Lead DI Security and Compliance Analyst

Jobtailor

Kentucky

On-site

USD 110,000 - 165,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor in Kentucky seeks a senior IT audit leader to act as the primary liaison for IT audit activities within the CISO organization, coordinating with Internal Audit, external auditors, and IT control owners to ensure timely and accurate execution.

You will conduct risk assessments, ITGC design and testing, SoD analyses, and control testing across ERP and cloud environments, while guiding training, documentation, and ongoing audit readiness for the organization.

Qualifications

  • Bachelor's degree or equivalent years of relevant work experience.
  • Authorized to work in the U.S.; we will not sponsor individuals for employment visas, now or in the future.
  • Typically requires 12+ years of relevant experience.
  • Minimum of 3+ years of progressive experience in information technology, information security, IT compliance, or IT audit.
  • Demonstrated hands‑on experience with IT General Controls (ITGC) design, documentation, and testing within a SOX‑regulated environment.
  • Experience in second line of defense, internal audit team, or external audit engagement in an IT capacity.
  • Strong understanding of risk assessment methodologies and the ability to evaluate and document IT risk.
  • Familiarity with ERP systems (SAP, Oracle, Workday, Salesforce, IFS Cloud), cloud infrastructure (AWS, Azure, GCP), and identity governance and SoD technology platforms.
  • Technical knowledge of Security Operations, Access Management, Platform Security, and Data Security technologies at an engineering or architecture level.
  • Understanding of control frameworks: COSO, COBIT, NIST CSF, ISO 27001, and SOX 302/404.
  • Familiarity with cybersecurity principles including access management, vulnerability management, and data protection.
  • Auditing, compliance, or risk management experience with ITGC walkthroughs and control testing.
  • Exposure to audits under PCAOB AS 2201 is a plus.
  • Certifications: CISA, CISM, CISSP, CIA, CPA.

Responsibilities

  • Serve as primary liaison for IT audit activities within the CISO organization.
  • Coordinate between Internal Audit, external auditors, and IT control owners to ensure timely audit execution.
  • Track open audit requests, evidence submissions, and management responses, ensuring timely resolution and escalation of issues.
  • Execute risk‑based assessments and independent control testing activities from the second line of defense perspective, providing objective assurance on IT controls.
  • Conduct annual and ad hoc IT risk assessments to identify, evaluate, and prioritize risks across the IT environment.
  • Perform second‑line‑of‑defense control testing across ITGC domains, including SoD analysis and change management sampling.
  • Monitor the effectiveness of first‑line control self‑assessments (CSAs) and support User Access Reviews (UARs).
  • Identify trends in control failures and emerging risks, escalating systemic issues with actionable recommendations.
  • Develop and maintain standardized tools, guidance materials, and training programs to build GRC capability.
  • Develop, maintain, and distribute IT audit readiness checklists tailored to control domains and regulatory requirements.
  • Design and deliver training programs and awareness sessions for IT control owners, process owners, and first‑line staff on ITGC requirements, SOX compliance, and evidence collection best practices.
  • Maintain a GRC knowledge base and content for ongoing stakeholder reference.
  • Act as a key contact between CISO, Internal Audit, Risk & Controls, and other technology functions to foster governance culture.
  • Build and maintain trusted relationships with Internal Audit leadership, Risk & Controls management, IT leadership, and business process owners.
  • Provide regular status reporting on audit activities, risk posture, and control effectiveness to the CISO and senior IT leadership.

Skills

IT audit
IT governance
SOX compliance
risk assessment
ITGC
Access Management
Security Operations
identity governance
SoD
vulnerability management
data protection
cloud infrastructure
ERP systems
COSO/COBIT/NIST/ISO27001
PCAOB AS 2201

