1

It Risk And Assurance Manager Jobs in California

KPMG is currently seeking a Manager, IT Internal Audit to join our Audit and Assurance practice ... Work with client senior management to design, and implement new IT risk and control frameworks ...

Reporting to the Global IT SOX Risk Management Leader, you'll drive strategic SOX readiness projects and provide risk advisory expertise across many process areas to ensure compliance with SOX while ...

Reporting to the Global IT SOX Risk Management Leader, you'll drive strategic SOX readiness projects and provide risk advisory expertise across many process areas to ensure compliance with SOX while ...

About the Team The IT Risk & Controls function sits within the Finance Risk Management (FRM) team and plays a critical role in designing secure, compliant, and scalable systems that support our ...

... audits, IT SOX, SAP controls, and technology risk assurance across a complex global environment ... Collaborate with management and external auditors on IT SOX and SAP controls, including testing ...

Manager, Business Assurance

Irvine, CA · On-site

$101K - $113K/yr

Understanding of IT controls, systems risks, and data governance * Deep understanding of internal ... Risk assessment and mitigation strategies * Financial and operational auditing * Internal controls ...

SRCO is a management-led function purpose-built to deliver a modern, sustainable, and risk-focused ... We are seeking an IT SOX Lead Risk Advisor who thrives at the intersection of risk management ...

SRCO is a management-led function purpose-built to deliver a modern, sustainable, and risk-focused ... We are seeking an IT SOX Lead Risk Advisor who thrives at the intersection of risk management ...

SRCO is a management-led function purpose-built to deliver a modern, sustainable, and risk-focused ... We are seeking an IT SOX Lead Risk Advisor who thrives at the intersection of risk management ...

... assurance and advisory work that helps teams strengthen our overall control environment ... This Technology Risk Audit Manager role owns the technical side of that mission - IT SOX/ITGC ...

SRCO is a management-led function purpose-built to deliver a modern, sustainable, and risk-focused ... We are seeking an IT SOX Lead Risk Advisor who thrives at the intersection of risk management ...

Oversee IT risk assessment and scoping process to ensure alignment with financial reporting risks ... Adhere to the Company's Quality Management System (QMS) as well as domestic and global quality ...

SRCO is a management-led function purpose-built to deliver a modern, sustainable, and risk-focused ... We are seeking an IT SOX Lead Risk Advisor who thrives at the intersection of risk management ...

Specific Duties and Responsibilities • Responsible for strategic leadership, oversight, and day-to-day management of the IT SOX compliance program. * • Oversee IT risk assessment and scoping ...

Showing results 21-40

It Risk And Assurance Manager information

What is the difference between It Risk And Assurance Manager vs It Security Analyst?

AspectIt Risk And Assurance ManagerIt Security Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentOversees risk management, audits, compliance in organizationsMonitors security systems, investigates incidents, implements security measures
Employer & Industry UsageFinancial, healthcare, large enterprisesIT departments across various industries

The It Risk And Assurance Manager focuses on managing overall IT risks, compliance, and assurance processes, while the It Security Analyst concentrates on monitoring and securing IT systems daily. Both roles require security certifications but differ in scope and responsibilities within organizations.

Is IT risk and assurance management a good career?

IT risk and assurance management is a growing field that involves identifying and mitigating technology-related risks to ensure organizational security and compliance. It often requires certifications like CISA or CISSP and skills in cybersecurity, audit, and risk assessment. The role offers opportunities for advancement and is in demand across various industries.

What does an IT Risk And Assurance Manager do?

An IT Risk and Assurance Manager oversees the identification, assessment, and mitigation of information technology risks to ensure the security, compliance, and integrity of IT systems. They develop and implement control frameworks, conduct audits, and work with teams to address vulnerabilities, often utilizing standards like ISO 27001 or frameworks such as COBIT. Strong analytical skills, knowledge of cybersecurity, and relevant certifications like CISA or CISSP are typically required for this role.

What are popular job titles related to It Risk And Assurance Manager jobs in California?

For It Risk And Assurance Manager jobs in California, the most frequently searched job titles are:

What job categories do people searching It Risk And Assurance Manager jobs in California look for?

