IT Risks & Control Manager

Nebius

United States

On-site

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive compensation
Career growth
Flexible and ownership mindset

Job summary

Nebius is building a next-generation AI cloud platform globally and seeks an IT Risk & Controls Manager to embed risk across engineering and technology teams. You will shape IT SOX controls, partner with engineers, manage evidence quality, and coordinate with auditors while driving modernization through automation and AI-enabled tooling.

The role requires strong in-house tech experience, COSO/COBIT knowledge and a hands-on, autonomous approach across international teams and time zones.

Qualifications

  • Degree in Information Systems, Computer Science, Engineering, Accounting or related field, or equivalent experience.
  • Eight+ years in IT risk, IT controls, IT SOX, technology assurance or related area.
  • In-house technology or corporate ownership experience required; advisory-only background not sufficient.

Responsibilities

  • Act as risk and controls partner for a technology organization or portfolio, mapping architecture, operations, risks and financial reporting dependencies.
  • Own and improve IT risk and control framework, including scoping, risk assessment, RCM and control catalog maintenance.
  • Lead IT SOX readiness, including walkthroughs, evidence review, testing coordination and remediation oversight.
  • Collaborate with engineering, platform, infrastructure, security and corporate IT teams to design scalable controls.
  • Design and assess IT general controls across access, change management, SDLC, operations, incidents and third-party services.
  • Evaluate IT application controls and automated controls, ensuring accuracy of system-generated information.
  • Translate complex risks into practical guidance for engineers and finance stakeholders.
  • Use data analytics, automation and AI-assisted tools to improve control coverage and evidence quality.

Skills

IT risk management
IT controls
IT SOX
COSO
COBIT
Cloud/DevOps/CI-CD
IAM & security
Kubernetes
communication with engineers
english proficiency

Education

Bachelor's degree in Information Systems/CS/Engineering/Accounting

Tools

GRC tools (Workiva/Jira/ServiceNow GRC)

Job description

About Nebius:

Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.

Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.

Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.

The role

Nebius isseekingaIT Risk & Controls Managerto act as an embedded risk partnertoour engineering and technology organizations.

You will help scale and strengthen a modern IT SOX andcontrolsframework acrossNebius’scustom-built AI cloud platform, infrastructure, corporate technologyenvironmentand other systems supporting financial reporting.

This role goes beyond traditional IT audit testing. You will work directly with engineering leaders, system owners, Finance, InternalControlsand external auditors toidentifyrisk, design scalable controls, improve evidence quality, driveremediationand embed compliance into the way our technology organizationsoperate.

The successful candidate will combine deep IT risk andcontrolsexpertisewith meaningful in-house technology experience. You must be equally comfortable discussing technical control design with engineers, explaining risk implications to businessleadersand aligning audit expectations with external assurance providers.

