1

It Governance Risk Jobs (NOW HIRING)

$41.75 - $55.75/hr

The IT Governance/Risk/Compliance Analyst position offers a dynamic opportunity for an experienced analyst to help shape the future of our governance, risk, and compliance initiatives. In this role ...

AVP, IT & AI Governance

New York, NY · On-site

$171K - $215K/yr

The AVP will oversee IT governance, AI governance, model risk alignment, technology risk management, and regulatory compliance across the organization. This role serves as a key control function ...

IT Security and Governance Analyst

Louisville, KY · On-site

$43.25 - $57.50/hr

Brown-Forman is a premium spirits company that offers a dynamic opportunity for an experienced IT Governance/Risk/Compliance Analyst. In this role, you will identify and mitigate IT risks, ensure ...

next page

Showing results 1-20

It Governance Risk information

What is IT governance risk?

IT Governance Risk refers to the potential threats and vulnerabilities that can affect an organization's information technology systems, processes, and data. It involves identifying, assessing, and managing risks related to IT operations, compliance, security, and strategic alignment with business objectives. Effective IT governance risk management helps organizations ensure regulatory compliance, protect sensitive information, and support business continuity. Professionals in this field develop policies, procedures, and controls to mitigate risks and enable informed decision-making.

How does an IT governance risk professional typically collaborate with other departments within an organization?

IT Governance Risk professionals frequently work cross-functionally, partnering with departments such as IT, legal, compliance, and business units to ensure that risk management practices align with organizational objectives and regulatory requirements. This collaboration often involves facilitating risk assessments, developing and implementing policies, and providing guidance on risk mitigation strategies. Clear communication and strong relationship-building skills are key, as the role requires translating technical risks into business impacts and gaining buy-in from stakeholders across the company.

What are the key skills and qualifications needed to thrive as an IT governance, risk, and compliance (GRC) professional, and why are they important?

To thrive as an IT GRC professional, you need a solid understanding of information security principles, risk management frameworks, and relevant regulatory standards, often supported by a degree in IT or cybersecurity and certifications like CISA or CISSP. Familiarity with GRC tools such as RSA Archer, ServiceNow GRC, and risk assessment methodologies is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you interpret complex regulations and collaborate with stakeholders. These competencies ensure effective risk mitigation, regulatory compliance, and alignment between IT and business objectives.

What is the difference between It Governance Risk vs It Security Analyst?

AspectIt Governance RiskIt Security Analyst
CertificationsCISA, CRISCCISSP, Security+
Work EnvironmentPolicy development, risk assessment, complianceMonitoring security systems, incident response
Industry UsageGovernance, risk management, compliance teamsSecurity operations teams, IT departments

It Governance Risk focuses on establishing policies, managing IT risks, and ensuring compliance across the organization. In contrast, an It Security Analyst primarily monitors security systems, investigates incidents, and implements security measures. While both roles require understanding of IT frameworks and certifications like CISA or CISSP, their core responsibilities differ: governance versus security operations.

Is IT governance risk and compliance a good career?

IT Governance Risk and Compliance is a growing field that involves managing an organization’s IT policies, security, and regulatory requirements. It requires knowledge of frameworks like ISO 27001 or COBIT and often benefits from certifications such as CISA or CISSP. The role offers opportunities in various industries with a focus on risk management, security, and compliance strategies.

What are the roles of IT governance risk?

IT governance risk involves identifying, assessing, and managing risks related to information technology to ensure alignment with organizational goals and compliance requirements. IT governance risk professionals develop policies, implement controls, and monitor systems to mitigate threats such as data breaches, cyberattacks, and operational failures, often using frameworks like COBIT or ISO 27001. Strong risk management helps organizations maintain security, improve decision-making, and ensure regulatory compliance.
More about It Governance Risk jobs

What cities are hiring for It Governance Risk jobs?

Cities with the most It Governance Risk job openings:

Infographic showing various It Governance Risk job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 89% Full Time, 8% Part Time, and 2% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution.

Manager, IT Governance, Risk and Compliance

TKO Group Holdings, Inc.

New York, NY • On-site

Full-time

Medical, Retirement, PTO

Posted 12 days ago


Job description

Who We Are:
TKO Group Holdings, Inc. (NYSE: TKO) is a premium sports and entertainment company. TKO owns iconic properties including UFC, the world's premier mixed martial arts organization; WWE, the global leader in sports entertainment; and PBR, the world's premier bull riding organization. Together, these properties reach 1 billion households across 210 countries and territories and organize more than 500 live events year-round, attracting more than three million fans. TKO also services and partners with major sports rights holders through IMG, an industry-leading global sports marketing agency; and On Location, a global leader in premium experiential hospitality.
Job Summary
The IT Governance, Risk and Compliance Manager is responsible for executing the day-to-day responsibilities for TKO's IT compliance program which include supporting SOX and IT General Controls, audit readiness, governance documentation, and technical data reconciliation activities. Reporting to TKO's Senior Director of IT Governance, Risk and Compliance, this role will partner closely with Legal, IT, Security, Internal Audit, Finance, and business stakeholders to support TKO's control environment, enterprise compliance obligations, and risk management initiatives.
This role requires both subject matter expertise and hands-on execution of compliance projects and operational tasks. The successful candidate will bring deep experience in IT compliance and controls with the ability to operate autonomously while supporting multiple business units and stakeholders within a complex environment.
Essential Duties and Responsibilities
IT Compliance Execution
  • Support the Senior Director of IT Governance, Risk and Compliance in building the overall compliance strategy and roadmap
  • Implementation and day-to-day support of an enterprise Governance, Risk and Compliance platform to include automation of risk and control matrices, evidence collection workflows, and executive reporting & dashboards.
  • Assist in tracking and delivery of key compliance initiatives including executive status updates regarding the program's status and health
  • Provide front line support and subject matter expertise to system leads and business partners on compliance processes such as proper control execution, industry standard documentation, and change management best practices