The top searched job categories for It Risk And Assurance Manager jobs in California are:

Infographic showing various It Risk And Assurance Manager job openings in California as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 13% Part Time, 2% Temporary, and 1% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution.

IT Risk & Compliance Analyst

Superbeo

San Francisco, CA • On-site

Contractor

Re-posted 7 days ago


Job description

Job Title: IT Risk & Compliance Analyst

Job Location: San Francisco, CA 94104

  • Please local candidates that are able to work hybrid work schedule, Tuesday and Wednesday, at the SF Offices.

Job Duration: 6 months (Possibility of extension)

Qualifications (Must Have):

  • Ability to map key Information Security and Technology controls identified in policies, standards, and process documents to industry frameworks such as NIST CSF, NIST 800-53, CSA CCM, CIS v8.1, and regulatory requirements in FHFA Advisory Bulletins.
  • Interpret compliance information to create a recurring cadence of reports of open findings, observations, self-identified issues, progress on risk and compliance initiatives.
  • Willingness to learn/use ITRC tools (e.g., ProcessUnity, Black Kite) and support ITRC team lead with supply chain cyber risk program management

Primary Responsibilities:

  • Conduct readiness assessments, including reviews of relevant documentation in advance of audits, 2LOD assessments, and external assessments.
  • Maintain the inventory of SOX IT General Controls (ITGC) and control tests in ServiceNow, updating as directed, and identifying opportunities for improvements in reporting and in using automation.
  • Liaison between control owner and internal auditors, and 2LOD assessors during audits and assessments, responsible for supporting control owners in the timely submission of artifacts.
  • Ability to map key Information Security and Technology controls identified in policies, standards, and process documents to industry frameworks such as NIST CSF, NIST 800-53, CSA CCM, CIS v8.1, and regulatory requirements in FHFA Advisory Bulletins.
  • Ability to identify and document technology processes.
  • Manage the LogicGate Governance Library ensuring Information Security and Technology documents align with approval and publication requirements, relying equally on automated reminders as well as active engagement with document owners.
  • Maintain ITRC document archives in the ITRC shared repository.
  • Responsible for reporting status at a recurring cadence of open findings, observations, recommendations, and self-identified issues, and for submitting formal audit observation closure documentation.
  • As directed by the ITRC MD, document and report the progress and value of in-flight ITRC initiatives, identified risks, and planned initiatives.
  • Provide compliance review of requests for deviations from Information Security and Technology policies and standards, confirming compliance with Technology Exception requirements for components such as compensating controls, risk assessment, and  documentation supporting exception request rationale.
  • Participate as a key stakeholder in the Architecture Assessment Review process, documenting meeting decisions,  tracking deliverable commitments, and ensuring next steps are completed for proposed new technologies or changes in existing technologies.
  • Support ITRC team members as needed in conducting third-party security risk assessments for changes to existing third parties or proposed third party technologies.

Skills/Knowledge:

  • Required Core Competencies:  Customer Focus, Decision Quality, Ensures Accountability, Drives Results, Drives Engagement, Collaborates, Values Differences, Communicates Effectively with all levels of staff and management, Instills Trust
  • 3 - 5 years of experience in technology risk or IT audit.
  • Knowledge and experience with technology frameworks is required, e.g., CIS v8.1, CSA CCM, CoBIT, NIST, ITIL, et al.
  • Knowledge of Operational Risk Management and Technology Risk Management.
  • Demonstrated ability to promote teamwork, act as a change agent, effectively remove obstacles, maintain high level of morale and motivation, and lead by example.
  • Familiarity with SOX ITGC
  • Must be proficient with Microsoft Office (Word, Excel, PowerPoint) and Microsoft SharePoint.
  • Must have strong communication skills and be able to effectively communicate with all functional levels of the organization.
  • Project management, planning, problem-solving and organizational skills required, preferably using Atlassian JIRA
  • Strong analytical, issue identification, prioritization, resolution, and report writing skills required.
  • Must be proactive and must be able to meet established deadlines.
  • Experience with a Governance, Risk and Compliance (GRC) tool is highly desirable, preferably ServiceNow and LogicGate.
  • Ability to learn use of the ProcessUnity/CyberGRX third party risk management platform