Governance, Risk, and Compliance Senior Associate, IT Controls & Assurance

Weaver

New York, Northern (NY, KY)

Hybrid

USD 82,000 - 100,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health benefits
401(k) plan
Flexible scheduled time off
Sick and safe leave

Job summary

Weaver, a national accounting and advisory firm, seeks a Senior Associate for its Governance, Risk, and Compliance practice in New York. You will oversee IT controls and assurance work across SOC 1/2 engagements and SOX readiness, coordinating with technology, finance, and internal Audit teams.

The role emphasizes risk evaluation, control testing, and client deliverables, with mentorship and growth opportunities in a collaborative culture.

Qualifications

  • Bachelor’s degree in Accounting, MIS, CS, or related field.
  • 2+ years of professional services or similar field.
  • Working knowledge of SOC reporting concepts and attestation standards.
  • Understanding of SOX 404 and IT risk effects on financial reporting.
  • Ability to connect IT controls to business, reporting, and security objectives.
  • Experience supervising junior team members.
  • Strong written and verbal communication skills.

Responsibilities

  • Execute and manage SOC 1 and SOC 2 Type 1/2 examinations, including planning and testing.
  • Perform IT SOX work on IT general controls and reports.
  • Develop and maintain risk and control matrices (RCMs) during planning.
  • Evaluate control design and operating effectiveness across IT domains.
  • Develop process narratives, system descriptions, and test plans.
  • Identify exceptions and communicate practical recommendations to leadership.

Skills

Communication
Leadership
Multi-tasking
Analytical thinking

Education

Bachelor's degree in Accounting / MIS / CS

Tools

Fieldguide
AuditBoard
Workiva
Drata
Vanta

Job description

Governance, Risk, and Compliance Senior Associate, IT Controls & Assurance

Job Category : Advisory

Requisition Number : GOVER003160

  • Posted : August 18, 2026
  • Full-Time
Locations

Showing 1 location

New York, NY

Description

The Weaver Experience

Weaver is a full-service national accounting, advisory and consulting firm with opportunities for professionals in many different fields. We seek to bring a human element to the world of accounting, which includes creating a diverse, collaborative, and entrepreneurial workplace culture. Our leaders truly care about the well-being of all our employees and encourage them to pursue their ambitions.

While our business is based in numbers, our success is truly based on people. It’s why we commit to supporting our people not just in their professional growth, but also in their ability to lead balanced, integrated lives. At the foundation of that commitment areour core values .Weaver’s core values were created specifically to empower our people to deliver extraordinary service and be their best selves. Our goal is to balance high development with high performance in order to meet the long-term goals of each individual, team, and our firm.

Learn more about our services, industry experience and culture atweaver.com .

Position Profile

Weaver is seeking a Senior Associate to join our Governance, Risk, and Compliance (GRC) practice with a primary focus on IT controls and technology assurance. This role will support a balanced portfolio of System and Organization Controls (SOC) 1 and SOC 2 examinations, IT-related Sarbanes-Oxley (SOX) compliance engagements, and other information security and compliance projects as client needs arise.

The GRC IT team works with technology, information security, finance, internal audit, and business stakeholders to evaluate controls, communicate practical recommendations, and deliver high-quality client service. Team members gain exposure to a variety of industries, technologies, control environments, and regulatory expectations while developing both technical and engagement-management skills.

The Senior Associate is responsible for leading assigned workstreams and supporting the planning, execution, supervision, and completion of engagements. The ideal candidate combines sound professional judgment, strong IT controls knowledge, willingness to test or review lower risk non-IT controls, clear communication, and the ability to manage multiple concurrent assignments while coaching junior team members.

What You Will Do

  • Execute and help manage SOC 1 and SOC 2 Type 1 and Type 2 examinations, including planning, walkthroughs, risk assessment, control evaluation, testing, documentation, issue evaluation, and report support.
  • Perform IT SOX work over in-scope systems and processes, including IT general controls, automated controls, key reports, interfaces, and other technology-dependent controls relevant to internal control over financial reporting.
  • Experience developing and maintaining risk and control matrices (RCMs) during engagement planning, including documenting processes, identifying relevant risks, mapping controls to risks and engagement objectives, and defining appropriate control testing procedures.
  • Evaluate control design and operating effectiveness across logical access, change management, computer operations, cybersecurity, incident management, business continuity, vendor management, and related domains.
  • Develop and review process narratives, system descriptions, risk and control matrices, test plans, workpapers, evidence requests, and client-ready deliverables.
  • Identify exceptions and control gaps, assess their significance, and communicate clear, practical recommendations to engagement leadership and client stakeholders.
  • Coordinate day-to-day client requests, monitor engagement status and budgets, elevate risks promptly, and help keep concurrent projects on schedule.
  • Supervise and coach Associates by reviewing workpapers, providing timely feedback, and reinforcing firm methodology and quality expectations.
  • Support other technology risk, information security, and compliance engagements as business needs arise, which may include readiness assessments, internal audit, regulatory compliance, or controls advisory projects.
  • Contribute to practice development through methodology improvements, knowledge sharing, proposal support, and participation in recruiting and team initiatives.

