Program Manager Level III

Aviso de fuente externaen Allyis

Overview:We are seeking a Senior or Manager-level GRC professional to join our Digital Technology team in strengthening the design and operation of technology controls across the enterpri...

Fuente externa - sin verificarhace 2 semanasVigente hasta: 6 sep 2026

Salario

No especificado

Ubicación

San José, Costa Rica

Tipo de empleo

Tiempo completo

Modalidad

No especificado

Program Manager Level III

San José, Costa Rica

Descripción del empleo

Overview:We are seeking a Senior or Manager-level GRC professional to join our Digital Technology team in strengthening the design and operation of technology controls across the enterprise. In this role, you'll plan and execute control testing across IT General Controls and IT Application Controls, evaluate control evidence against audit standards, and help drive remediation when gaps are identified. You'll also play a growing role in assessing risk for AI systems as the organization scales its use of AI internally and through third-party tools. This is a highly cross-functional role, requiring close partnership with Engineering, Information Security, Legal, and Internal Audit to keep our control environment current, defensible, and aligned to evolving regulatory expectations.
What you will do in this role:Design, document, and recommend technology controls mapped to applicable frameworks including NIST AI Risk Management Framework, NIST SP 800-53, ISO 27001, and SOX IT General Controls.Perform testing of relevant technology covering both design and operating effectiveness across NIST AI RMF controls, IT General controls (Logical Access, Change Management, IT Operations) and IT Application Controls.Develop control test plans that are repeatable, auditor-defensible, and appropriately scoped to the control objective.Collect, organize, and critically evaluate control evidence; assess completeness, accuracy, and relevance.Document test procedures, sampling rationale, results, and conclusions in accordance with internal methodology and external audit standards.Support AI risk assessments for internal AI systems and third-party AI tools, evaluating risk across multiple risk domains.Analyze current and emerging regulatory and internal policy requirements to identify internal control gaps and develop recommendations to address.Issue Management: Evaluate identified issues, determine root causes, and recommend remediation solutions. Track commitments across technology teams, identify milestone slippage early, and escalate as appropriate.
Hiring Manager Notes:
From the JD, what are the top "must have non-negotiable" skill sets that need to be present on a resume to be successful for this role?This individual must have IT risk and controls or IT Audit experience.Must be proficient in IT general controls (Logical Access, Change Management, IT Operations.Someone that was worked in the Big 4 audit firms in IT Audit will typically have this experience.We are looking for 2 positions and open to a senior or manager levelWhat backgrounds/skills can we be more flexible with that can be learned on the job?Having AI Risk/Governance experience is flexible and can be learned on the jobDoes this position require to come into the office?No. Position is remote at Costa RicaWhat will the interview process look like?We should be able to decide with two interviews. Myself and another Sr.Manager on the teamWhat is the schedule for the role (i.e. - 9am-5pm)?Schedule is 9am-5pm Central US time
What you need to be successful in this role:Undergraduate degree in information technology, management information systems, or a related field5+ years of experience in IT risk management, information security compliance, or internal IT audit in large enterprise environments.Able to communicate complex control findings clearly to both technical teams and non-technical stakeholders, including senior leadership.Comfortable working both independently or in teams and working within a complex environment.Excellent analytical, technical and problem-solving skills, with strong attention to detailStrong understanding of IT General Computer Controls (ITGCs), system development lifecycle, and IT auditing techniques; including broad knowledge of IT technologies, operating systems, databases, and application platforms.
Nice to HaveKnowledge of SOX, NIST SP 800-53, NIST AI Risk Management Framework (AI RMF), ISO 42001, or EU AI Act is a plus.Professional accreditation (e.g., CISA, CISM) is a plus.Familiarity with ServiceNow Integrated Risk Management (IRM) platform is a plus

¿Es tuya esta vacante?

Reclámala gratis y recibe candidatos con video en CazVid.

Empleos similares