{"schemaVersion":"jobsearcher.job.v1","id":"f6c94c2a31c1979a0b8e99eb","url":"https://jobsearcher.com/jobs/f6c94c2a31c1979a0b8e99eb","canonicalUrl":"https://jobsearcher.com/jobs/f6c94c2a31c1979a0b8e99eb","title":"IT Risks & Control Manager","description":"About Nebius:\nNebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.\nBuilt by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.\nListed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D. The role\nNebius is seeking a IT Risk & Controls Manager to act as an embedded risk partner to our engineering and technology organizations. \nYou will help scale and strengthen a modern IT SOX and controls framework across Nebius’s custom-built AI cloud platform, infrastructure, corporate technology environment and other systems supporting financial reporting. \nThis role goes beyond traditional IT audit testing. You will work directly with engineering leaders, system owners, Finance, Internal Controls and external auditors to identify risk, design scalable controls, improve evidence quality, drive remediation and embed compliance into the way our technology organizations operate. \nThe successful candidate will combine deep IT risk and controls expertise with meaningful in-house technology experience. You must be equally comfortable discussing technical control design with engineers, explaining risk implications to business leaders and aligning audit expectations with external assurance providers. \nYour responsibilities will include: \n\nAct as the risk and controls partner for an assigned technology organization or system portfolio, developing a detailed understanding of its architecture, operations, risks and financial-reporting dependencies.  \nOwn and continuously improve the relevant IT risk and control framework, including system scoping, risk assessment, RCM and control-catalogue maintenance, documentation and control ownership.  \nLead IT SOX readiness for assigned systems, including walkthrough preparation, evidence-quality review, testing coordination, issue evaluation and remediation oversight.  \nPartner with engineering, platform, infrastructure, security and corporate IT teams to design and implement scalable controls that address risk while supporting operational efficiency.  \nDesign, assess and enhance ITGCs across areas such as user access, privileged access, segregation of duties, change management, SDLC, system operations, incident management and third-party services.  \nAssess IT application controls, automated controls and IT-dependent business controls, including the completeness and accuracy of system-generated information used in business-process controls.  \nEvaluate how business controls depend on systems, integrations, configurations, reports and underlying ITGCs, and work with both business and IT control owners to resolve gaps.  \nApply risk and controls thinking to modern engineering practices, including cloud infrastructure, DevOps, CI/CD, repositories, deployment processes, containerized environments and audit logging.  \nLead the assessment and remediation of control gaps arising from new systems, major technology transformations, platform changes, integrations and acquisitions.  \nReview third-party assurance reports and determine the impact of vendor controls and complementary user-entity controls on the Nebius control environment.  \nMaintain effective working relationships with external auditors and advisers, aligning on audit scope, evidence expectations, testing approaches, reliance opportunities, timelines and issue resolution.  \nTranslate complex technical risks and auditor requirements into practical guidance for engineering and system owners.  \nUse data analytics, automation, continuous monitoring and AI-assisted tools to improve control coverage, evidence quality and the efficiency of the IT SOX program.  \nContribute to the development of IT controls methodology, standards, tooling, training, reporting and the broader Risk Partner operating model.  \nProvide clear, concise updates on control health, audit readiness, deficiencies and remediation progress to senior technology and Finance stakeholders. \n\nWe expect you to have: \n\nA degree in Information Systems, Computer Science, Engineering, Accounting, Finance or a related discipline, or equivalent professional experience.  \nAt least eight years of progressive experience in IT risk, IT controls, IT SOX, technology assurance, IT audit or a closely related area.  \nMeaningful in-house technology or corporate ownership experience is required. Big Four or consulting experience is valuable when combined with subsequent in-house responsibility, but an exclusively advisory or external-audit background will not be sufficient.  \nExperience working in a first-line technology, engineering, systems or IT operations role, or as an embedded in-house risk partner supporting a technology organization.  \nHands-on experience in an engineering-led technology, cloud, SaaS, platform or digital-product environment.  \nStrong practical knowledge of SOX 404, ITGCs, IT application controls, automated controls, COSO and COBIT.  \nDemonstrated experience with control design, implementation, monitoring, evidence review, audit readiness, issue evaluation and remediation.  \nPractical understanding of modern technology environments, including cloud infrastructure, IAM, DevOps, CI/CD, SDLC, software repositories, deployment practices, system integrations and container orchestration such as Kubernetes.  \nExperience connecting business-process controls to supporting systems, automated controls, IPEs/IUCs and underlying IT dependencies.  \nThe ability to communicate effectively with engineers, technical leaders, Finance stakeholders and external auditors.  \nStrong judgment and the confidence to challenge control owners while developing practical, scalable solutions.  \nA highly autonomous and hands-on approach, with the ability to operate effectively in an evolving environment with incomplete processes and competing priorities.  \nStrong written and verbal English.  \nThe ability to work effectively across international time zones and travel when needed to build relationships with key technology and audit stakeholders.  \n\nIt will be an added bonus if you have: \n\nA professional certification such as CISA, CRISC, CISM, CIA, CPA or an equivalent qualification.  \nExperience building or materially transforming an IT SOX or technology-controls framework in a listed or pre-IPO technology company.  \nExperience in AI infrastructure, cloud platforms, large-scale SaaS, fintech, marketplaces or another engineering-intensive environment.  \nExperience with GRC and audit-management tools such as Workiva, Jira, ServiceNow GRC or similar platforms.  \nExperience with enterprise SaaS and financial systems such as NetSuite, HR platforms, billing systems, procurement tools or treasury systems.  \nExperience onboarding acquired companies or newly implemented systems into SOX scope.  \nExperience with control automation, continuous monitoring, data analytics or AI-assisted assurance.  \nExposure to AI governance, AI/ML control environments or controls supporting AI-enabled development and operations. \n Pay Transparency\nWe offer competitive compensation and benefits packages. Actual compensation will be determined based on job-related factors, including experience, skills, qualifications, the level at which the candidate is hired, and geographic location, consistent with applicable law. Base Compensation Range $120,000—$180,000 USD Benefits & Perks:\n\nCompetitive compensation\nCareer growth and learning opportunities\nFlexibility and ownership\nCollaborative and innovative culture\nOpportunity to work on impactful AI projects\nInternational environment and talented teams\n\nWhat's it like to work at Nebius:\nFast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI \nEqual Opportunity Statement:\nNebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.\nApplicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire. \nIf you need accommodations during the application process, please let us know.","company":"Nebius","rawCompany":"nebius","city":"Denver","state":"CO","isRemote":false,"isActive":false,"createdAt":"2026-09-02T04:15:32.270Z","occupations":[{"code":"11-3021.00","title":"Computer and Information Systems Managers","slug":"computer-and-information-systems-managers"},{"code":"11-9199.02","title":"Compliance Managers","slug":"compliance-managers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"IT Risks & Control Manager","description":"About Nebius:\nNebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.\nBuilt by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.\nListed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D. The role\nNebius is seeking a IT Risk & Controls Manager to act as an embedded risk partner to our engineering and technology organizations. \nYou will help scale and strengthen a modern IT SOX and controls framework across Nebius’s custom-built AI cloud platform, infrastructure, corporate technology environment and other systems supporting financial reporting. \nThis role goes beyond traditional IT audit testing. You will work directly with engineering leaders, system owners, Finance, Internal Controls and external auditors to identify risk, design scalable controls, improve evidence quality, drive remediation and embed compliance into the way our technology organizations operate. \nThe successful candidate will combine deep IT risk and controls expertise with meaningful in-house technology experience. You must be equally comfortable discussing technical control design with engineers, explaining risk implications to business leaders and aligning audit expectations with external assurance providers. \nYour responsibilities will include: \n\nAct as the risk and controls partner for an assigned technology organization or system portfolio, developing a detailed understanding of its architecture, operations, risks and financial-reporting dependencies.  \nOwn and continuously improve the relevant IT risk and control framework, including system scoping, risk assessment, RCM and control-catalogue maintenance, documentation and control ownership.  \nLead IT SOX readiness for assigned systems, including walkthrough preparation, evidence-quality review, testing coordination, issue evaluation and remediation oversight.  \nPartner with engineering, platform, infrastructure, security and corporate IT teams to design and implement scalable controls that address risk while supporting operational efficiency.  \nDesign, assess and enhance ITGCs across areas such as user access, privileged access, segregation of duties, change management, SDLC, system operations, incident management and third-party services.  \nAssess IT application controls, automated controls and IT-dependent business controls, including the completeness and accuracy of system-generated information used in business-process controls.  \nEvaluate how business controls depend on systems, integrations, configurations, reports and underlying ITGCs, and work with both business and IT control owners to resolve gaps.  \nApply risk and controls thinking to modern engineering practices, including cloud infrastructure, DevOps, CI/CD, repositories, deployment processes, containerized environments and audit logging.  \nLead the assessment and remediation of control gaps arising from new systems, major technology transformations, platform changes, integrations and acquisitions.  \nReview third-party assurance reports and determine the impact of vendor controls and complementary user-entity controls on the Nebius control environment.  \nMaintain effective working relationships with external auditors and advisers, aligning on audit scope, evidence expectations, testing approaches, reliance opportunities, timelines and issue resolution.  \nTranslate complex technical risks and auditor requirements into practical guidance for engineering and system owners.  \nUse data analytics, automation, continuous monitoring and AI-assisted tools to improve control coverage, evidence quality and the efficiency of the IT SOX program.  \nContribute to the development of IT controls methodology, standards, tooling, training, reporting and the broader Risk Partner operating model.  \nProvide clear, concise updates on control health, audit readiness, deficiencies and remediation progress to senior technology and Finance stakeholders. \n\nWe expect you to have: \n\nA degree in Information Systems, Computer Science, Engineering, Accounting, Finance or a related discipline, or equivalent professional experience.  \nAt least eight years of progressive experience in IT risk, IT controls, IT SOX, technology assurance, IT audit or a closely related area.  \nMeaningful in-house technology or corporate ownership experience is required. Big Four or consulting experience is valuable when combined with subsequent in-house responsibility, but an exclusively advisory or external-audit background will not be sufficient.  \nExperience working in a first-line technology, engineering, systems or IT operations role, or as an embedded in-house risk partner supporting a technology organization.  \nHands-on experience in an engineering-led technology, cloud, SaaS, platform or digital-product environment.  \nStrong practical knowledge of SOX 404, ITGCs, IT application controls, automated controls, COSO and COBIT.  \nDemonstrated experience with control design, implementation, monitoring, evidence review, audit readiness, issue evaluation and remediation.  \nPractical understanding of modern technology environments, including cloud infrastructure, IAM, DevOps, CI/CD, SDLC, software repositories, deployment practices, system integrations and container orchestration such as Kubernetes.  \nExperience connecting business-process controls to supporting systems, automated controls, IPEs/IUCs and underlying IT dependencies.  \nThe ability to communicate effectively with engineers, technical leaders, Finance stakeholders and external auditors.  \nStrong judgment and the confidence to challenge control owners while developing practical, scalable solutions.  \nA highly autonomous and hands-on approach, with the ability to operate effectively in an evolving environment with incomplete processes and competing priorities.  \nStrong written and verbal English.  \nThe ability to work effectively across international time zones and travel when needed to build relationships with key technology and audit stakeholders.  \n\nIt will be an added bonus if you have: \n\nA professional certification such as CISA, CRISC, CISM, CIA, CPA or an equivalent qualification.  \nExperience building or materially transforming an IT SOX or technology-controls framework in a listed or pre-IPO technology company.  \nExperience in AI infrastructure, cloud platforms, large-scale SaaS, fintech, marketplaces or another engineering-intensive environment.  \nExperience with GRC and audit-management tools such as Workiva, Jira, ServiceNow GRC or similar platforms.  \nExperience with enterprise SaaS and financial systems such as NetSuite, HR platforms, billing systems, procurement tools or treasury systems.  \nExperience onboarding acquired companies or newly implemented systems into SOX scope.  \nExperience with control automation, continuous monitoring, data analytics or AI-assisted assurance.  \nExposure to AI governance, AI/ML control environments or controls supporting AI-enabled development and operations. \n Pay Transparency\nWe offer competitive compensation and benefits packages. Actual compensation will be determined based on job-related factors, including experience, skills, qualifications, the level at which the candidate is hired, and geographic location, consistent with applicable law. Base Compensation Range $120,000—$180,000 USD Benefits & Perks:\n\nCompetitive compensation\nCareer growth and learning opportunities\nFlexibility and ownership\nCollaborative and innovative culture\nOpportunity to work on impactful AI projects\nInternational environment and talented teams\n\nWhat's it like to work at Nebius:\nFast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI \nEqual Opportunity Statement:\nNebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.\nApplicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire. \nIf you need accommodations during the application process, please let us know.","datePosted":"2026-09-02T04:15:32.270Z","dateModified":"2026-09-02T04:15:32.270Z","hiringOrganization":{"@type":"Organization","name":"Nebius","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Denver","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"f6c94c2a31c1979a0b8e99eb"},"url":"https://jobsearcher.com/jobs/f6c94c2a31c1979a0b8e99eb"}}