To be successful in this role, the following qualifications arerequired:

  • Bachelor’s degree in Accounting, Management Information Systems, Computer Science, or related field
  • 2+ years of experience in professional services or similar field
  • Working knowledge of SOC reporting concepts and applicable attestation standards, including experience supporting SOC 1 and/or SOC 2 engagements
  • Understanding of SOX Section 404, internal control over financial reporting, and how technology risks and controls affect financial reporting
  • Ability to understand business and financial reporting processes, identify relevant technology risks, and connect IT controls to business, reporting, and security objectives
  • Experience reviewing workpapers and supervising, coaching, or informally leading junior team members
  • Strong written and verbal communication skills, including the ability to explain technical control matters to both technical and nontechnical stakeholders.
  • Strong organization, attention to detail, professional skepticism, and the ability to manage multiple priorities and deadlines
  • Ability to appropriately use firm-approved AI and automation tools to improve engagement efficiency, research, documentation, and data analysis while maintaining confidentiality, professional judgment, quality-control requirements, and compliance with firm policies
  • Ability to travel to client locations or Weaver offices as engagement needs require.

Additionally, the following qualifications arepreferred:

  • CISA, CPA, CIA, CISSP, CISM, or another relevant certification, or demonstrated progress toward certification
  • Awareness or exposure to relevant frameworks and criteria such as NIST, ISO/IEC 27001, HITRUST, PCI DSS, and other security or compliance standards
  • Experience with audit and GRC platforms such as Fieldguide, AuditBoard, Workiva, Drata, Vanta, or similar tools
  • Experience serving clients in financial services, technology, insurance, healthcare, or other regulated industries.

Compensation and Benefits : At Weaver, our most valuable resources is our people. We take the time to evaluate our employees' wants and needs and invest our resources accordingly. A reasonable estimate of the compensation range for this position is $82,000 to $100,000. Actual compensation will be based on a variety of factors including but not limited to experience, skills, certifications, and geographical location. In addition to compensation packages, Weaver offers competitive health benefits, such as medical, dental, vision, disability, life insurance, and a 401(k) plan. Further, we support our employees by offering flexible scheduled time off (STO), minimum of 56 hours of sick and safe leave, 11 holidays, and 2 scheduled recharge days! Learn more here - Weaver benefits .

We also offer in-house CPE and learning opportunities through our internal Learning & Development department. Our multi-faceted internal learning program including technical improvement, practice development, management/leadership training, and whole-life growth. Our goal is to balance both high development with high performance to meet the long-term goals of each individual, team, and our firm.

People are our formula! At Weaver, we recognize that everyone brings different strengths, backgrounds, and working styles to our team. We cultivate a safe and inclusive work environment that celebrates each individual’s unique qualities through visibility, progression, advocacy, and support. We are proudly an equal opportunity employer.

This role is Employee Referral Program eligible.

Equal Opportunity Employer

This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Governance, Risk, and Compliance Senior Associate or Supervisor (IT)
Governance, Risk, and Compliance Senior Associate or Supervisor (IT)

Weaver • Dallas (TX)

On-site
USD 90,000 - 140,000
Health benefits
Flexible time off
CPE and training
Governance, Risk, and Compliance Senior Associate or Supervisor (IT)
Governance, Risk, and Compliance Senior Associate or Supervisor (IT)

Weaver • Austin (TX)

On-site
USD 90,000 - 130,000
Health benefits
Flexible STO
Sick and safe leave
+1
Governance, Risk, and Compliance Senior Associate or Supervisor (IT)
Governance, Risk, and Compliance Senior Associate or Supervisor (IT)

Weaver • Houston (TX)

On-site
USD 90,000 - 130,000
Health benefits
401(k) plan
Paid holidays
+3
Governance, Risk, and Compliance Associate - IT
Governance, Risk, and Compliance Associate - IT

Weaver • New York (NY)

On-site
USD 75,000 - 85,000
Health benefits
401(k) plan
Paid time off
+4
Governance, Risk, and Compliance Senior Associate or Supervisor (IT)
Governance, Risk, and Compliance Senior Associate or Supervisor (IT)

Weaver • Fort Worth (TX)

On-site
USD 90,000 - 130,000
Health benefits
401(k) plan
PTO
+2
Governance, Risk, and Compliance Associate - IT
Governance, Risk, and Compliance Associate - IT

Weaver • Philadelphia

On-site
USD 75,000 - 85,000
Health benefits
401(k) plan
Flexible time off
Governance, Risk, and Compliance Associate - IT
Governance, Risk, and Compliance Associate - IT

Weaver • Little Falls (NJ)

On-site
USD 70,000 - 100,000
Governance, Risk, and Compliance Associate or Senior Associate - Asset Management Consulting
Governance, Risk, and Compliance Associate or Senior Associate - Asset Management Consulting

Weaver • Dallas (TX)

On-site
USD 70,000 - 110,000
In-house CPE
Learning & Development
Equal opportunity employer
Governance, Risk, and Compliance Senior Manager - Public Sector with State Government and Higher Ed. Focus
Governance, Risk, and Compliance Senior Manager - Public Sector with State Government and Higher Ed. Focus

Weaver • Austin (TX), Northern (KY)

Hybrid
USD 120,000 - 160,000
Competitive health benefits
401(k) plan
Flexible time off (STO)
Governance, Risk, and Compliance Associate or Senior Associate - Asset Management Consulting
Governance, Risk, and Compliance Associate or Senior Associate - Asset Management Consulting

Weaver • Houston (TX)

On-site
USD 72,500 - 90,000
Flexible scheduled time off
Health benefits (medical, dental, vision)
401(k) plan