation for creating a great culture to support business success. We believe that our IMPACT values – Inclusion, Mastery, Purpose, Action, Curiosity, Teamwork – starts with us. IMPACT is also your invitation to join Schneider Electric where you can contribute to turning sustainability ambition into actions, no matter what role you play. It is a call to connect your career with the ambition of achieving a more resilient, efficient, and sustainable world. We are looking for IMPACT Makers; exceptional people who turn sustainability ambitions into actions at the intersection of automation, electrification, and digitization. We celebrate IMPACT Makers and believe everyone has the potential to be one. Become an IMPACT Maker with Schneider Electric – apply today! €40 billion global revenue +9% organic growth 150 000+ employees in 100+ countries You must submit an online application to be considered for any position with us. This position will be posted until filled. Schneider Electric aspires to be the most inclusive and caring company in the world, by providing equitable opportunities to everyone, everywhere, and ensuring all employees feel uniquely valued and safe to contribute their best. We mirror the diversity of the communities in which we operate, and ‘inclusion’ is one of our core values. We believe our differences make us stronger as a company and as individuals and we are committed to championing inclusivity in everything we do. At Schneider Electric, we uphold the highest standards of ethics and compliance, and we believe that trust is a foundational value. Our Trust Charter is our Code of Conduct and demonstrates our commitment to ethics, safety, sustainability, quality and cybersecurity, underpinning every aspect of our business and our willingness to behave and respond respectfully and in good faith to all our stakeholders. You can find out more about our Trust Charter here Schneider Electric is an Equal Opportunity Employer. It is our policy to provide equal employment and advancement opportunities in the areas of recruiting, hiring, training, transferring, and promoting all qualified individuals regardless of race, religion, color, gender, disability, national origin, ancestry, age, military status, sexual orientation, marital status, or any other legally protected characteristic or conduct.

Similar jobs

Data Governance Senior

Freddie MacMcLean, VA· 1 wk ago
Information Technology$105k–$157k/yrapply on careers.freddiemac.com