Governance, Risk, and Compliance Senior Associate, IT Controls & Assurance
$82k - $100kWeaver
Governance, Risk, and Compliance Senior Associate, IT Controls & Assurance Job Category : Advisory Requisition Number : GOVER003160 Posted : August 18, 2026 Full-Time Locations Showing 1 location New York, NY Description The Weaver Experience Weaver is a full-service national accounting, advisory and consulting firm with opportunities for professionals in many different fields. We seek to bring a human element to the world of accounting, which includes creating a diverse, collaborative, and entrepreneurial workplace culture. Our leaders truly care about the well-being of all our employees and encourage them to pursue their ambitions. While our business is based in numbers, our success is truly based on people. It’s why we commit to supporting our people not just in their professional growth, but also in their ability to lead balanced, integrated lives. At the foundation of that commitment areour core values .Weaver’s core values were created specifically to empower our people to deliver extraordinary service and be their best selves. Our goal is to balance high development with high performance in order to meet the long-term goals of each individual, team, and our firm. Learn more about our services, industry experience and culture atweaver.com . Position Profile Weaver is seeking a Senior Associate to join our Governance, Risk, and Compliance (GRC) practice with a primary focus on IT controls and technology assurance. This role will support a balanced portfolio of System and Organization Controls (SOC) 1 and SOC 2 examinations, IT-related Sarbanes-Oxley (SOX) compliance engagements, and other information security and compliance projects as client needs arise. The GRC IT team works with technology, information security, finance, internal audit, and business stakeholders to evaluate controls, communicate practical recommendations, and deliver high-quality client service. Team members gain exposure to a variety of industries, technologies, control environments, and regulatory expectations while developing both technical and engagement-management skills. The Senior Associate is responsible for leading assigned workstreams and supporting the planning, execution, supervision, and completion of engagements. The ideal candidate combines sound professional judgment, strong IT controls knowledge, willingness to test or review lower risk non-IT controls, clear communication, and the ability to manage multiple concurrent assignments while coaching junior team members. What You Will Do Execute and help manage SOC 1 and SOC 2 Type 1 and Type 2 examinations, including planning, walkthroughs, risk assessment, control evaluation, testing, documentation, issue evaluation, and report support. Perform IT SOX work over in-scope systems and processes, including IT general controls, automated controls, key reports, interfaces, and other technology-dependent controls relevant to internal control over financial reporting. Experience developing and maintaining risk and control matrices (RCMs) during engagement planning, including documenting processes, identifying relevant risks, mapping controls to risks and engagement objectives, and defining appropriate control testing procedures. Evaluate control design and operating effectiveness across logical access, change management, computer operations, cybersecurity, incident management, business continuity, vendor management, and related domains. Develop and review process narratives, system descriptions, risk and control matrices, test plans, workpapers, evidence requests, and client-ready deliverables. Identify exceptions and control gaps, assess their significance, and communicate clear, practical recommendations to engagement leadership and client stakeholders. Coordinate day-to-day client requests, monitor engagement status and budgets, elevate risks promptly, and help keep concurrent projects on schedule. Supervise and coach Associates by reviewing workpapers, providing timely feedback, and reinforcing firm methodology and quality expectations. Support other technology risk, information security, and compliance engagements as business needs arise, which may include readiness assessments, internal audit, regulatory compliance, or controls advisory projects. Contribute to practice development through methodology improvements, knowledge sharing, proposal support, and participation in recruiting and team initiatives. To be successful in this role, the following qualifications are required: Bachelor’s degree in Accounting, Management Information Systems, Computer Science, or related field 2+ years of experience in professional services or similar field Working knowledge of SOC reporting concepts and applicable attestation standards, including experience supporting SOC 1 and/or SOC 2 engagements Understanding of SOX Section 404, internal control over financial reporting, and how technology risks and controls affect financial reporting Ability to understand business and financial reporting processes, identify relevant technology risks, and connect IT controls to business, reporting, and security objectives Experience reviewing workpapers and