Manager, IT Risk and Compliance
JOB OVERVIEW
The Manager – IT Risk and Compliance reports to the Executive Director - IT Risk & Compliance, and ensures that all IT operations, processes, and systems are compliant with industry standards and legal regulations. Utilizes a strong background in IT audit, risk, and compliance, with a focus on SOX compliance and operational information security audits. Conducts risk assessments, manages access to applications, and develops internal controls in coordination with the Executive Director, IT Risk & Compliance. May lead or mentor IT professionals as the team structure evolves. Leverages a deep understanding of IT governance frameworks, data privacy laws, network security architecture, and business continuity planning.
RESPONSIBILITIES & DUTIES
Ensure that all IT operations, processes, and systems comply with industry standards and legal regulations, including a focus on SOX compliance and operational information security audits.
Conduct comprehensive risk assessments and manage the mitigation of identified risks to maintain the integrity and security of company IT infrastructure.
Oversee access to all applications, ensuring that only authorized individuals have access to relevant data and systems.
Develop and maintain robust internal controls, in coordination with the Executive Director, to safeguard the company’s digital assets and data.
Develop and maintain IT policies and procedures, subject to Executive Director review and approval, to support the company’s operations and regulatory compliance.
Conduct regular reviews of system access and IT controls to identify potential weaknesses and areas for improvement.
May provide guidance and mentorship to IT risk and compliance staff as team responsibilities expand.
Monitor regulatory changes and developments to ensure company practices remain in compliance, escalating findings and recommendations to the Executive Director, IT Risk & Compliance.
Evaluate and recommend new technologies to improve compliance and risk management processes.
Support and help implement programs/initiatives to enhance compliance awareness, contributing to continuous improvement of the Company’s Compliance and Risk Management programs under the direction of the Executive Director.
Travel to various locations, both within our organization and externally, may be required depending on your role and responsibilities.
Follows assigned work schedule with regular and predictable attendance.
Performs other duties as assigned.
QUALIFICATIONS
Over 6 years of experience in IT audit, risk, and compliance.
Bachelor's degree in Information Technology, Computer Science, or a related field required. Advanced degrees or certifications in IT compliance or risk management are preferred.
Proven experience in leading IT SOX compliance and operational information security audits.
Strong understanding of industry standards and legal regulations related to IT and data compliance.
Excellent problem-solving skills and the ability to work under pressure.
Strong communication skills and the ability to work effectively with both technical and non-technical staff.
PROFESSIONAL CERTIFICATIONS
Relevant certifications such as CISA, CRISC, CDPSE, and CISM from ISACA.
SIE Certification
Series 99
Series 7 preferred
If you do not already have a Securities license relevant to your role at Innovayte, you may be required to take and pass the Securities Industries Essentials exam provided by FINRA. In addition, based on your role responsibilities, you may also be required to pass additional Securities Industry exams to allow you to operate in your role and be compliant with FINRA and the SEC requirements. These licenses, when required, need to be obtained within certain specific time frames, typically 120 calendar days.
TECHNICAL SKILLS
To be successful in this role, you should have experience with and an understanding of the following:
Experience with cloud-based data compliance, including familiarity with platforms like Microsoft Azure.
Knowledge of IT governance frameworks such as COBIT, ITIL, and ISO 27001.
Proficiency in using GRC (Governance, Risk, and Compliance) tools for risk assessments and compliance management.
Experience with data privacy laws such as GDPR, CCPA, and HIPAA.
Understanding of network security architecture and security system design.
Experience with incident response planning and security breach drills.
Proficiency in conducting internal and external audits for IT compliance.
Experience with business continuity planning and disaster recovery strategies.
CULTURAL COMPETENCIES
Innovayte is dedicated to building an environment where each team member can thrive, contribute meaningfully, and grow professionally and personally. We believe that our core values—rooted in
respect,
empowerment,
innovation,
service,
integrity,
trust, and
accountability
are essential to achieving our mission. These values guide us in everything we do, from daily interactions to strategic decisions. We’re looking for individuals who not only share these principles but are excited to bring them to life in meaningful ways.
PHYSICAL DEMANDS/WORK ENVIRONMENT
This job operates in a professional office environment, which may include a corporate office setting or a remote/home office environment, and routinely uses standard office equipment and technology such as computers, phones, printers, and video conferencing tools. While performing the duties of this job, the associate is regularly required to communicate effectively, including speaking, hearing, and participating in virtual meetings on camera. The associate is frequently required to sit for extended periods of time, as well as occasionally stand, walk, use hands and fingers, and reach with hands and arms. This job may require the ability to lift files or office materials, open filing cabinets, and bend or stand on a stool as necessary. Remote associates are expected to maintain a safe, secure, and productive work environment with reliable internet access.
DISCLAIMER/ASSOCIATE ACKNOWLEDGEMENT
The above statements describe the general nature and level of work only. They are not an exhaustive list of all required responsibilities, duties, and skills. Other duties may be added, or this description amended at any time.
Equity Trust Company is an equal opportunity at will employer and does not discriminate against any employee or applicant for employment because of age, race, religion, color, disability, sex, sexual orientation, or national origin.