IT Governance, Risk and Compliance Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Our client is seeking a Senior Associate in IT Governance Risk and Compliance to join their Cybersecurity and Compliance team. This role plays a key part in supporting the company’s SOX and IT compliance program by evaluating the design and operating effectiveness of IT controls, supporting control owners in consistent SOX adoption, and executing select compliance-owned controls. The Senior IT GRC Associate will work closely with the company’s IT, Security and Finance departments, as well as its parent company’s teams, Internal Audit, and External Auditors to help maintain a strong, sustainable, and audit-ready IT control environment, while also identifying opportunities to improve efficiency and consistency across control execution. Key Responsibilities of the IT Governance, Risk and Compliance Engineer Job in Chicago, IL: IT Control Testing & Assurance
- Perform testing of IT General Controls (ITGCs), IT Application Controls (ITACs), and key system-generated reports in accordance with company policy and SOX requirements.
- Evaluate control design and operating effectiveness, develop testing procedures, review evidence, and clearly document results.
- Perform re-testing and validate remediation efforts for control deficiencies.
- Support testing related to enterprise systems.
SOX Compliance & Control Owner Support
- Partner with IT and business control owners to support SOX compliance adoption and drive consistency in control execution.
- Provide guidance on documentation standards, evidence expectations, and process improvements.
- Participate in SOX walkthroughs and serve as a key liaison for Internal and External Audit requests.
Compliance-Owned Control Execution
- Execute and document controls managed by the Cyber and Compliance team, including access reviews, privileged/admin activity reviews, authentication reviews, and key report validations.
- Ensure controls are performed accurately, completely, and on time per defined frequency.
Access & Security Governance
- Review user access provisioning, modifications, and terminations for in-scope systems.
- Assist in monitoring and review of privileged access and administrative activity.
- Identify control gaps, policy deviations, and risks, and recommend remediation or enhancements.
Documentation, Quality & Continuous Improvement
- Maintain audit-ready documentation within GRC tools or designated repositories.
- Help standardize control descriptions, testing approaches, and evidence requirements.
- Identify opportunities to streamline, automate, or improve the effectiveness of controls and compliance processes.
Requirements
- Bachelor’s degree in Information Systems, Cybersecurity, Accounting, Finance, or a related field (or equivalent experience).
- 3-5 years of experience in IT GRC, IT audit, SOX compliance, technology risk, or a related role.
- Hands-on experience testing ITGCs and supporting SOX compliance activities.
- Understanding of logical access controls, change management, and IT operations controls.
- Strong analytical skills with attention to detail and sound judgment.
- Ability to clearly communicate control requirements and testing outcomes to both technical and non-technical stakeholders.
Preferred
- Experience with Microsoft Dynamics 365 Finance and Operations (D365 F&O) control testing or audit support.
- Prior experience executing or testing IT Application Controls (ITACs).
- Familiarity with GRC tools (e.g., AuditBoard, Workiva, Fastpath).
- Working knowledge of identity and access management (IAM) concepts.
- Professional certifications such as CISA, CISM, CRISC, or CIA.
Benefits & conditions
3.63.6 out of 5 stars Chicago, IL 60607 Hybrid work $60 - $75 an hour - Temp-to-hire, Pulled from the full job description
- 401(k)
- Health insurance
- Vision insurance
- Dental insurance
- Employee assistance program, Nesco Resource offers a comprehensive benefits package for our associates, which includes a MEC (Minimum Essential Coverage) plan that encompasses Medical, Vision, Dental, 401K, and EAP (Employee Assistance Program) services. Equal Employment Opportunity
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence
A Guide to Green Tech and Green IT Careers
Now is the time for industrialized software development