> Markdown version of [/jobs/ext/2921821-director-it-governance-risk-compliance](https://www.wearedevelopers.com/jobs/ext/2921821-director-it-governance-risk-compliance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director, IT Governance, Risk & Compliance - **Company:** CMC - **Location:** Irving, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Systems, Identity and Access Management, Information Technology Audit, IT Management, SAP (Applications), SAP GRC, SAP Security, Enterprise Software Applications, IT General Controls (ITGC), SAP S/4HANA, Servicenow - **Published:** September 15, 2026 - **Apply:** https://jobs.cmc.com/talentcommunity/apply/1429562900/?locale=en_US ## About the Role * 12+ years of progressive experience in IT audit, technology risk, governance, compliance, cybersecurity assurance, or related disciplines, including at least 5 years leading managers or senior professional teams * Proven experience leading and maturing an IT audit, technology compliance, governance, or technology risk organization within a large, complex enterprise * Prior Big 4 public accounting or external audit experience serving large companies is strongly preferred, with direct responsibility for IT audit, SOX ITGC, controls assurance, or technology risk engagements * Deep knowledge of SOX ITGCs, control design and testing, risk assessment, deficiency evaluation, remediation, audit evidence, and management reporting * Strong working knowledge of enterprise applications and infrastructure controls, including SAP security, segregation of duties, privileged access, change management, computer operations, interfaces, and key reports * Demonstrated success improving audit readiness, strengthening control environments, reducing repeat findings, and advancing compliance program maturity beyond tactical audit response * Executive-level communication and stakeholder management skills, including the ability to influence across IT, Finance, Internal Audit, external auditors, and business leadership * CISA certification strongly preferred. CPA, CIA, CRISC, or other relevant certification is a plus * Experience with SAP S/4HANA, SAP GRC, ServiceNow GRC / IRM, Workiva, Archer, MetricStream, or comparable governance and compliance platforms * Knowledge of commonly used frameworks and requirements such as COBIT, COSO, NIST CSF, ISO 27001, SOC reporting, CMMC, NIS2, and AI governance Your Education * Bachelor's degree in Information Systems, Accounting, Finance, Cybersecurity, Business, or a related field. MBA preferred ## Description * Lead the continued maturation of CMC's IT Governance, Risk & Compliance program and define the next phase of its maturity strategy * Establish consistent governance standards, accountability models, decision rights, and control ownership across technology functions * Strengthen control design, policy management, compliance monitoring, and standard artifacts, with rigor proportionate to financial, regulatory, cybersecurity, and operational risk * Drive alignment among business objectives, technology strategy, compliance requirements, and risk management priorities * Promote a culture of accountability, operational discipline, and continuous improvement in which compliance is embedded in day-to-day delivery * Serve as the primary IT leadership interface for Internal Audit, external auditors, and compliance stakeholders * Improve audit readiness through standardized evidence management, documentation practices, remediation governance, control monitoring, request intake, and clear closure criteria * Partner with technology and business leaders to proactively address audit findings, improve evidence quality, and reduce recurring deficiencies and late-cycle surprises * Provide executive-level insight on governance maturity, compliance performance, control effectiveness, remediation aging, evidence quality, and emerging risk * Ensure compliance activities improve operations and control effectiveness rather than simply satisfy audit requirements, while maintaining the distinction between management ownership and independent assurance * Oversee ITGC and SOX compliance across access management, change management, computer operations, interfaces, key reports, and technology-dependent controls * Establish and execute annual approach to IT SOX scoping in collaboration with Internal Audit and management stakeholders * Direct governance for SAP access, segregation of duties, privileged access, Firefighter / emergency access, user access reviews, and SAP GRC capabilities * Establish a risk-based method to prioritize deficiencies by financial reporting exposure, regulatory impact, cybersecurity risk, and operational complexity * Partner with IT, Finance, Internal Audit, Cybersecurity, and business stakeholders to support effective governance, compliance, and control execution * Support business units and control owners in identifying IT control gaps * Provide training and guidance to IT control owners and business unit managers on SOX requirements, control objectives, and best practices * Implement a repeatable evidence operating model with standardized repositories, request ownership, naming conventions, quality checks, retention requirements, and closure criteria * Drive timely, sustainable remediation of deficiencies and validate that corrective actions are designed, implemented, documented, and testable * Establish dashboards and metrics that show control effectiveness, exceptions, remediation progress, audit demand, and recurring failure patterns * Identify opportunities to automate controls, evidence collection, access reviews, monitoring, and reporting through SAP GRC and other enabling technologies * Use lessons learned from audits and control failures to improve processes, training, system design, and accountability * Work with management to evaluate control evidence against quality standards prior to submitting it to auditors * Identify control deficiencies and recommend remediation plans in collaboration with Internal Audit ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Inside Mercedes-Benz: How CIO Katrin Lehmann is Empowering 5,000 Developers and Driving Digital Change](https://www.wearedevelopers.com/videos/1360-inside-mercedes-benz-how-cio-katrin-lehmann-is-empowering-5-000-developers-and-driving-digital-change) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [Robots are coming into the wild! Full-Stack Robotics Engineers, be ready!](https://www.wearedevelopers.com/videos/479-robots-are-coming-into-the-wild-full-stack-robotics-engineers-be-ready) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Companies to Work For in Berlin: Top 14 Companies in 2023 ](https://www.wearedevelopers.com/magazine/188-best-companies-to-work-for-in-berlin-top-14-companies-in-2023) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)