Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Who You Are
We're looking for a Manager – IT Compliance with deep, hands-on SOX expertise across IT General Controls (ITGCs) and IT Application Controls (ITACs). In this high-impact individual contributor role reporting to the Director of IT Compliance, you'll assist in driving the IT Compliance program and strategy - conducting control design and periodic control effectiveness testing, and working closely with control owners on gap remediation and validation across the systems that support financial reporting.
As a cross-functional influencer, you'll partner closely with Engineering, Product, Security, Finance, and Compliance to keep controls effective as our platforms evolve - embedding automation into compliance workflows and guiding the responsible adoption of AI-enabled technologies. You'll balance delivery speed with control sustainability, bringing the judgment of someone who has designed, tested, and remediated SOX IT controls in complex technology environments, ideally with Big 4 and/or high-growth technology company experience.
What You'll Do
Assist in driving the IT Compliance program and strategy in partnership with the Director of IT Compliance and Strategy, the SOX Compliance function, and internal and external auditors - including scoping, risk assessment, documentation, and testing readiness for the SOX ITGC and ITAC program within your owned domain.
Conduct control design assessments and periodic control effectiveness testing across ITGCs and ITACs, evaluating whether controls are appropriately designed and operating effectively, and reporting results to leadership.
Be accountable for domain-level compliance outcomes; drive multi-quarter initiatives (new system onboarding, control rationalization, evidence automation, continuous controls monitoring) with predictable, milestone-based delivery.
Oversee the day-to-day effectiveness of ITGC operations across logical access management, change management, computer operations (batch processing, backup and recovery, job scheduling, logging), and cloud configuration controls for in-scope systems.
Own the ITAC portfolio: identify, document, and support testing of key automated controls, key reports and IPE (completeness and accuracy), configuration controls, and interface/data-transfer controls in partnership with Engineering and Finance.
Maintain the inventory of systems and tools that support financial reporting (directly or indirectly) and apply risk-based tiering to prioritize control implementation and testing effort.
Serve as the hands-on lead for internal and external IT audits, SOX reviews, and control assessments - facilitating walkthroughs, coordinating PBC requests, supporting testing, and reporting status to leadership.
Work closely with control owners on gap remediation and validation efforts - driving root-cause analysis, advising on remediation design, validating fixes before closure, and preventing repeat findings.
Embed automation and intelligent engineering practices into compliance workflows - automated evidence collection, continuous controls monitoring, and analytics - and evaluate and guide the responsible adoption of advanced and intelligent (AI-enabled) technologies aligned with roadmap needs and control requirements.
Define and communicate the control architecture & requirements, balancing delivery speed against long-term sustainability so controls remain effective and durable as systems, platforms, and delivery models evolve.
Ensure change management and SDLC controls support system stability and release quality while sustaining engineering velocity - making controls preventive, repeatable, and scalable within CI/CD pipelines, infrastructure-as-code, and automated access workflows.
Prepare high-quality documentation (narratives, flowcharts, risk-and-control matrices, test workpapers) and continuous improvement of IT control processes.
Partner cross-functionally with Engineering, Product, Security, Finance, and Compliance; coach and develop control owners; resolve conflicts constructively; and foster a culture of disciplined innovation and continuous technological evolution.
What You’ll Bring
Bachelor’s degree in Information Technology, Accounting, Management Information Systems (MIS), or Finance.
7–10 years of progressive experience in IT audit, internal controls, or technology risk management, including supervisory experience; Big 4 experience preferred.
Professional credentials such as CISA, CRISC, CIA, or CPA strongly preferred.
Deep, hands-on expertise in SOX 404 ITGCs and ITACs, including key reports/IPE, configuration controls, and interface controls.
Strong command of internal control frameworks (COSO, COBIT) and risk assessment methodologies.
Working knowledge of cloud platforms, CI/CD pipelines, DevOps practices, and modern SaaS architectures - and how to design and evaluate controls in these environments.
Sound understanding of security and control principles, including logical access, change management, least privilege, segregation of duties, computer operations, and vulnerability management.
Proven ability to plan and deliver audits and multi-quarter control initiatives with predictable outcomes in complex technology environments.
Strong communication, analytical, problem-solving, and program management skills, with the ability to translate technical detail for executive and audit audiences.
Demonstrated ability to influence stakeholders and uphold standards without direct authority; technology industry experience strongly preferred.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at HighLevel
Explore Top Companies in this Space
Lattice
Software as a Service (SaaS), Human Resources (HR) Technology
Clipboard
Software as a Service (SaaS), Technology
Promethean
Education Technology / EdTech / Software as a Service (SaaS)
Remote
Software as a Service (SaaS), Remote Work Technology
HighLevel
View Company ProfileHighLevel is a comprehensive, all-in-one, AI-powered business operating system and marketing platform designed primarily for digital marketing agencies, freelancers, and small businesses. It provides a centralized suite of tools that replace multiple standalone software subscriptions. Core features include a CRM, sales pipelines, website and funnel builders, email/SMS marketing automation, appointment scheduling, reputation management, and white-labeling capabilities. By consolidating these functions, HighLevel helps businesses capture, nurture, and close leads while streamlining their operations and scaling their growth.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.

