IT Governance, Risk and Compliance Engineer

Nesco Resource, LLC
Chicago, IL, United States
25 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$124,800.0 - $156,000.0
Working hours
Regular working hours
Job source

Tech stack

Software Documentation Cyber Security Information Systems Identity and Access Management Information Technology Audit IT Management Information Technology Operations Smartsuite IT General Controls (ITGC) Microsoft Dynamics 365 Finance & Operations

Job description

Our client is seeking a Senior Associate in IT Governance Risk and Compliance to join their Cybersecurity and Compliance team. This role plays a key part in supporting the company’s SOX and IT compliance program by evaluating the design and operating effectiveness of IT controls, supporting control owners in consistent SOX adoption, and executing select compliance-owned controls. The Senior IT GRC Associate will work closely with the company’s IT, Security and Finance departments, as well as its parent company’s teams, Internal Audit, and External Auditors to help maintain a strong, sustainable, and audit-ready IT control environment, while also identifying opportunities to improve efficiency and consistency across control execution. Key Responsibilities of the IT Governance, Risk and Compliance Engineer Job in Chicago, IL: IT Control Testing & Assurance

  • Perform testing of IT General Controls (ITGCs), IT Application Controls (ITACs), and key system-generated reports in accordance with company policy and SOX requirements.
  • Evaluate control design and operating effectiveness, develop testing procedures, review evidence, and clearly document results.
  • Perform re-testing and validate remediation efforts for control deficiencies.
  • Support testing related to enterprise systems.

SOX Compliance & Control Owner Support

  • Partner with IT and business control owners to support SOX compliance adoption and drive consistency in control execution.
  • Provide guidance on documentation standards, evidence expectations, and process improvements.
  • Participate in SOX walkthroughs and serve as a key liaison for Internal and External Audit requests.

Compliance-Owned Control Execution

  • Execute and document controls managed by the Cyber and Compliance team, including access reviews, privileged/admin activity reviews, authentication reviews, and key report validations.
  • Ensure controls are performed accurately, completely, and on time per defined frequency.

Access & Security Governance

  • Review user access provisioning, modifications, and terminations for in-scope systems.
  • Assist in monitoring and review of privileged access and administrative activity.
  • Identify control gaps, policy deviations, and risks, and recommend remediation or enhancements.

Documentation, Quality & Continuous Improvement

  • Maintain audit-ready documentation within GRC tools or designated repositories.
  • Help standardize control descriptions, testing approaches, and evidence requirements.
  • Identify opportunities to streamline, automate, or improve the effectiveness of controls and compliance processes.

Requirements

  • Bachelor’s degree in Information Systems, Cybersecurity, Accounting, Finance, or a related field (or equivalent experience).
  • 3-5 years of experience in IT GRC, IT audit, SOX compliance, technology risk, or a related role.
  • Hands-on experience testing ITGCs and supporting SOX compliance activities.
  • Understanding of logical access controls, change management, and IT operations controls.
  • Strong analytical skills with attention to detail and sound judgment.
  • Ability to clearly communicate control requirements and testing outcomes to both technical and non-technical stakeholders.

Preferred

  • Experience with Microsoft Dynamics 365 Finance and Operations (D365 F&O) control testing or audit support.
  • Prior experience executing or testing IT Application Controls (ITACs).
  • Familiarity with GRC tools (e.g., AuditBoard, Workiva, Fastpath).
  • Working knowledge of identity and access management (IAM) concepts.
  • Professional certifications such as CISA, CISM, CRISC, or CIA.

Benefits & conditions

3.63.6 out of 5 stars Chicago, IL 60607 Hybrid work $60 - $75 an hour - Temp-to-hire, Pulled from the full job description

  • 401(k)
  • Health insurance
  • Vision insurance
  • Dental insurance
  • Employee assistance program, Nesco Resource offers a comprehensive benefits package for our associates, which includes a MEC (Minimum Essential Coverage) plan that encompasses Medical, Vision, Dental, 401K, and EAP (Employee Assistance Program) services. Equal Employment Opportunity

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah · World Congress 2025

2:17 min

Governing enterprise IT as a global automotive CIO

Katrin Lehmann Katrin Lehmann +1 · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

5:00 min

Managing complex state with scope-based resource management

Bjarne Stroustrup · World Congress 2022

2:08 min

Managing complex structures and corporate guidelines

Alexandra Petri · World Congress 2023

Videos

See all

Related articles

See all