About this role
The IT Controls & Compliance Manager is responsible for overseeing the execution, monitoring, and continuous improvement of IT governance, risk, and compliance programs across multiple manufacturing facilities and business units. This role ensures that IT processes and controls support public company obligations, regulatory requirements, cybersecurity standards, and internal policies.
The position partners closely with Information Technology, Finance, Internal Audit, Operations, Information Security, and external auditors to maintain an effective control environment. The Manager serves as a day-to-day owner of IT control execution, compliance monitoring, audit coordination, change governance, and process improvement activities.
Key ResponsibilitiesControls Administration & Governance
- Maintain and enhance the IT controls framework supporting organizational compliance requirements.
- Document, review, and update IT policies, standards, procedures, and control documentation.
- Monitor effectiveness of IT General Controls and key technology-related business controls.
- Coordinate periodic control testing and remediation activities.
- Track and report control deficiencies, corrective action plans, and control improvement opportunities.
Compliance Management
- Support compliance programs related to SOX, cybersecurity governance, data protection, and corporate policies.
- Ensure compliance activities are performed consistently across business units and manufacturing locations.
- Coordinate evidence collection and retention required for internal and external audits.
- Maintain compliance records, documentation repositories, and audit support materials.
Audit Coordination
- Serve as a primary IT liaison for internal and external audits.
- Coordinate audit requests, interviews, testing schedules, walkthroughs, and evidence collection.
- Track audit findings and ensure corrective actions are completed on schedule.
- Assist management with audit response preparation and remediation planning.
Change Control Management
- Administer enterprise change management processes and governance standards.
- Coordinate Change Advisory Board meetings and support change review processes.
- Review change records to ensure proper approvals, testing, documentation, and risk assessments are completed.
- Monitor change-related performance metrics, success rates, emergency changes, and compliance trends.
Asset & Configuration Governance
- Support governance of IT asset management and configuration management processes.
- Ensure hardware, software, endpoint, server, and infrastructure inventories remain accurate and compliant.
- Monitor software licensing compliance and asset lifecycle controls.
- Validate compliance with asset disposition, refresh, and inventory management procedures.
Risk Management
- Participate in periodic IT risk assessments across infrastructure, applications, manufacturing systems, and business processes.
- Identify control gaps, process weaknesses, and compliance risks.
- Develop and track remediation plans in partnership with business and technology teams.
- Assist with business continuity and disaster recovery governance activities.
Incident & Event Management Oversight
- Monitor compliance with incident and event management processes.
- Ensure root cause analysis and corrective actions are documented and completed.
- Track operational and compliance metrics related to major incidents and service disruptions.
- Identify process improvement opportunities based on incident trends and recurring issues.
Reporting & Continuous Improvement
- Develop compliance dashboards, KPI reporting, and management updates.
- Present compliance metrics, audit status, risk items, and remediation progress to IT leadership.
- Recommend process improvements to strengthen governance, operational maturity, and audit readiness.
- Support automation initiatives that improve control effectiveness, evidence management, and reporting.
Education
- Bachelor's degree in Information Systems, Computer Science, Accounting, Business Administration, Risk Management, or related field.
Experience
- 5-8 years of experience in IT controls, compliance, audit, governance, cybersecurity, or risk management.
- Experience supporting public company compliance requirements, including SOX-related IT controls.
- Experience working within manufacturing, multi-site operations, or distributed business environments.
- Experience with audit coordination, control testing, evidence collection, and remediation tracking.
- Previous supervisory, team leadership, or cross-functional program leadership experience preferred.
Preferred Certifications
- CISA
- CRISC
- CISSP
- CIA
- ITIL Foundation
- PMP preferred
Technical
Leadership
Business
IT General Controls
Cross-functional collaboration
Manufacturing operations awareness
SOX Compliance
Process improvement
Financial controls understanding
Change Management
Project management
Regulatory compliance
Audit Management
Communication and presentation skills
Vendor governance
Risk Assessments
Organizational effectiveness
Business process discipline
Policy Governance
Follow-through and accountability
Operational risk awareness
Asset Management
Cybersecurity Controls
- ITGC testing completion: 100%
- Audit findings closed on time: greater than 95%
- Change success rate: greater than 98%
- Emergency changes: less than 5%
- Asset inventory accuracy: greater than 99%
- Compliance training completion: 100%
- Evidence collection timeliness: 100%
- Policy review completion: 100%
Reports to the Director, IT Site Services & Controls Compliance. This role may directly supervise or coordinate work performed by Controls Analysts, Compliance Analysts, Change Management Coordinators, Asset Governance Specialists, or other IT governance resources.
Key Stakeholders- CIO and IT Leadership
- Finance and Accounting
- Internal Audit
- Manufacturing Site Leadership
- Information Security
- External Auditors
- Business Process Owners
- Technology Vendors and Service Providers