Analyst II Tech Governance & Assurance
Overview
We seek a skilled IT Risk & Controls professional to lead our first line of defense in IT compliance. You will own daily readiness testing and audit facilitation for critical programs like SOX SOC 1 SOC 2 CCPA/CPRA cybersecurity audits and NYDFS attestation. This hands-on role embeds within control owners to perform self-testing and drive automation reducing manual effort. Expect collaboration with IT Engineering Security and external auditors to maintain audit readiness year-round.
What You'll Do11
- 1Audit Facilitation
- 2SOC 1 SOC 2 and SOX audit coordination
- 3Act as liaison between owners and external auditors
- 4Track findings and ensure remediation closure
- 5First-Line Control Testing across ITGC domains
- 6Design and execute control self-tests
- 7Maintain control narratives and risk matrices
- 8Support CCPA/CPRA and NYDFS certification processes
- 9Automate evidence collection and testing scripts
- 10Implement continuous controls monitoring solutions
- 11Recommend process improvements for efficiency
Requirements11
- 14+ years IT audit experience with SOX ITGC and SOC engagements
- 22+ years ITGC framework familiarity (COSO COBIT SOC Trust Services)
- 32+ years audit facilitation background
- 4Proficiency in GRC platforms such as ServiceNow GRC or Archer
- 5Scripting skills in SQL Python Alteryx or Power BI
- 6Internal audit or Big Four experience preferred
- 7Financial services or banking background
- 8Valid U.S. work authorization without sponsorship required
- 9Core competency in control testing automation
- 10Strong documentation and stakeholder communication abilities
- 11Familiarity with CCPA/CPRA and NYDFS regulations
Salary Insight
$73 - $121k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.

Javen Technologies, Inc
VerifiedSenior IT Risk and Compliance Analyst - GRC Framework Expertise
Lead ownership of IT governance alignment supporting Bank's GRC framework Enterprise Risk Management and Sarbanes-Oxley compliance. Drive improvements through collaboration with IT staff. Analyze technology risks and develop appropriate controls. Stand out by delivering measurable risk reduction outcomes within first 90 days.
Beacon Staffing
VerifiedIT Risk and Compliance Analyst - Beacon Staffing
Lead ownership of IT governance and compliance initiatives at Beacon Staffing. Own development of controls and drive continuous monitoring. Impact visibility across 2-3 days weekly onsite. Differentiate through expertise in SOX and COSO frameworks.

Acunor Infotech
VerifiedIT Audit Contractor, SOX IT & Application Controls
You will execute the SOX compliance program for a fast-paced Internal Audit organization in Palo Alto. Handle IT General Controls (ITGC), IT Application Controls (ITAC), Key Report Testing, and SOC 1 reviews across the audit lifecycle. Collaborate with control owners, external auditors, and IT teams to drive audit readiness and remediation. This contract role offers a direct impact on audit quality with a hybrid schedule (2 days onsite).
Wolfe, LLC
VerifiedSenior GRC Analyst Wolfe LLC
Lead compliance evidence ownership for PCI DSS Level 1 SOC 2 Type II IT GRC Kubernetes AWS React certifications. Stack with QSA and external auditors. Define AI governance controls and review process.
WithumSmith+Brown
VerifiedIT SOX Senior Consultant
WithumSmith+Brown seeks an experienced IT SOX Senior Consultant to lead Risk Advisory growth. This hybrid role involves leading audits across multiple locations and driving improvements in internal controls.

Mitchell Martin, Inc.
VerifiedIT Risk & Compliance Data Reporting Analyst
You will own IT risk and compliance data reporting for a Chicago-based financial firm, ensuring adherence to governance frameworks like NIST and ISO 27001. You will build dashboards and reports that track control effectiveness, risk assessments, and audit readiness. Working with IT, security, and audit teams, you will translate raw data into actionable insights for leadership. This contract role stands out for its focus on reporting automation and direct impact on regulatory compliance.