Director, IT Governance, Risk & Compliance

Commercial Metals Company

Irving, Northern (TX, KY)

Hybrid

USD 180,000 - 240,000

Full time

10 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Day 1 benefits coverage
401(k) company match
Life and disability insurance
Employee stock purchase plan
Training and advancement opportunities

Job summary

Commercial Metals Company is seeking a senior IT Audit and Technology Risk leader in Irving, TX. You will drive governance maturity, policy management, and control design across SAP and enterprise systems, collaborating with internal and external auditors.

You will guide risk-based remediation, metrics, and evidence quality, ensuring compliance while supporting business objectives in a Fortune 500 environment.

Qualifications

  • 12+ years in IT audit, technology risk, governance, or cybersecurity assurance.
  • Proven leadership of teams or managers.
  • Big 4 external audit experience preferred, with IT audit or SOX ITGC focus.
  • Deep knowledge of SOX ITGC, control design and testing, risk assessment and remediation.
  • Strong knowledge of SAP security, access reviews, change management, and reporting.

Responsibilities

  • Lead IT Governance, Risk & Compliance program maturation and strategy.
  • Establish governance standards, decision rights, and control ownership.
  • Strengthen policy management, compliance monitoring, and evidence artifacts.
  • Align IT objectives with business strategy and risk priorities.
  • Interact with Internal Audit, external auditors, and compliance stakeholders.

Skills

IT audit
technology risk
governance
compliance
cybersecurity assurance

Education

Bachelor's degree in Information Systems
MBA preferred

Tools

SAP GRC
ServiceNow GRC
Workiva
Archer
MetricStream

Job description

Select how often (in days) to receive an alert:

Location: Irving, TX, US, 75039

Group: Finance

Division: Information Technology

Job ID: 23870

it's what's inside that counts

There’s more to CMC than our products and the buildings, structures, and roads they go into. At CMC, it’s the people inside our recycling centers, fabrication plants, manufacturing facilities, steel mills and offices that make us who we are as a company. Our success comes from finding, retaining, and supporting the highest quality talent by offering:

  • Day 1 Benefits Coverage with low cost Medical, Vision, Dental
  • Day 1 Paid-time Off and Vacation
  • 4.5% Company Match 401(k) plan
  • Competitive Compensation and Bonuses
  • Company-paid Life and Disability Insurance
  • Employee Stock Purchase Plan
  • Training and Advancement Opportunities
Why This Job

CMC provides an excellent opportunity to learn the steel, construction reinforcement and ground stabilization industries and to grow in your career. Whether you will spend your day brainstorming in an office cubicle, operating a crane, running manufacturing equipment or troubleshooting technical obstacles, at CMC, you’ll get the training and support from your team that you need to excel in your role and reach your full potential.

