1

It Governance Risk Jobs (NOW HIRING)

IT Governance Consultant

MD · On-site

$90K - $150K/yr

Certified in Governance, Risk and Compliance (CGRC), (GRC Professional), FISMA, SOC, PCI DSS * 8+ years of experience supporting federal agencies or defense organizations within: * IT governance, ...

$92K - $120K/yr

IT - Governance Risk and Compliance - IT - Gov Analyst Posted Thursday, August 20, 2026 at 10:00 AM Job Title: IT - Gov Analyst, Status: Exempt, Reports to: Manager - IT - Governance Risk and ...

Support day-to-day operations of IT Governance, Risk and Compliance functions. Execute technology risk management processes and provide input to support continuous improvement of process and program ...

IT Governance Manager

Atlanta, GA · On-site

$94K - $112K/yr

Title: IT Governance Manager Location: Atlanta, GA Key Responsibilities Governance & Compliance ... Support documentation of funding justifications, risk assessments, and policy compliance as part of ...

The position is primarily focused on IT risk management but also plays a key part in assisting the Director of Business Continuity with all aspects of the IT Governance, Risk and Compliance (GRC ...

The position is primarily focused on IT risk management but also plays a key part in assisting the Director of Business Continuity with all aspects of the IT Governance, Risk and Compliance (GRC ...

$69K - $69K/yr

... organization's governance, risk, privacy, and compliance program, ensuring technology systems ... It partners closely with Legal, Information Security, IT, People Team, and Procurement to identify ...

Facilitate cross-functional collaboration (IT, Engineering, Legal, HR) to address security risks. * Advise IT and IS leadership on risk impacts and governance priorities. * Assist with the design and ...

Showing results 21-40

IT Governance Risk information

What is IT governance risk?

IT Governance Risk refers to the potential threats and vulnerabilities that can affect an organization's information technology systems, processes, and data. It involves identifying, assessing, and managing risks related to IT operations, compliance, security, and strategic alignment with business objectives. Effective IT governance risk management helps organizations ensure regulatory compliance, protect sensitive information, and support business continuity. Professionals in this field develop policies, procedures, and controls to mitigate risks and enable informed decision-making.

How does an IT governance risk professional typically collaborate with other departments within an organization?

IT Governance Risk professionals frequently work cross-functionally, partnering with departments such as IT, legal, compliance, and business units to ensure that risk management practices align with organizational objectives and regulatory requirements. This collaboration often involves facilitating risk assessments, developing and implementing policies, and providing guidance on risk mitigation strategies. Clear communication and strong relationship-building skills are key, as the role requires translating technical risks into business impacts and gaining buy-in from stakeholders across the company.

What are the key skills and qualifications needed to thrive as an IT governance, risk, and compliance (GRC) professional, and why are they important?

To thrive as an IT GRC professional, you need a solid understanding of information security principles, risk management frameworks, and relevant regulatory standards, often supported by a degree in IT or cybersecurity and certifications like CISA or CISSP. Familiarity with GRC tools such as RSA Archer, ServiceNow GRC, and risk assessment methodologies is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you interpret complex regulations and collaborate with stakeholders. These competencies ensure effective risk mitigation, regulatory compliance, and alignment between IT and business objectives.

What is the difference between It Governance Risk vs It Security Analyst?

AspectIt Governance RiskIt Security Analyst
CertificationsCISA, CRISCCISSP, Security+
Work EnvironmentPolicy development, risk assessment, complianceMonitoring security systems, incident response
Industry UsageGovernance, risk management, compliance teamsSecurity operations teams, IT departments

It Governance Risk focuses on establishing policies, managing IT risks, and ensuring compliance across the organization. In contrast, an It Security Analyst primarily monitors security systems, investigates incidents, and implements security measures. While both roles require understanding of IT frameworks and certifications like CISA or CISSP, their core responsibilities differ: governance versus security operations.

Is IT governance risk and compliance a good career?

IT Governance Risk and Compliance is a growing field that involves managing an organization’s IT policies, security, and regulatory requirements. It requires knowledge of frameworks like ISO 27001 or COBIT and often benefits from certifications such as CISA or CISSP. The role offers opportunities in various industries with a focus on risk management, security, and compliance strategies.

What are the roles of IT governance risk?

