Position Summary
The IT Controls & Compliance Manager is responsible for overseeing the execution, monitoring, and continuous improvement of IT governance, risk, and compliance programs across multiple manufacturing facilities and business units. This role ensures that IT processes and controls support public company obligations, regulatory requirements, cybersecurity standards, and internal policies.
The position partners closely with Information Technology, Finance, Internal Audit, Operations, Information Security, and external auditors to maintain an effective control environment. The Manager serves as a day-to-day owner of IT control execution, compliance monitoring, audit coordination, change governance, and process improvement activities.
Key Responsibilities
Controls Administration & Governance
- Maintain and enhance the IT controls framework supporting organizational compliance requirements.
- Document, review, and update IT policies, standards, procedures, and control documentation.
- Monitor effectiveness of IT General Controls and key technology-related business controls.
- Coordinate periodic control testing and remediation activities.
- Track and report control deficiencies, corrective action plans, and control improvement opportunities.
Compliance Management
- Support compliance programs related to SOX, cybersecurity governance, data protection, and corporate policies.
- Ensure compliance activities are performed consistently across business units and manufacturing locations.
- Coordinate evidence collection and retention required for internal and external audits.
- Maintain compliance records, documentation repositories, and audit support materials.
Audit Coordination
- Serve as a primary IT liaison for internal and external audits.
- Coordinate audit requests, interviews, testing schedules, walkthroughs, and evidence collection.
- Track audit findings and ensure corrective actions are completed on schedule.
- Assist management with audit response preparation and remediation planning.
Change Control Management
- Administer enterprise change management processes and governance standards.
- Coordinate Change Advisory Board meetings and support change review processes.
- Review change records to ensure proper approvals, testing, documentation, and risk assessments are completed.
- Monitor change-related performance metrics, success rates, emergency changes, and compliance trends.
Asset & Configuration Governance
- Support governance of IT asset management and configuration management processes.
- Ensure hardware, software, endpoint, server, and infrastructure inventories remain accurate and compliant.
- Monitor software licensing compliance and asset lifecycle controls.
- Validate compliance with asset disposition, refresh, and inventory management procedures.
Risk Management
- Participate in periodic IT risk assessments across infrastructure, applications, manufacturing systems, and business processes.
- Identify control gaps, process weaknesses, and compliance risks.
- Develop and track remediation plans in partnership with business and technology teams.
- Assist with business continuity and disaster recovery governance activities.
Incident & Event Management Oversight
- Monitor compliance with incident and event management processes.
- Ensure root cause analysis and corrective actions are documented and completed.
- Track operational and compliance metrics related to major incidents and service disruptions.
- Identify process improvement opportunities based on incident trends and recurring issues.
Reporting & Continuous Improvement
- Develop compliance dashboards, KPI reporting, and management updates.
- Present compliance metrics, audit status, risk items, and remediation progress to IT leadership.
- Recommend process improvements to strengthen governance, operational maturity, and audit readiness.
- Support automation initiatives that improve control effectiveness, evidence management, and reporting.
Qualifications
Education
- Bachelor's degree in Information Systems, Computer Science, Accounting, Business Administration, Risk Management, or related field.
Experience
- 5-8 years of experience in IT controls, compliance, audit, governance, cybersecurity, or risk management.
- Experience supporting public company compliance requirements, including SOX-related IT controls.
- Experience working within manufacturing, multi-site operations, or distributed business environments.
- Experience with audit coordination, control testing, evidence collection, and remediation tracking.
- Previous supervisory, team leadership, or cross-functional program leadership experience preferred.
Preferred Certifications
- CISA
- CRISC
- CISSP
- CIA
- ITIL Foundation
- PMP preferred
Required Competencies
Technical | Leadership | Business |
IT General Controls | Cross-functional collaboration | Manufacturing operations awareness |
SOX Compliance | Process improvement | Financial controls understanding |
Change Management | Project management | Regulatory compliance |
Audit Management | Communication and presentation skills | Vendor governance |
Risk Assessments | Organizational effectiveness | Business process discipline |
Policy Governance | Follow-through and accountability | Operational risk awareness |
Asset Management | ||
Cybersecurity Controls |
Key Performance Indicators
- ITGC testing completion: 100%
- Audit findings closed on time: greater than 95%
- Change success rate: greater than 98%
- Emergency changes: less than 5%
- Asset inventory accuracy: greater than 99%
- Compliance training completion: 100%
- Evidence collection timeliness: 100%
- Policy review completion: 100%
Typical Reporting Structure
Reports to the Director, IT Site Services & Controls Compliance. This role may directly supervise or coordinate work performed by Controls Analysts, Compliance Analysts, Change Management Coordinators, Asset Governance Specialists, or other IT governance resources.
Key Stakeholders
- CIO and IT Leadership
- Finance and Accounting
- Internal Audit
- Manufacturing Site Leadership
- Information Security
- External Auditors
- Business Process Owners
- Technology Vendors and Service Providers
Learn more about this Employer on their Career Site
