Senior Staff IT Controls & AI-Augmented Assurance Engineer (AI/GRC)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Staff IT Controls & AI-Augmented Assurance Engineer (AI/GRC): Leading the design and scaling of IT General Controls across enterprise applications with an accent on AI-augmented assurance and automation. Focus on building AI-native continuous controls monitoring, integrating LLMs for evidence review, and ensuring SOX 404 compliance across NetSuite, Workday, and Salesforce.
Location: Must be based in the USA. Hybrid roles in San Francisco, Seattle, Denver, and New York (office attendance 2-3 days per week).
Salary: $175,000 – $225,000 /yr
Company
is a platform that helps small businesses manage payroll, health insurance, 401(k)s, and HR.
What you will do
- Own ITGC design and operation across enterprise applications, including logical access, change management, SDLC, and segregation of duties (SoD).
- Lead the 1st-line control environment for NetSuite, Workday, and Salesforce, embedding controls into operational workflows.
- Manage the audit lifecycle as the primary liaison with Internal Audit, External Audit, and the SOX PMO.
- Build AI-native continuous controls monitoring using LLM-based evidence review and agentic control testing.
- Oversee the controls posture for 's internal AI and automation portfolio, ensuring risk classification and validation.
- Govern application change management, privileged access, and periodic user access reviews (UARs).
Requirements
- 10+ years of experience in IT controls, audit, or enterprise applications governance.
- Deep expertise in SOX 404, COSO, and COBIT frameworks.
- Hands-on experience operating as a control owner across NetSuite, Workday, and/or Salesforce.
- Proven track record leading external audit engagements (Big 4 or equivalent).
- Experience building and deploying AI-augmented controls, such as LLM-based reviewers or automated anomaly detection.
- Strong judgment on AI risk, including model risk and prompt injection.
Nice to have
- Relevant certifications such as CISA, CISSP, CIA, or CPA.
- Familiarity with SOC 1/2, ISO 27001, NIST CSF, or PCI DSS frameworks.
Culture & Benefits
- Competitive base pay, benefits, and equity (RSUs).
- Hybrid work environment with physical offices in major US hubs.
- Inclusive culture focused on supporting the small business economy.
- Equal opportunity employer with a commitment to diversity and reasonable accommodations.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →