IT Compliance Manager
HighLevel is an AI-powered business operating system that gives agencies, entrepreneurs and SMBs the infrastructure to build, automate and scale. Today, HighLevel supports SMBs across 150+ countries, fueling community-driven growth rooted in real customer outcomes.
To date, businesses operating on HighLevel have generated over $7 billion in ecosystem value, demonstrating the impact of shared infrastructure at scale. By centralizing conversations, automation and intelligence into one system, we help businesses move faster, reduce complexity and execute efficiently.
Behind the platform, HighLevel powers more than 4 billion API hits and 2.5 billion message events daily. With 250 terabytes of distributed data, 250+ microservices and over 1 million domain names supported, our architecture is built for performance, resilience and long-term scalability.
Our People:
With over 2,000 team members across 10+ countries, HighLevel operates as a global, remote-first organization built for speed and ownership. We value initiative, clarity and execution, creating space for ambitious people to build systems that support millions of businesses worldwide. Here, innovation thrives, ideas are celebrated and people come first, no matter where they call home.
Our Impact:
Every month, HighLevel enables more than 1.5 billion messages, 200 million leads and 20 million conversations for the more than 1 million businesses we support. Behind those numbers are real people building independence, expanding opportunity and creating measurable impact. We’re proud to be a part of that.
Learn more about us on our YouTube Channel or Blog Posts
Who You Are
We're looking for a Manager – IT Compliance with deep, hands-on SOX expertise across IT General Controls (ITGCs) and IT Application Controls (ITACs). In this high-impact individual contributor role reporting to the Director of IT Compliance, you'll assist in driving the IT Compliance program and strategy - conducting control design and periodic control effectiveness testing, and working closely with control owners on gap remediation and validation across the systems that support financial reporting.
As a cross-functional influencer, you'll partner closely with Engineering, Product, Security, Finance, and Compliance to keep controls effective as our platforms evolve - embedding automation into compliance workflows and guiding the responsible adoption of AI-enabled technologies. You'll balance delivery speed with control sustainability, bringing the judgment of someone who has designed, tested, and remediated SOX IT controls in complex technology environments, ideally with Big 4 and/or high-growth technology company experience.
What You'll Do
-
Assist in driving the IT Compliance program and strategy in partnership with the Director of IT Compliance and Strategy, the SOX Compliance function, and internal and external auditors - including scoping, risk assessment, documentation, and testing readiness for the SOX ITGC and ITAC program within your owned domain.
-
Conduct control design assessments and periodic control effectiveness testing across ITGCs and ITACs, evaluating whether controls are appropriately designed and operating effectively, and reporting results to leadership.
-
Be accountable for domain-level compliance outcomes; drive multi-quarter initiatives (new system onboarding, control rationalization, evidence automation, continuous controls monitoring) with predictable, milestone-based delivery.
-
Oversee the day-to-day effectiveness of ITGC operations across logical access management, change management, computer operations (batch processing, backup and recovery, job scheduling, logging), and cloud configuration controls for in-scope systems.
-
Own the ITAC portfolio: identify, document, and support testing of key automated controls, key reports and IPE (completeness and accuracy), configuration controls, and interface/data-transfer controls in partnership with Engineering and Finance.
-
Maintain the inventory of systems and tools that support financial reporting (directly or indirectly) and apply risk-based tiering to prioritize control implementation and testing effort.
-
Serve as the hands-on lead for internal and external IT audits, SOX reviews, and control assessments - facilitating walkthroughs, coordinating PBC requests, supporting testing, and reporting status to leadership.
-
Work closely with control owners on gap remediation and validation efforts - driving root-cause analysis, advising on remediation design, validating fixes before closure, and preventing repeat findings.
-
Embed automation and intelligent engineering practices into compliance workflows - automated evidence collection, continuous controls monitoring, and analytics - and evaluate and guide the responsible adoption of advanced and intelligent (AI-enabled) technologies aligned with roadmap needs and control requirements.
-
Define and communicate the control architecture & requirements , balancing delivery speed against long-term sustainability so controls remain effective and durable as systems, platforms, and delivery models evolve.
-
Ensure change management and SDLC controls support system stability and release quality while sustaining engineering velocity - making controls preventive, repeatable, and scalable within CI/CD pipelines, infrastructure-as-code, and automated access workflows.
-
Prepare high-quality documentation (narratives, flowcharts, risk-and-control matrices, test workpapers) and continuous improvement of IT control processes.
-
partner cross-functionally with Engineering, Product, Security, Finance, and Compliance; coach and develop control owners; resolve conflicts constructively; and foster a culture of disciplined innovation and continuous technological evolution.
What You’ll Bring
-
Bachelor’s degree in Information Technology, Accounting, Management Information Systems (MIS), or Finance.
-
7–10 years of progressive experience in IT audit, internal controls, or technology risk management, including supervisory experience; Big 4 experience preferred.
-
Professional credentials such as CISA, CRISC, CIA, or CPA strongly preferred.
-
Deep, hands-on expertise in SOX 404 ITGCs and ITACs, including key reports/IPE, configuration controls, and interface controls.
-
Strong command of internal control frameworks (COSO, COBIT) and risk assessment methodologies.
-
Working knowledge of cloud platforms, CI/CD pipelines, DevOps practices, and modern SaaS architectures - and how to design and evaluate controls in these environments.
-
Sound understanding of security and control principles, including logical access, change management, least privilege, segregation of duties, computer operations, and vulnerability management.
-
Proven ability to plan and deliver audits and multi-quarter control initiatives with predictable outcomes in complex technology environments.
-
Strong communication, analytical, problem-solving, and program management skills, with the ability to translate technical detail for executive and audit audiences.
-
Demonstrated ability to influence stakeholders and uphold standards without direct authority; technology industry experience strongly preferred.
EEO Statement:
The company is an Equal Opportunity Employer. As an employer subject to affirmative action regulations, we invite you to voluntarily provide the following demographic information. This information is used solely for compliance with government recordkeeping, reporting, and other legal requirements. Providing this information is voluntary and refusal to do so will not affect your application status. This data will be kept separate from your application and will not be used in the hiring decision.
We encourage you to review our Privacy Policy before submitting your application
As published by lever
Resume/CV, Full name, Pronouns, Email, Phone, Current location, Current company, LinkedIn URL, Twitter URL, GitHub URL, Portfolio URL, Other website
- Do you incorporate AI into your daily coding? If so, which tools or models do you use? written answer
- Are you legally authorised to work in India? choose one
- Will you now or in the future require sponsorship for employment (e.g., work visa, visa transfer) in India? choose one
- Gender (Select one) choose one · optional
- Ethnicity (Select one): choose one · optional