Why This Role Stands Out
This hybrid role at SilverSearch, Inc. offers you the chance to significantly impact technology compliance and control programs, enhancing your expertise in SOX ITGC and PCI DSS. You'll thrive here if you are a proactive leader ready to manage compliance end-to-end and drive improvements within a reputable enterprise.
Quick Overview
Job Description
Job Description:
We are seeking an experienced Compliance Manager to lead key technology compliance and control programs within a complex enterprise environment. This position will have significant ownership of SOX IT General Controls (ITGC) and PCI DSS compliance, partnering across Technology, Information Security, Internal Audit, external audit teams, and business stakeholders.
This is a hands-on leadership role for someone who can manage compliance programs end-to-end while also improving the underlying control environment. The successful candidate will be comfortable evaluating controls, identifying gaps, coordinating audits and assessments, driving remediation, and communicating risk and compliance status to senior stakeholders.
Key Responsibilities
- Lead and manage the SOX ITprogram, including control design reviews, testing activities, evidence coordination, deficiency management, and remediation.
- Own key aspects of the PCI DSS compliance lifecycle, including scoping, gap assessments, evidence gathering, control validation, and annual assessment activities.
- Coordinate directly with external auditors and third-party assessors, managing walkthroughs, documentation requests, testing evidence, and issue resolution.
- Develop and maintain risk-control matrices, control narratives, policies, procedures, and supporting compliance documentation.
- Partner with technology, security, engineering, and business teams to identify control weaknesses and establish practical remediation plans.
- Track audit and compliance findings through resolution and ensure corrective actions are completed within agreed-upon timelines.
- Evaluate changes to regulatory requirements and industry standards and determine their impact on existing controls and processes.
- Support broader Governance, Risk & Compliance (GRC) activities, including risk assessments, policy management, and third-party/vendor compliance.
- Provide leadership with clear reporting on compliance status, outstanding risks, audit findings, and remediation efforts.
- Help improve compliance processes through better tooling, reporting, standardization, and appropriate automation.
- Provide guidance and mentorship to other members of the compliance and governance organization.
Required Qualifications
- Bachelor's degree in Information Systems, Information Security, Accounting, Business, or a related discipline, or equivalent relevant experience.
- 5+ years of IT compliance, technology risk, IT audit, information security governance, or related experience.
- Demonstrated hands-on ownership of SOX ITand PCI DSS compliance programs.
- Strong understanding of SOX 404, IT General Controls, and COSO-based control environments.
- Practical experience with PCI DSS assessments, including scoping, evidence gathering, gap identification, remediation, and working with external assessors/QSAs.
- Experience managing or coordinating external audits from planning and walkthroughs through findings and remediation.
- Ability to evaluate technical control issues and clearly communicate their associated business and compliance risks.
- Strong documentation skills with experience developing control narratives, risk-control matrices, policies, and procedures.
- Strong stakeholder management skills and the ability to work effectively across technical, audit, security, and business teams.
- Experience with a GRC or audit management platform such as ServiceNow GRC, Archer, AuditBoard, or a comparable solution.
- Strong written and verbal communication skills, including the ability to communicate effectively with senior leadership.
Preferred Qualifications
- Professional certification such as CISA, CISSP, CRISC, PCIP, or a related credential.
- Experience supporting compliance within a large enterprise, regulated organization, or public-company environment.
- Exposure to additional frameworks such as SOC 2, ISO 27001, or NIST CSF.
- Understanding of cloud control environments, particularly AWS, and how cloud services intersect with SOX and PCI requirements.
- Experience improving or automating compliance testing, evidence collection, control monitoring, or reporting processes.
Similar jobs
- BN
Vice President, Compliance & Control (Ethics Office)
BNY
Pittsburgh, PA🇺🇸Hybrid7 weeks agoComplianceEmployee RelationsRisk Management - LE
Air Force Cryptologic & Compliance Analyst
NewLeidos
Odenton, MD🇺🇸$73.5k - $132.8k/yrHybridYesterdayComplianceHTTPSRecruitingTechnology - HD
Compliance Specialist
NewHinderliter de Llamas & Associates
Winston Salem, North Carolina🇺🇸$18 - $20/hrHybrid3 hours ago401kHuman Resources - RC
Compliance Manager
NewRoers Companies LLC
Phoenix, Arizona🇺🇸$93.1k - $122.5k/yrHybrid3 hours agoComplianceContinuous ImprovementOnboarding+6 - CE
Senior Compliance Manager
NewCerapedics Inc
Broomfield, Colorado🇺🇸$146k - $211k/yrHybrid3 hours ago401kHuman Resources - KO
Sr. Compliance Engineer
NewKohler
Kohler, WI🇺🇸$92.4k - $141k/yrOn-siteYesterdayEngineering