Point your AI agent at freehire and let it find you a job.

Get the CLI →

TMUS Global Solutions

NewBe an early applicant

Sr Manager, Product & Engineering

Discussion

T-Mobile is looking for a hands-on Manager of SOX & Governance, Risk, and Compliance (GRC) to lead a team responsible for internal controls, audit readiness, and risk management across our enterprise technology platforms. This role sits at the intersection of compliance, engineering, and operations owning SOX program execution while driving GRC maturity across Oracle ERP, SAP supply chain systems, and Java-based custom applications.

You will directly manage a team of analysts and controls specialists, partner with Internal Audit, Legal, and Engineering leads, and serve as the primary point of escalation for compliance findings, control deficiencies, and platform-level risk. If you thrive in high-accountability environments and can translate technical risk into executive-level decisions this role is built for you.

REQUIRED QUALIFICATIONS:

  • 10+ years of progressive experience in IT audit, SOX compliance, or GRC with at least 2+ years in a people management role.
  • Demonstrated hands-on experience with Oracle ERP (Cloud or E-Business Suite) controls access provisioning, segregation of duties (SoD), and financial close processes.
  • Working knowledge of SAP (S/4HANA or ECC) from a controls and audit perspective basis configuration, authorization objects, and business process controls.
  • Familiarity with Java-based application environments able to assess ITGC risks, deployment pipelines, and change management controls in custom-built systems.
  • Deep understanding of SOX Section 302/404 requirements, PCAOB standards, and ITGC control domains (Change Management, Logical Access, Computer Operations, SDLC).
  • Proven track record of managing external audit relationships and delivering clean SOX opinions on schedule. This includes managing Big 4 engagement scope, pushing back on audit findings, and negotiating remediation timelines.
  • Experience with at least one GRC platform (Audit Board, ServiceNow GRC, RSA Archer, Workiva, or equivalent).
  • Strong executive communication skills able to synthesize complex compliance issues into concise risk narratives for non-technical leaders.
  • Bachelor's degree in information systems, Accounting, Business, Computer Science, or related field.
  • Working knowledge of identity and access governance tooling (e.g., SailPoint, Saviynt, Oracle IAM, or SAP GRC Access Control) sufficient to direct specialist work and assess SoD remediation quality.
  • Demonstrated judgment in escalating control deficiency findings knowing when and how quickly to surface issues to leadership, distinguishing reportable conditions from items appropriate for management remediation.
  • Ability to influence and drive accountability across functions without direct authority securing buy-in from Engineering, Legal, and Finance stakeholders on control design, evidence timelines, and remediation commitments.
  • Experience with control automation and continuous monitoring techniques, including data analytics tools (e.g., ACL, IDEA, or SQL-based queries) for automated control testing and exception identification.
  • Proficiency in control documentation standards: authoring and reviewing control narratives, risk-and-control matrices (RCMs), and process flow diagrams to a level that satisfies Big 4 audit scrutiny.
  • Familiarity with data privacy and regulatory frameworks adjacent to SOX (e.g., GDPR, CCPA, FCC/FTC requirements) and their potential impact on IT control scope and evidence handling.
  • Familiarity with DevSecOps pipelines, CI/CD tooling, and change management control validation in automated deployment environments .
  • Demonstrated practice of succession planning and team depth-building for a function where key-person risk during audit cycles can be acute.
  • DevSecOps pipelines, CI/CD tooling

PREFERRED QUALIFICATIONS:

  • CISA, CISSP, CISM, CIA, or CPA certification (one or more preferred).
  • Experience in telecom, retail, or large-scale supply chain environments.
  • Familiarity with DevSecOps pipelines, CI/CD tooling, and automated control testing.
  • Exposure to third-party risk management (TPRM) and vendor compliance programs.
  • Experience supporting SOX readiness for newly acquired entities or greenfield system implementations.
  • Working knowledge of cloud control frameworks (AWS, Azure, GCP) and their intersection with SOX ITGC scope.
  • Lead SOX scoping, walkthroughs, testing execution, and remediation tracking across IT General Controls (ITGCs) and Application Controls for Oracle, SAP, and Java platforms.
  • Manage a team of 612 GRC analysts and ITGC specialists; set priorities, conduct performance reviews, manage hiring and headcount planning, and develop talent through coaching and stretch assignments. Explicitly includes workload balancing across varying IC skill levels (junior analysts through senior ITGC specialists) during peak audit periods.
  • Own the GRC program lifecycle: risk assessments, control design, evidence collection, deficiency management, and continuous monitoring.
  • Serve as primary liaison for external auditors (Big 4), Internal Audit, and enterprise risk functions during quarterly and annual audit cycles.
  • Partner with Oracle, SAP, and application engineering teams to design and validate automated controls, access governance, and change management processes.
  • Maintain and improve the GRC platform (e.g., AuditBoard, ServiceNow GRC, or equivalent); drive adoption and reporting automation.
  • Produce executive-level reporting on control health, open findings, and remediation SLAs for VP and C-suite stakeholders.
  • Drive policy and standards development; ensure alignment with COSO, COBIT, NIST, and applicable regulatory frameworks.
  • Identify and escalate emerging compliance risks related to system changes, vendor integrations, or new platform deployments.
  • Support M&A integration activities and new system implementations from a controls and compliance perspective.
  • Own SOX program management end-to-end: maintain the control inventory, govern the annual audit timeline, track cross-functional dependencies, and enforce milestone accountability. This role manages a program at scale, not only a team.

Skills

See also

Management jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available