Governance, Risk, and Documentation Management
  • Assist in establishing, documenting, and maintaining IT compliance requirements
  • Lead process re-design efforts to identify and eliminate redundant risk management processes and/or controls
  • Understand and support the risk management objectives of other TKO risk management functions
  • Maintain current inventories of in-scope systems and applications that are required to support key regulatory requirements (e.g., ICFR), in-flight IT projects, and relevant stakeholders
  • Maintain IT compliance documentation and templates, including Risk and Control Matrices, process flows, system interface documentation, and remediation plans
  • Assist in the review and assessment of documentation prepared by system leads and control owners for quality, completeness, and alignment with compliance requirements

SOX, IT General Controls, and Audit Support
  • Provide support for internal and external audits, including SOX and IT General Controls testing
  • Support the IT Compliance leader with collecting and maintaining evidence required for audit requests and management reviews, ensuring timely and accurate delivery of required materials
  • Support identification, tracking, and remediation of control gaps, deficiencies, and related action plans
  • Support risk assessments, control reviews, and compliance evaluations processes

Technical Data Reconciliation and Compliance Operations
  • Monitor adherence with internal policies and key metrics regarding control environment activities (e.g. reconciliation activities, data analysis, data hygiene, etc.)
  • Track application system owner's adherence to the access termination process including conducting a look back analysis for terminations that do not meet the termination policy.
  • Execute established continuous monitoring processes.

Monitoring, Reporting, and Training
  • Prepare reporting for management regarding compliance status, risks, remediation efforts, and control effectiveness
  • Document, maintain and socialize training materials related to IT compliance, data privacy, and security practices
  • Support awareness efforts for IT teams and business stakeholders to promote a culture of accountability and compliance

Required Qualifications
  • 5+ years experience in IT compliance, IT audit, risk management, cybersecurity compliance, or a related governance function
  • Hands on experience developing and maintaining Risk and Control Matrices, process flows, remediation plans, system inventories, and related compliance documentation
  • Demonstrated experience supporting cross-functional stakeholders such as Legal, IT, Security, Internal Audit, Finance, and business leads

Preferred Qualifications
  • Bachelor's degree in Computer Science, Information Systems, Information Security, Accounting, Finance, or a related field
  • Demonstrated experience supporting SOX and IT General Controls in a complex public company environment
  • Experience supporting compliance activities in connection with mergers and acquisitions
  • Experience managing third-party assurance processes, including SOC report review and evaluation
  • Familiarity with enterprise control frameworks such as NIST and ISO 27001
  • Knowledge of SAP (S/4) a plus as this is our Enterprise Finance and Accounting ERP

Knowledge, Skills, and Abilities
  • Strong knowledge of SOX, ITGC, and general compliance frameworks
  • Advanced proficiency in Excel with a strong working knowledge of PowerQuery, SQL, or similar tools preferred
  • Understanding of access management, vendor management, change management, and audit evidence requirements
  • Strong analytical and problem-solving skills with exceptional attention to detail
  • Excellent written and verbal communication skills, including the ability to communicate technical concepts to non-technical stakeholders

Certifications
Preferred certifications include:
  • Certified Information Systems Auditor (CISA)
  • Certified Information Systems Security Professional (CISSP)
  • Certified in Risk and Information Systems Control (CRISC)

Per local requirements and in the interest of transparency, the hourly rate shown below reflects the prevalent current hiring range for this position. Hiring pay rates are based on a number of factors, including location and may vary depending on job-related qualifications, knowledge, skills and experience. The company strives to provide locally competitive rewards packages, which include base rate along with, as applicable, short- and long-term incentives, growth and developmental opportunities, and robust benefits, such as health care, retirement, vacation and other paid time off, and additional offerings.
Hiring Rate Minimum:
$105,000 annually(minimum will not fall below the applicable State/local minimum salary thresholds)
Hiring Rate Maximum:
$140,000 annually
TKO is an Equal Opportunity Employer and complies with all applicable federal, state, and local laws regarding non-discrimination in employment. TKO makes employment decisions based on merit and qualifications, without considering an employee's or applicant's race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, marital status, veteran status, or any other basis prohibited under federal, state or local laws governing non-discrimination in employment in every location in which the Company has facilities. TKO also provides reasonable accommodations for qualified individuals with disabilities in accordance with the Americans with Disabilities Act (ADA) and applicable state or local laws. For information about Privacy and Information Security for TKO employment candidates, please review our Privacy Policy. For information regarding Terms of Use for this and other TKO websites, please review our Terms of Use.