What You'll Do
  • Lead the continued maturation of CMC's IT Governance, Risk & Compliance program and define the next phase of its maturity strategy
  • Establish consistent governance standards, accountability models, decision rights, and control ownership across technology functions
  • Strengthen control design, policy management, compliance monitoring, and standard artifacts, with rigor proportionate to financial, regulatory, cybersecurity, and operational risk
  • Drive alignment among business objectives, technology strategy, compliance requirements, and risk management priorities
  • Promote a culture of accountability, operational discipline, and continuous improvement in which compliance is embedded in day-to-day delivery
  • Serve as the primary IT leadership interface for Internal Audit, external auditors, and compliance stakeholders
  • Improve audit readiness through standardized evidence management, documentation practices, remediation governance, control monitoring, request intake, and clear closure criteria
  • Partner with technology and business leaders to proactively address audit findings, improve evidence quality, and reduce recurring deficiencies and late-cycle surprises
  • Provide executive-level insight on governance maturity, compliance performance, control effectiveness, remediation aging, evidence quality, and emerging risk
  • Ensure compliance activities improve operations and control effectiveness rather than simply satisfy audit requirements, while maintaining the distinction between management ownership and independent assurance
  • Oversee ITGC and SOX compliance across access management, change management, computer operations, interfaces, key reports, and technology-dependent controls
  • Establish and execute annual approach to IT SOX scoping in collaboration with Internal Audit and management stakeholders
  • Direct governance for SAP access, segregation of duties, privileged access, Firefighter / emergency access, user access reviews, and SAP GRC capabilities
  • Establish a risk-based method to prioritize deficiencies by financial reporting exposure, regulatory impact, cybersecurity risk, and operational complexity
  • Partner with IT, Finance, Internal Audit, Cybersecurity, and business stakeholders to support effective governance, compliance, and control execution
  • Support business units and control owners in identifying IT control gaps
  • Provide training and guidance to IT control owners and business unit managers on SOX requirements, control objectives, and best practices
  • Implement a repeatable evidence operating model with standardized repositories, request ownership, naming conventions, quality checks, retention requirements, and closure criteria
  • Drive timely, sustainable remediation of deficiencies and validate that corrective actions are designed, implemented, documented, and testable
  • Establish dashboards and metrics that show control effectiveness, exceptions, remediation progress, audit demand, and recurring failure patterns
  • Identify opportunities to automate controls, evidence collection, access reviews, monitoring, and reporting through SAP GRC and other enabling technologies
  • Use lessons learned from audits and control failures to improve processes, training, system design, and accountability
  • Work with management to evaluate control evidence against quality standards prior to submitting it to auditors
  • Identify control deficiencies and recommend remediation plans in collaboration with Internal Audit
What You'll Need
  • 12+ years of progressive experience in IT audit, technology risk, governance, compliance, cybersecurity assurance, or related disciplines, including at least 5 years leading managers or senior professional teams
  • Proven experience leading and maturing an IT audit, technology compliance, governance, or technology risk organization within a large, complex enterprise
  • Prior Big 4 public accounting or external audit experience serving large companies is strongly preferred, with direct responsibility for IT audit, SOX ITGC, controls assurance, or technology risk engagements
  • Deep knowledge of SOX ITGCs, control design and testing, risk assessment, deficiency evaluation, remediation, audit evidence, and management reporting
  • Strong working knowledge of enterprise applications and infrastructure controls, including SAP security, segregation of duties, privileged access, change management, computer operations, interfaces, and key reports
  • Demonstrated success improving audit readiness, strengthening control environments, reducing repeat findings, and advancing compliance program maturity beyond tactical audit response
  • Executive-level communication and stakeholder management skills, including the ability to influence across IT, Finance, Internal Audit, external auditors, and business leadership
  • CISA certification strongly preferred. CPA, CIA, CRISC, or other relevant certification is a plus
  • Experience with SAP S/4HANA, SAP GRC, ServiceNow GRC / IRM, Workiva, Archer, MetricStream, or comparable governance and compliance platforms
  • Knowledge of commonly used frameworks and requirements such as COBIT, COSO, NIST CSF, ISO 27001, SOC reporting, CMMC, NIS2, and AI governance
Your Education
  • Bachelor's degree in Information Systems, Accounting, Finance, Cybersecurity, Business, or a related field. MBA preferred

We are CMC, a Fortune 500® company at the leading edge of our industry. Our construction reinforcement and steel products have supported construction projects and structures around the world. The secret to our success? We’ve built our legacy by assembling a team of innovators and doers to tackle some of the most challenging construction reinforcement problems facing our world for more than 100 years — and we’re just getting started.

CMC is committed to providing equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, age, physical or mental disability, national origin, citizenship, military or veteran status, sexual orientation, gender identity and/or expression, genetic information, or other status protected by federal, state or local law.

Established in 1915 | Copyright 2025 CMC. All rights reserved

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director, IT Governance, Risk & Compliance
Director, IT Governance, Risk & Compliance

Commercial Metals • Irving (TX)

On-site
USD 150,000 - 210,000
Day 1 Benefits Coverage with low cost
401(k) company match
Bonuses
+3
Director, IT Governance, Risk & Compliance
Director, IT Governance, Risk & Compliance

CMC • Irving (TX)

On-site
USD 140,000 - 170,000
Day 1 Benefits Coverage
401(k) company match
Bonuses
+3
Superintendent
Superintendent

CMC • Catoosa (OK)

On-site
USD 65,000 - 90,000
Day 1 Benefits
Paid time off
401(k) match
+5
Finance Manager
Finance Manager

Commercial Metals • Irving (TX)

On-site
USD 110,000 - 150,000
Day 1 Benefits
401(k) match
Lifestyle Benefit
+4
Quality Inspector
Quality Inspector

CMC • Denton (TX)

On-site
USD 42,000 - 62,000
Day 1 Benefits Coverage
4.5% 401(k) company match
Life and Disability Insurance
+1
Superintendent
Superintendent

Commercial Metals • Catoosa (OK)

On-site
USD 55,000 - 82,000
Day 1 Benefits Coverage
Paid Time Off
401(k) with company match
+5
Superintendent
Superintendent

Commercial Metals Company • Catoosa (OK)

On-site
USD 70,000 - 110,000
Day 1 Benefits
PTO & Vacation
401(k) Match
+4
Office Manager
Office Manager

Commercial Metals • Knoxville (TN)

On-site
USD 42,000 - 65,000
Medical insurance
Paid time off
401(k) match
+5
Finance Manager
Finance Manager

Commercial Metals Company • Irving (TX)

On-site
USD 120,000 - 180,000
Day 1 Benefits
Paid Time Off
401(k) Match
+4
Finance Manager
Finance Manager

CMC • Irving (TX)

On-site
USD 110,000 - 140,000
Day 1 benefits
401(k) match
Bonuses
+5