Your responsibilities will include:
  • Act as the risk and controls partner for an assigned technology organization or system portfolio, developing a detailed understanding of its architecture, operations,risksand financial-reporting dependencies.
  • Own and continuously improve the relevant IT risk and control framework, including system scoping, risk assessment, RCM and control-catalogue maintenance,documentationand control ownership.
  • Lead IT SOX readiness for assigned systems, including walkthrough preparation, evidence-quality review, testing coordination, issueevaluationand remediation oversight.
  • Partner with engineering, platform, infrastructure,securityand corporate IT teams to design and implement scalable controls that address risk while supporting operational efficiency.
  • Design, assess and enhance ITGCs across areas such as user access, privileged access, segregation of duties, change management, SDLC, system operations, incidentmanagementand third-party services.
  • Assess IT application controls, automated controls and IT-dependent business controls, including the completeness and accuracy of system-generated information used in business-process controls.
  • Evaluate how business controls depend on systems, integrations, configurations, reports and underlying ITGCs, and work with both business and IT control owners to resolve gaps.
  • Apply risk and controls thinking to modern engineering practices, including cloud infrastructure, DevOps, CI/CD, repositories, deployment processes, containerizedenvironmentsand audit logging.
  • Lead the assessment and remediation of control gaps arising from new systems, major technology transformations, platform changes,integrationsand acquisitions.
  • Review third-party assurance reports anddeterminethe impact of vendor controls and complementary user-entity controls on theNebiuscontrol environment.
  • Maintain effective working relationships with external auditors and advisers,aligning onaudit scope, evidence expectations, testing approaches, reliance opportunities, timelines and issue resolution.
  • Translate complex technical risks and auditor requirements into practical guidance for engineering and system owners.
  • Use data analytics, automation, continuousmonitoringand AI-assisted tools to improve control coverage, evidencequalityand the efficiency of the IT SOX program.
  • Contribute to the development of IT controlsmethodology, standards, tooling, training, reporting and the broader Risk Partner operating model.
  • Provide clear, concise updates on control health, audit readiness, deficiencies and remediation progress to senior technology and Finance stakeholders.
We expect you to have:
  • A degree in Information Systems, Computer Science, Engineering, Accounting, Finance or a related discipline, or equivalent professional experience.
  • At least eight years of progressive experience in IT risk, IT controls, IT SOX, technology assurance, ITauditor a closely related area.
  • Meaningful in-house technology or corporate ownership experience isrequired. Big Four or consulting experience is valuable when combined withsubsequentin-house responsibility, but an exclusively advisory or external-audit background will not be sufficient.
  • Experience working in a first-line technology, engineering,systemsor IT operations role, or as an embedded in-house risk partner supporting a technology organization.
  • Hands-on experience in an engineering-led technology, cloud, SaaS,platformor digital-product environment.
  • Strong practical knowledge of SOX 404, ITGCs, IT application controls, automated controls,COSOand COBIT.
  • Demonstrated experience with control design, implementation, monitoring, evidence review, audit readiness, issueevaluationand remediation.
  • Practical understanding of modern technology environments, including cloud infrastructure, IAM, DevOps, CI/CD, SDLC, software repositories, deployment practices, systemintegrationsand container orchestration such as Kubernetes.
  • Experience connecting business-process controls to supporting systems, automated controls, IPEs/IUCsand underlying IT dependencies.
  • The ability to communicate effectively with engineers, technical leaders, Financestakeholdersand external auditors.
  • Strong judgment and the confidence to challenge control owners while developing practical, scalable solutions.
  • A highly autonomous and hands-on approach, with the ability tooperateeffectively in an evolving environment with incomplete processes and competing priorities.
  • Strong written and verbal English.
  • The ability to work effectively across international time zones and travel when needed to build relationships with key technology and audit stakeholders.
It will be an added bonus if you have:
  • A professional certificationsuch as CISA, CRISC, CISM, CIA,CPAoran equivalentqualification.
  • Experience building or materially transforming an IT SOX or technology-controlsframework in a listed or pre-IPO technology company.
  • Experience in AI infrastructure, cloud platforms, large-scale SaaS, fintech,marketplacesor another engineering-intensive environment.
  • Experience with GRC andaudit-managementtools such as Workiva, Jira, ServiceNow GRC or similar platforms.
  • Experience with enterprise SaaS and financial systems such as NetSuite, HR platforms, billing systems, procurementtoolsor treasury systems.
  • Experience onboardingacquiredcompanies or newly implemented systems into SOX scope.
  • Experience with control automation, continuous monitoring, dataanalyticsor AI-assisted assurance.
  • Exposure to AI governance, AI/ML control environments or controls supporting AI-enabled development and operations.
Benefits & Perks:
  • Competitive compensation
  • Career growth and learning opportunities
  • Flexibility and ownership
  • Collaborative and innovative culture
  • Opportunity to work on impactful AI projects
  • International environment and talented teams
What's it like to work at Nebius:

Fast moving- Bold thinking- Constant growth- Meaningful impact- Trust and real ownership- Opportunity to shape the future of AI

Equal Opportunity Statement:

Nebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.

Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire.

If you need accommodations during the application process, please let us know.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Risks & Control Manager
IT Risks & Control Manager

Nebius • Berlin (NH)

On-site
USD 140,000 - 170,000
Competitive pay
Career growth
Flexibility & ownership
+3
Internal Control Business Partner
Internal Control Business Partner

Nebius • United States

On-site
USD 120,000 - 180,000
Competitive compensation
Career growth
Flexibility and ownership
+3
Internal Control Business Partner
Internal Control Business Partner

Nebius • Berlin (NH)

On-site
USD 120,000 - 180,000
Competitive compensation
Career growth and learning
Flexibility and ownership
+2
Internal Control Business Partner
Internal Control Business Partner

Nebius • Prague (OK)

On-site
USD 110,000 - 170,000
Competitive compensation
Career growth and learning
Flexibility and ownership
+3
Financial Controller
Financial Controller

Nebius • United States

Hybrid
USD 140,000 - 175,000
Health insurance
401(k) plan
Parental leave
+2
Technical Due Diligence Manager- Data Centers, EMEA
Technical Due Diligence Manager- Data Centers, EMEA

Nebius • United States

On-site
USD 120,000 - 180,000
Competitive compensation
Career growth and learning
Flexibility and ownership
+3
Financial Controller
Financial Controller

Socket.dev • United States

On-site
USD 140,000 - 175,000
Health insurance
401(k) plan
Parental leave
+2
US PSOC Manager
US PSOC Manager

Nebius • United States

On-site
USD 147,000 - 184,000
Competitive compensation
Career growth opportunities
Collaborative and innovative culture
+1
Technical Due Diligence Manager
Technical Due Diligence Manager

Nebius • United States

On-site
USD 150,000 - 183,000
Competitive pay
Career growth
Flexibility
+3
Senior Applied AI Solutions Engineer
Senior Applied AI Solutions Engineer

Nebius • Amsterdam (VA)

Hybrid
USD 200,000 - 350,000
Competitive compensation
Career growth
Flexible working arrangements
+3