> Markdown version of [/jobs/ext/2462643-it-governance-risk-and-compliance-engineer](https://www.wearedevelopers.com/jobs/ext/2462643-it-governance-risk-and-compliance-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Governance, Risk and Compliance Engineer - **Company:** Nesco Resource, LLC - **Location:** Chicago, IL, United States - **Experience:** Expert - **Salary:** $124,800.0 - $156,000.0 - **Contract:** Temporary to permanent - **Skills:** Software Documentation, Cyber Security, Information Systems, Identity and Access Management, Information Technology Audit, IT Management, Information Technology Operations, Smartsuite, IT General Controls (ITGC), Microsoft Dynamics 365 Finance & Operations - **Published:** August 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=11edace5c2965b0b ## About the Role * Bachelor's degree in Information Systems, Cybersecurity, Accounting, Finance, or a related field (or equivalent experience). * 3-5 years of experience in IT GRC, IT audit, SOX compliance, technology risk, or a related role. * Hands-on experience testing ITGCs and supporting SOX compliance activities. * Understanding of logical access controls, change management, and IT operations controls. * Strong analytical skills with attention to detail and sound judgment. * Ability to clearly communicate control requirements and testing outcomes to both technical and non-technical stakeholders. Preferred * Experience with Microsoft Dynamics 365 Finance and Operations (D365 F&O) control testing or audit support. * Prior experience executing or testing IT Application Controls (ITACs). * Familiarity with GRC tools (e.g., AuditBoard, Workiva, Fastpath). * Working knowledge of identity and access management (IAM) concepts. * Professional certifications such as CISA, CISM, CRISC, or CIA. ## Description Our client is seeking a Senior Associate in IT Governance Risk and Compliance to join their Cybersecurity and Compliance team. This role plays a key part in supporting the company's SOX and IT compliance program by evaluating the design and operating effectiveness of IT controls, supporting control owners in consistent SOX adoption, and executing select compliance-owned controls. The Senior IT GRC Associate will work closely with the company's IT, Security and Finance departments, as well as its parent company's teams, Internal Audit, and External Auditors to help maintain a strong, sustainable, and audit-ready IT control environment, while also identifying opportunities to improve efficiency and consistency across control execution. Key Responsibilities of the IT Governance, Risk and Compliance Engineer Job in Chicago, IL: IT Control Testing & Assurance * Perform testing of IT General Controls (ITGCs), IT Application Controls (ITACs), and key system-generated reports in accordance with company policy and SOX requirements. * Evaluate control design and operating effectiveness, develop testing procedures, review evidence, and clearly document results. * Perform re-testing and validate remediation efforts for control deficiencies. * Support testing related to enterprise systems. SOX Compliance & Control Owner Support * Partner with IT and business control owners to support SOX compliance adoption and drive consistency in control execution. * Provide guidance on documentation standards, evidence expectations, and process improvements. * Participate in SOX walkthroughs and serve as a key liaison for Internal and External Audit requests. Compliance-Owned Control Execution * Execute and document controls managed by the Cyber and Compliance team, including access reviews, privileged/admin activity reviews, authentication reviews, and key report validations. * Ensure controls are performed accurately, completely, and on time per defined frequency. Access & Security Governance * Review user access provisioning, modifications, and terminations for in-scope systems. * Assist in monitoring and review of privileged access and administrative activity. * Identify control gaps, policy deviations, and risks, and recommend remediation or enhancements. Documentation, Quality & Continuous Improvement * Maintain audit-ready documentation within GRC tools or designated repositories. * Help standardize control descriptions, testing approaches, and evidence requirements. * Identify opportunities to streamline, automate, or improve the effectiveness of controls and compliance processes. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) - [Engineering/Manager Pendulum: Generating compound interest on your career](https://www.wearedevelopers.com/videos/100348-engineering-manager-pendulum-generating-compound-interest-on-your-career) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j)