IT governance risk involves identifying, assessing, and managing risks related to information technology to ensure alignment with organizational goals and compliance requirements. IT governance risk professionals develop policies, implement controls, and monitor systems to mitigate threats such as data breaches, cyberattacks, and operational failures, often using frameworks like COBIT or ISO 27001. Strong risk management helps organizations maintain security, improve decision-making, and ensure regulatory compliance.
More about IT Governance Risk jobs

What cities are hiring for It Governance Risk jobs?

Cities with the most It Governance Risk job openings:

Infographic showing various It Governance Risk job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 90% Full Time, 7% Part Time, and 2% Contract. Highlights an 82% Physical, 5% Hybrid, and 13% Remote job distribution.

Senior Director, IT Governance, Risk and Compliance

Remote

Full-time

Medical, Retirement, PTO

Posted 28 days ago


Job description

Who We Are:

TKO Group Holdings, Inc. (NYSE: TKO) is a premium sports and entertainment company. TKO owns iconic properties including UFC, the world's premier mixed martial arts organization; WWE, the global leader in sports entertainment; and PBR, the world's premier bull riding organization. Together, these properties reach 1 billion households across 210 countries and territories and organize more than 500 live events year-round, attracting more than three million fans. TKO also services and partners with major sports rights holders through IMG, an industry-leading global sports marketing agency; and On Location, a global leader in premium experiential hospitality.

Job Summary

The Senior Director, IT Governance, Risk and Compliance, is responsible for leading and executing core elements of TKO's IT compliance program, with a focus on SOX and IT General Controls, audit readiness, governance documentation, benchmarking against recognized security frameworks, third-party assurance, and technical data reconciliation activities. Reporting to TKO's SVP of IT Business Systems, this role will partner closely with Legal, IT, Security, Internal Audit, Finance, and business stakeholders to strengthen TKO's control environment, support enterprise compliance obligations, help lead risk management, and drive consistent execution across systems and processes.

This role requires both strategic oversight and hands-on execution. The successful candidate will bring deep experience in IT compliance and controls, strong technical data management capability, and the ability to operate effectively across a complex environment with disparate systems, inconsistent data structures, and evolving business needs.

Essential Duties and Responsibilities

IT Compliance Planning and Program Execution

  • Establish an overall compliance strategy and roadmap which includes selecting and implementing an enterprise Governance, Risk and Compliance platform to automate RCM authoring and drive evidence collection workflows.

  • Own prioritization, tracking, and delivery of key compliance initiatives including executive status updates regarding the program status and health

  • Provide subject matter expertise and guidance to system leads and business partners on compliance expectations, control execution, documentation standards, and system implementation lifecycle considerations

  • Advise and ensure PCI compliance is being sustained by in-scope business units.

  • Oversee internal resources, project-based support, or cross-functional contributors in connection with audit preparation, SOC reporting, PCI compliance adherence, and compliance execution.

Governance, Risk, and Documentation Management

  • Coordination across other risk management stakeholder functions (e.g. Legal, Finance, Internal Audit, Corporate IT, BU level IT organizations) to accomplish the following:

    • Support and evolve existing IT Risk Management Program to ensure controls address Technology, Cybersecurity, Data, Resiliency/Recovery, and Emerging (AI, etc.) risks.

    • Establish IT compliance requirements

    • Identify and eliminate redundant risk management processes and/or controls

    • Understand and support the risk management objectives of other risk management functions

  • Maintain current inventories of in-scope systems and applications that are required to support key regulatory requirements (e.g., ICFR), in-flight IT projects, and relevant stakeholders

  • Develop the framework and standards for core IT compliance documentation and templates, including Risk and Control Matrices, process flows, system interface documentation, and remediation plans

  • Determine the review criteria and cadence for assessing documentation prepared by system leads and control owners for quality, completeness, and alignment with compliance requirements

  • Establish policies, procedures, and governance practices that support effective and sustainable compliance execution

SOX, IT General Controls, and Audit Support

  • Act as primary point of contact for IT compliance supporting internal and external audits, including SOX and IT General Controls testing

  • Organize, collect, and maintain evidence required for audit requests and management review

  • Liaise with internal stakeholders and auditors to ensure timely and accurate delivery of required materials

  • Create repeatable processes for the identification, tracking, and remediation of control gaps, deficiencies, and related action plans

  • Create and support an IT risk assessments, control reviews, and compliance evaluations process

SOC Reporting and Third-Party Assurance

  • Manage the lifecycle of Service Organization Control reporting

  • Ensure completion of management evaluation documentation related to third-party controls and reliance

  • Support assessment of third-party compliance risk in areas such as access management, vendor management, and change management

Technical Data Reconciliation and Compliance Operations

  • Partner with IT and Finance colleagues to monitor adherence with internal policies and key metrics regarding control environment activities (e.g. reconciliation activities, data analysis, data hygiene, etc.)

