> Markdown version of [/jobs/ext/1697647-head-of-it-assurance-director](https://www.wearedevelopers.com/jobs/ext/1697647-head-of-it-assurance-director). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Head of IT Assurance Director - **Company:** SMBC, L.C. - **Location:** White Plains, NY, United States (Remote available) - **Experience:** Expert - **Salary:** $180,000.0 - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Information Systems, Databases, Data Governance, Information Technology Audit, Information Technology Operations, Systems Development Life Cycle, IT General Controls (ITGC), Information Technology - **Published:** July 7, 2026 - **Apply:** https://www.juju.com/job/00000000gemave ## About the Role The IT Assurance Director is expected to have the following, but not limited to: + The ability to interact and collaborate with subordinates, peers, and senior management in a professional and partnering manner and instill confidence that will influence decision making. + Expert decision making is expected on complex, technical issues. Typically, these will entail technology and control issues as well as other issues such as organizational development. Position will participate in the decision-making process for department and company-wide policies. + Position is expected to identify and resolve issues as they arise. + Position will be responsible for determining the need for and directly managing external resources that are engaged for projects. We would like to see candidates who have the following qualifications; + Bachelors degree in information systems, accounting, or equivalent. + 15+ years of professional audit experience in public accounting, internal audit, and/or consulting and a strong technology background. + CPA and CISA certification or comparable certification. + Expert knowledge of COBIT, IT general controls and applications, and data governance framework of DCAM. + Working knowledge of various technologies, applications, operating systems, and databases. + Expert understanding of current cybersecurity risks and trends. + Expert understanding of the system development lifecycle and the business risks associated with system implementations. + Demonstrated project management skills. + Demonstrated communication skills (verbal, writing, presentation) and + Executive management presence. ## Description Finance Control Oversight ("FCO") IT Assurance Director leads IT assessments for SMBC Combined US Operations entities ("CUSO") in the areas of internal control over financial reporting ("ICFR") and regulatory reporting quality assurance ("RRQA"). FCO is within SPDAD FAD Controllers. In addition, the IT Assurance Director supports broader FCO assessment activities by evaluating technology, data, and information governance controls that support financial reporting, regulatory reporting, capital planning, and other Finance risk management initiatives. FCO IT Control's work is focused on the following primary activities: + Evaluating internal control environment in IT general control and application and making recommendations; + Taking a leadership role with the CUSO entities' IT controls to comply with the U.S. and Japan Sarbanes-Oxley Act (collectively "SOX"); + Performing and updating periodic IT risk assessments and communicating to management; + Developing FCO IT control policies and procedures; + Assisting SMBC's independent auditor with their annual audit; and + Performing various other consulting and special projects. Responsibilities The IT Assurance Director is responsible for drafting the annual IT assessment plan and managing IT audit execution of significant components of it. The IT Assurance Director will: + Coordinate the annual risk assessment, collecting input from senior management and assessing SMBC Americas Division ("AD")/CUSO's strategic initiatives and changes in the business and IT, and document ITGC assessment approach to the identified risks. + Develop and the execute the risk-based IT assessment plan. + Plan and develop IT assessment programs (including IT entity level control, access control, system development/change, IT operations, cybersecurity and IT application - IPE and data quality); + Manage the annual IT assessments (including SOX testing) for SMBC AD/CUSO to meet timeline commitments. Ensure that all assessment steps meet objectives and are completed and reviewed on schedule. + Review internal control testing of IT Controls for quality assurance; + Understand and assess the IT system flows, technology risks, and the related controls supporting the business processes. Identify gaps and inefficiencies in the IT environments and provide recommendations to close those gaps and improve process efficiencies; + Evaluate control exceptions to determine if a deficiency exists and the level of that deficiency. Discuss issues with management to agree on risks and remediation needed; + Communicate findings and recommendations to all levels of departmental and operating unit management verbally and through concisely written reports; + Supervise staff and review their work to ensure it meets the standards of the FCO Policies and Procedures; + Develop and foster strong professional relationships within SMBC AD/CUSO. + Build the department's standing and credibility throughout SMBC AD/CUSO; and + Take a proactive role in departmental continuous improvement initiatives. ## Related Videos - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Data Governance in the Era of AI](https://www.wearedevelopers.com/videos/1622-data-governance-in-the-era-of-ai) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) - [Navigating the Corporate Jungle: Life as a Developer in a large Company](https://www.wearedevelopers.com/videos/621-navigating-the-corporate-jungle-life-as-a-developer-in-a-large-company) ## Related Articles - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Should Tech Managers Be Developers First? Pros and Cons](https://www.wearedevelopers.com/magazine/327-should-tech-managers-be-developers-first-pros-and-cons) - [Does The Tech Industry Have The Best Work-life Balance?](https://www.wearedevelopers.com/magazine/427-does-the-tech-industry-have-the-best-work-life-balance) - [Best Companies to Work For in Berlin: Top 14 Companies in 2023 ](https://www.wearedevelopers.com/magazine/188-best-companies-to-work-for-in-berlin-top-14-companies-in-2023)