The Senior Analyst, IT Governance, Risk & Compliance is responsible for executing project deliverables and operational tasks that support TKO’s IT compliance program, including SOX and IT General Controls, audit readiness, governance documentation, and technical data reconciliation.
Reporting to the Manager of IT Governance, Risk & Compliance, this role partners closely with colleagues in Legal, IT, Security, Internal Audit, Finance, and business functions to track and deliver work in support of TKO’s control environment, enterprise compliance obligations, and risk management initiatives.
The ideal candidate brings expertise in governance, risk, and compliance, along with hands-on experience owning and delivering operational work in a highly matrixed and complex environment. This role requires the ability to work autonomously, manage multiple projects and workstreams, and coordinate dependencies across departments.
Essential Duties and Responsibilities
IT Compliance Execution
- Support the Manager of IT Governance, Risk & Compliance in creating and completing program-related work items.
- Own day-to-day support activities for active enterprise governance, risk, and compliance initiatives, including automation of risk and control matrices, evidence-collection workflows, executive reporting, and dashboards.
- Assist with tracking key compliance initiatives and deliverables.
- Provide front-line support to system leads and business partners on compliance processes, including proper control execution, industry-standard documentation, and change-management best practices.
Governance, Risk, and Documentation Management
- Assist with process redesign and ongoing maintenance efforts to identify and eliminate redundant risk-management processes and controls.
- Support the risk-management objectives of other TKO risk-management functions.
- Maintain IT compliance documentation and templates, including Risk and Control Matrices, process flows, system-interface documentation, and remediation plans.
SOX, IT General Controls, and Audit Support
- Complete support and follow-up activities for internal and external audits, including SOX and IT General Controls testing.
- Support the IT Compliance leader in collecting and maintaining evidence for audit requests and management reviews, ensuring timely and accurate delivery of required materials.
- Support the identification, tracking, and remediation of control gaps, deficiencies, and related action plans.
- Support risk assessments, control reviews, and compliance-evaluation processes.
Technical Data Reconciliation and Compliance Operations
- Monitor adherence to internal policies and key metrics related to control-environment activities, including reconciliation, data analysis, and data hygiene.
- Track application system owners’ adherence to the access-termination process, including conducting look-back analyses for terminations that do not meet policy requirements.
Monitoring, Reporting, and Training
- Prepare management reporting on compliance status, risks, remediation efforts, and control effectiveness.
- Document, maintain, and socialize training materials related to IT compliance, data privacy, and security practices.
- Support awareness efforts for IT teams and business stakeholders to promote a culture of accountability and compliance.
Required Qualifications
- 5+ years of experience in IT compliance, IT audit, risk management, cybersecurity compliance, or a related governance function.
- Hands-on experience developing and maintaining Risk and Control Matrices, process flows, remediation plans, system inventories, and related compliance documentation.
- Demonstrated experience supporting multiple cross-functional projects and work assignments.
Preferred Qualifications
- Bachelor’s degree in Computer Science, Information Systems, Information Security, Accounting, Finance, or a related field.
- Demonstrated experience supporting SOX and IT General Controls in a complex public-company environment.
- Hands-on experience supporting PCI compliance activities.
Knowledge, Skills, and Abilities
- Strong knowledge of SOX, IT General Controls, and general compliance frameworks.
- Advanced proficiency in Excel; strong working knowledge of Power Query, SQL, or similar tools preferred.
- Strong analytical and problem-solving skills, with exceptional attention to detail.
- Excellent written and verbal communication skills, including the ability to communicate technical concepts to non-technical stakeholders.