  • As part of the user termination process, work closely with the infrastructure and application system owners to ensure terminations are completed timely and if any are missed (outside the acceptable window), a full look back analysis is conducted and send confirmation materials to internal audit.

  • Establish continuous monitoring processes.

Monitoring, Reporting, and Training

  • Monitor changes in relevant compliance, privacy, and security requirements and support translation of those requirements into practical business processes

  • Prepare reporting for management regarding compliance status, risks, remediation efforts, and control effectiveness

  • Collaborate with Internal Audit, financial controls and IT in the development of training materials related to IT compliance, data privacy, and security practices

  • Support awareness efforts for IT teams and business stakeholders to promote a culture of accountability and compliance

Supervisory Responsibilities

This role may oversee internal resources, project-based support, or cross-functional contributors in connection with audit preparation, SOC reporting, PCI compliance adherence, and compliance execution.

Required Qualifications

  • Bachelor's degree in Computer Science, Information Systems, Information Security, Accounting, Finance, or a related field

  • 10+ years of significant progressive experience in IT compliance, IT audit, risk management, cybersecurity compliance, or a related governance function

  • Demonstrated experience supporting SOX and IT General Controls in a complex environment

  • Experience developing and enhancing Risk and Control Matrices, process flows, remediation plans, system inventories, and related compliance documentation

  • Strong cross-functional partnership experience with Legal, IT, Security, Internal Audit, Finance, and business stakeholders

Preferred Qualifications

  • Experience supporting compliance activities in connection with mergers and acquisitions

  • Experience managing third-party assurance processes, including SOC report review and evaluation

  • Familiarity with enterprise control frameworks such as NIST and ISO 27001

  • Experience in a public company or similarly regulated environment

  • Knowledge of SAP (S/4) a plus as this is our Enterprise Finance and Accounting ERP

Knowledge, Skills, and Abilities

  • Strong knowledge of SOX, ITGC, and general compliance frameworks

  • Advanced proficiency in Excel with a strong working knowledge of PowerQuery, SQL, or similar tools preferred

  • Understanding of access management, vendor management, change management, and audit evidence requirements

  • Strong analytical and problem-solving skills with exceptional attention to detail

  • Excellent written and verbal communication skills, including the ability to communicate technical concepts to non-technical stakeholders

  • Strong organizational, project management, and documentation skills

  • High degree of integrity, discretion, and professional judgment

  • Ability to balance strategic priorities with hands-on execution

Certifications

Preferred certifications include:

  • Certified Information Systems Auditor (CISA)

  • Certified Information Systems Security Professional (CISSP)

  • Certified in Risk and Information Systems Control (CRISC)

Per local requirements and in the interest of transparency, the hourly rate shown below reflects the prevalent current hiring range for this position. Hiring pay rates are based on a number of factors, including location and may vary depending on job-related qualifications, knowledge, skills and experience. The company strives to provide locally competitive rewards packages, which include base rate along with, as applicable, short- and long-term incentives, growth and developmental opportunities, and robust benefits, such as health care, retirement, vacation and other paid time off, and additional offerings.

Hiring Rate Minimum:

$157,500 annually(minimum will not fall below the applicable State/local minimum salary thresholds)

Hiring Rate Maximum:

$210,000 annually

TKO is an Equal Opportunity Employer and complies with all applicable federal, state, and local laws regarding non-discrimination in employment. TKO makes employment decisions based on merit and qualifications, without considering an employee's or applicant's race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, marital status, veteran status, or any other basis prohibited under federal, state or local laws governing non-discrimination in employment in every location in which the Company has facilities. TKO also provides reasonable accommodations for qualified individuals with disabilities in accordance with the Americans with Disabilities Act (ADA) and applicable state or local laws. For information about Privacy and Information Security for TKO employment candidates, please review our Privacy Policy. For information regarding Terms of Use for this and other TKO websites, please review our Terms of Use.