Education

Bachelor's degree or equivalent

Tools

SAP
Oracle
Workday
Salesforce
IFS Cloud

Job description

Responsibilities
  • Serve as a primary CISO organization liaison for IT audit activities
  • Coordinate between Internal Audit, external auditors, and IT control owners to ensure efficient, timely, and accurate audit execution
  • Track open audit requests, evidence submissions, and management responses, ensuring timely resolution and escalation of issues
  • Execute risk‑based assessments and independent control testing activities from the second line of defense perspective, providing objective assurance on the effectiveness of IT controls
  • Conduct annual and ad hoc IT risk assessments to identify, evaluate, and prioritize risks across the IT environment
  • Perform second‑line‑of‑defense control testing across ITGC domains, including role‑based access reviews, segregation of duties (SoD) analysis, change management sampling, and operational control testing
  • Monitor the effectiveness of first‑line control self‑assessments (CSAs) and provide feedback to strengthen the first line of defense
  • Conduct periodic access recertification reviews and support User Access Reviews (UARs) for in‑scope systems
  • Identify trends in control failures and emerging risks, escalating systemic issues to leadership with actionable recommendations
  • Develop and maintain standardized tools, guidance materials, and training programs to build organizational GRC capability and ensure audit preparedness
  • Develop, maintain, and distribute IT audit readiness checklists tailored to control domains, audit cycles, and specific regulatory requirements
  • Design and deliver training programs and awareness sessions for IT control owners, process owners, and first‑line staff on ITGC requirements, SOX compliance, and evidence collection best practices
  • Maintain a GRC knowledge base and content for ongoing stakeholder reference
  • Act as a key point of contact between the CISO organization, Internal Audit, and the Risk & Controls function and other technology functions, fostering a collaborative and transparent governance culture
  • Build and maintain trusted relationships with Internal Audit leadership, Risk & Controls management, IT leadership, and business process owners
  • Provide regular status reporting on audit activities, risk posture, and control effectiveness to the CISO and senior IT leadership
Requirements
  • Bachelor's Degree or Equivalent Years of Relevant Work Experience
  • Legal authorization to work in the U.S.; we will not sponsor individuals for employment visas, now or in the future
  • Typically requires 12+ years of relevant experience
  • Minimum of 3+ years of progressive experience in one or more of the following: information technology, information security, IT compliance, or IT audit
  • Demonstrated hands‑on experience with IT General Controls (ITGC) design, documentation, and testing within a SOX‑regulated environment
  • Experience working within or supporting a second line of defense function, internal audit team, or external audit engagement in an IT capacity
  • Strong understanding of risk assessment methodologies and the ability to evaluate and document IT risk
  • Familiarity with enterprise IT environments, including ERP systems (SAP, Oracle, Workday, Salesforce, IFS Cloud), cloud infrastructure (AWS, Azure, GCP), and identity governance and SOD technology platforms
  • Technical knowledge and proficiency with Security Operations, Access Management, Platform Security, and Data Security technologies at an engineering or architecture level
  • Solid understanding of IT control frameworks: COSO, COBIT, NIST Cybersecurity Framework (CSF), ISO 27001, and SOX 302/404
  • Working knowledge of cybersecurity principles including access management, identity governance, vulnerability management, and data protection
  • Familiarity with common enterprise application controls, database controls, and infrastructure controls relevant to IT audit
  • Experience in auditing, compliance, or risk management role with responsibility for risk assessments, ITGC walkthroughs, and control testing
  • Exposure to audits conducted under PCAOB standards (AS 2201) is plus
  • Certifications: CISA, CISM, CISSP, CIA, CPA
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior IT Audit & GRC Lead (SOX & ITGC)
Senior IT Audit & GRC Lead (SOX & ITGC)

Jobtailor • Kentucky

On-site
USD 110,000 - 165,000
Information Security Analyst
Information Security Analyst

Sylvan, Inc. • Detroit (MI)

On-site
USD 90,000 - 130,000
Senior Manager, IT Controls & Audit Compliance
Senior Manager, IT Controls & Audit Compliance

Jobtailor • Connecticut

On-site
USD 120,000 - 180,000
Senior Director, GRC, IT Controls, Cyber Culture
Senior Director, GRC, IT Controls, Cyber Culture

Jobtailor • Town of Florida (NY)

On-site
USD 180,000 - 240,000
Lead GRC Analyst (IT/Security)
Lead GRC Analyst (IT/Security)

Ultra Clean Technology • Manor (TX)

On-site
USD 90,000 - 120,000
IT GRC Lead Analyst
IT GRC Lead Analyst

Jobtailor • Westfield Center (OH)

On-site
USD 120,000 - 190,000
IT General Controls - IT Auditor
IT General Controls - IT Auditor

Prodware Solutions • New Brunswick (NJ)

On-site
USD 110,000 - 160,000
Senior Analyst, IT General Controls, Audit Support – Strategic Initiatives
Senior Analyst, IT General Controls, Audit Support – Strategic Initiatives

Jobtailor • Cleveland (OH)

On-site
USD 85,000 - 130,000
Senior IT Audit Manager
Senior IT Audit Manager

SwiftCruit • Waltham (MA)

On-site
USD 130,000 - 175,000
Equity
PTO
Health benefits
+1
CyberSecurity Specialist - GRC
CyberSecurity Specialist - GRC

TechDigital Group • Phoenix (AZ)

On-site
USD 120,000 - 150,000