> Markdown version of [/jobs/ext/1008562-manager-it-governance-risk-and-compliance-grc](https://www.wearedevelopers.com/jobs/ext/1008562-manager-it-governance-risk-and-compliance-grc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager, IT Governance, Risk and Compliance (GRC) - **Company:** Amkor Technology - **Location:** Tempe, AZ, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Information Systems, IT Management, Information Technology Operations, IT General Controls (ITGC), Information Technology - **Published:** June 9, 2026 - **Apply:** https://www.dice.com/job-detail/d8ea9f06-0a69-4fb0-b144-ec2da77a0a20 ## About the Role * Bachelor's degree in Information Technology, Computer Science, Information Systems, Accounting, Business or a related field. * A minimum of 7+ years' experience with Sarbanes-Oxley or compliance testing, including the development of remediation activities or steps. * Working knowledge and understanding of Sarbanes-Oxley compliance, including IT General Controls and Application controls. * Demonstrated experience with risk management frameworks and tools. * Excellent communication skills, along with the ability to effectively collaborate with IT leaders, IT practitioners, and internal and external audit partners, are key for this role. ## Description The Sr. Manager in IT Governance, Risk and Compliance (GRC) leads our IT compliance and risk management initiatives. This role will be responsible for overseeing IT SOX audit readiness and execution, managing IT risk assessments, and ensuring alignment with regulatory and internal control requirements. The ideal candidate will have deep expertise inIT controls/audit processes and hands-on experience of IT risk management. This position is based at Amkor's corporate headquarters in Tempe, AZ., * IT SOX Audit Management: + Manage the IT compliance program with an emphasis in SOX. + Monitor control execution and evidence collection using various methods that include periodic meetings/reviews with process, application, and control owners. + Assist control owners in developing remediation plans, provide thought leadership on new system implementations, significant modifications to existing systems, and IT policy changes, and assess the impact on internal IT controls. + Partner with internal and external auditors to support audit cycles. + Act as a central point for audit requests for evidence, liaison between control owners and external audit for document requests and support. + Ensure timely documentation and resolution of audit findings and control deficiencies. * Governance & Compliance: + Maintain policies, procedures, and standards to support IT governance and regulatory compliance. + Monitor changes in regulatory requirements and assess their impact on IT operations. + Provide training and awareness programs to promote a culture of compliance. * IT Risk Management: + Develop and maintain the IT risk management framework aligned with industry standards. + Conduct regular risk assessments and control evaluations across IT systems and processes. + Collaborate with stakeholders to identify, assess, and mitigate IT risks. * Reporting & Metrics: + Prepare and present risk and compliance metrics to senior leadership. + Track and report on audit progress, control effectiveness, and remediation status. ## Related Videos - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) - [Demystifying Crypto & Web3: A Technical Journey Through 15 Years of Innovation](https://www.wearedevelopers.com/videos/1516-demystifying-crypto-web3-a-technical-journey-through-15-years-of-innovation) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) ## Related Articles - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers)