IT Domain GRC Specialist handling IT controls in Back Office domain across Oracle ERP SaaS. Collaborating with Finance, HR, and GRC stakeholders to ensure SOx compliance and risk management.
Responsibilities
Define, implement, and ensure the effective operation of IT controls within the Back Office domain
Collaborate with Finance, HR, Business Owners, and multiple GRC stakeholders
Document control designs for Back Office processes
Coordinate and support Control Operators in maintaining structured, accurate evidence for control effectiveness
Project‑manage dependencies across teams
Strengthen RBAC structures by reviewing roles, permissions, and access levels
Define cybersecurity and data-protection requirements for Back Office systems
Support readiness and response efforts for cybersecurity incidents
Identify, mitigate, and monitor cybersecurity risks related to Back Office activities
Guide teams on Secure Development Lifecycle (SDL) practices
Measure compliance with IT policies, set KPIs, identify gaps, and lead corrective initiatives
Prepare documentation for internal and external audits
Ensure SOx compliance through timely evidence collection
Requirements
ISACA (or equivalent) qualification such as CISA, CISM, or CGEIT
Minimum 2 years’ experience in IT control design, assurance, or auditing
Experience documenting and presenting control recommendations to management
Experience estimating remediation costs and distinguishing between one-off vs recurring expenses
Experience collaborating with external and internal auditors, with solid understanding of SOx compliance and Crown Jewel asset protection
Hands-on experience with Oracle ERP SaaS, including implementing controls for financial and operational processes
Strong proficiency in documenting risk and control mappings for audit review
Ability to map business processes, system workflows, and RBAC structures
Strong MS Office skills, especially Excel, PowerPoint, Outlook, and SharePoint
Head of Risk & Regulatory Compliance leading risk management and compliance in Meruriyo’s Croatian entity. Ensuring alignment with EU regulatory requirements for crypto - asset services.
Regulatory Compliance Manager overseeing compliance matters for a leading international financial institution. Ensuring alignment with regulatory requirements across corporate and investment banking businesses in an international environment.
Investigator managing compliance with Oregon’s Government Ethics laws for the Oregon Government Ethics Commission. Conducting investigations, drafting reports, and providing legal advice to public officials.
Compliance Manager overseeing regulatory audits and compliance projects at Elevance Health. Ensuring adherence to regulations and managing audits while collaborating with various stakeholders.
Senior Manager guiding compliance for CVS Health's regulatory inquiries. Leading market conduct exams and driving action plans across the organization.
Director of Compliance Operations ensuring AltaLink's compliance with Alberta standards and regulations. Leading a team to manage corporate compliance activities effectively.
IT Risk and Compliance Senior Specialist at GDIT managing security for cloud and on - premises systems. Collaborating with stakeholders and developing security documentation while ensuring compliance with regulations.
Manager for Portfolio Compliance overseeing investment compliance and regulatory guidance in New York at AustralianSuper. Leading compliance monitoring and governance for investment activities.
Export Compliance Manager overseeing export compliance programs and processes. Ensuring alignment with global regulatory requirements while partnering with leadership to minimize risks in international trade.