Senior Manager IT Governance Risk and Compliance GRC- Remote

Aviso de fuente externaen Galactic Minds INC

Senior Manager, IT Governance, Risk, and Compliance (GRC)Costa Rica - Remote OverviewWe are seeking a Senior or Manager-level GRC professional to join our Digital Technology team in stren...

Fuente externa - sin verificarhace 2 semanasVigente hasta: 6 sep 2026

Salario

No especificado

Ubicación

Costa Rica

Tipo de empleo

Tiempo completo

Modalidad

Remoto

Senior Manager IT Governance Risk and Compliance GRC- Remote

Costa Rica

Descripción del empleo

Senior Manager, IT Governance, Risk, and Compliance (GRC)Costa Rica - Remote
OverviewWe are seeking a Senior or Manager-level GRC professional to join our Digital Technology team in strengthening the design and operation of technology controls across the enterprise.In this role, you will plan and execute control testing across IT General Controls (ITGCs) and IT Application Controls (ITACs), evaluate control evidence against audit standards, and help drive remediation when gaps are identified.You will also play a growing role in assessing risk for Artificial Intelligence (AI) systems as the organization scales its use of AI internally and through third-party tools.This is a highly cross-functional role, requiring close partnership with Engineering, Information Security, Legal, and Internal Audit to keep our control environment current, defensible, and aligned to evolving regulatory expectations.Key ResponsibilitiesControl Design & Recommendation: Design, document, and recommend technology controls mapped to applicable frameworks including NIST AI Risk Management Framework, NIST SP 800-53, ISO 27001, and SOX IT General Controls.Control Testing: Perform testing of relevant technology covering both design and operating effectiveness across NIST AI RMF controls, IT General Controls (Logical Access, Change Management, IT Operations), and IT Application Controls.Test Planning: Develop control test plans that are repeatable, auditor-defensible, and appropriately scoped to the control objective.Evidence Evaluation: Collect, organize, and critically evaluate control evidence; assess completeness, accuracy, and relevance.Documentation: Document test procedures, sampling rationale, results, and conclusions in accordance with internal methodology and external audit standards.AI Risk Assessment: Support AI risk assessments for internal AI systems and third-party AI tools, evaluating risk across multiple risk domains.Gap Analysis: Analyze current and emerging regulatory and internal policy requirements to identify internal control gaps and develop recommendations to address them.Issue Management: Evaluate identified issues, determine root causes, and recommend remediation solutions. Track commitments across technology teams, identify milestone slippage early, and escalate as appropriate.Required Qualifications (Must-Haves)Education: Undergraduate degree in Information Technology, Management Information Systems, or a related field.Experience: 5+ years of experience in IT risk management, information security compliance, or internal IT audit in large enterprise environments.IT Audit/Risk Expertise: Proven experience in IT risk and controls or IT Audit.ITGC Proficiency: Deep proficiency in IT General Controls (ITGCs), specifically Logical Access, Change Management, and IT Operations.Technical Knowledge: Strong understanding of system development lifecycle, IT auditing techniques, and broad knowledge of IT technologies, operating systems, databases, and application platforms.Communication Skills: Ability to communicate complex control findings clearly to both technical teams and non-technical stakeholders, including senior leadership.Analytical Skills: Excellent analytical, technical, and problem-solving skills, with strong attention to detail.Work Style: Comfortable working both independently and collaboratively within teams in a complex environment.Preferred Background: Candidates with IT Audit experience from Big 4 audit firms will be highly considered.Preferred Qualifications (Nice-to-Haves)AI Risk & Governance: Experience with AI Risk or AI Governance is a plus, though not strictly required (this can be learned on the job).

¿Es tuya esta vacante?

Reclámala gratis y recibe candidatos con video en CazVid.

Empleos similares