supervising, coaching, or informally leading junior team members Strong written and verbal communication skills, including the ability to explain technical control matters to both technical and nontechnical stakeholders. Strong organization, attention to detail, professional skepticism, and the ability to manage multiple priorities and deadlines Ability to appropriately use firm-approved AI and automation tools to improve engagement efficiency, research, documentation, and data analysis while maintaining confidentiality, professional judgment, quality-control requirements, and compliance with firm policies Ability to travel to client locations or Weaver offices as engagement needs require. Additionally, the following qualifications are preferred: CISA, CPA, CIA, CISSP, CISM, or another relevant certification, or demonstrated progress toward certification Awareness or exposure to relevant frameworks and criteria such as NIST, ISO/IEC 27001, HITRUST, PCI DSS, and other security or compliance standards Experience with audit and GRC platforms such as Fieldguide, AuditBoard, Workiva, Drata, Vanta, or similar tools Experience serving clients in financial services, technology, insurance, healthcare, or other regulated industries. Compensation and Benefits : At Weaver, our most valuable resources is our people. We take the time to evaluate our employees' wants and needs and invest our resources accordingly. A reasonable estimate of the compensation range for this position is $82,000 to $100,000. Actual compensation will be based on a variety of factors including but not limited to experience, skills, certifications, and geographical location. In addition to compensation packages, Weaver offers competitive health benefits, such as medical, dental, vision, disability, life insurance, and a 401(k) plan. Further, we support our employees by offering flexible scheduled time off (STO), minimum of 56 hours of sick and safe leave, 11 holidays, and 2 scheduled recharge days! Learn more here - Weaver benefits . We also offer in-house CPE and learning opportunities through our internal Learning & Development department. Our multi-faceted internal learning program including technical improvement, practice development, management/leadership training, and whole-life growth. Our goal is to balance both high development with high performance to meet the long-term goals of each individual, team, and our firm. People are our formula! At Weaver, we recognize that everyone brings different strengths, backgrounds, and working styles to our team. We cultivate a safe and inclusive work environment that celebrates each individual’s unique qualities through visibility, progression, advocacy, and support. We are proudly an equal opportunity employer. This role is Employee Referral Program eligible. Equal Opportunity Employer This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor. #J-18808-Ljbffr Weaver
- ...dynamic team to navigate complex risk landscapes and fortify technology governance, making a pivotal impact in... ...risk strategy.As a Tech Risk & Controls Senior Associate in Cybersecurity & Tech... ...aspects of Governance, Risk, and Compliance in line with the firm's standards...Senior
- Medasource is seeking an IT GRC Analyst to join our IT Security and Governance team on a 6-month contract-to-hire basis,... ...security governance, regulatory compliance, risk management, audit readiness, policy administration, and control monitoring for a healthcare organization...SuggestedRemote jobContract work
- Nelnet is seeking a senior IT Risk Manager to lead information security risk initiatives, coordinate risk assessments and audits, and drive remediation and internal controls across IT, security, audit, and compliance teams. The role emphasizes collaboration with stakeholders...SeniorWork at officeRemote work
$100k - $155k
...cybersecurity starts with you. About the Role: The Senior Governance, Risk, and Compliance Specialist is tasked with providing assurance and automation of CrowdStrike’s global... ...automation solutions that integrate controls across our systems and processes. This role...SeniorRemote jobWork experience placementWork at officeLocal area- ...Risk Consulting - Risk Technology - Sap Grc & Security - Senior ConsultantLocation: New York Other locations: Anywhere... ...rapid growth across SAP and Governance, Risk, and Compliance (GRC), EY is seeking SAP... ...Security and SAP GRC Access Control solutions across SAP environments...SeniorShift work
- CrowdStrike is seeking a Senior Governance, Risk, and Compliance Specialist to drive assurance and automation of our global compliance program. You will lead audit... ...compliance activities, build scalable automation for controls, and collaborate with teams to strengthen our...Senior
- ...clients. Payward's Global Compliance team is the regulatory... ...design, deployment, governance, and capability... ...high-quality, repeatable risk insights for Compliance... ...documented data flows, access controls confirmed, and... ...role with demonstrated senior-level execution....SeniorLocal area
$102.4k - $199.7k
...Nuclear Enterprise Assurance (NEA) Team... ..., and risk‑informed engineering... ...technical and senior stakeholders;... ...architectures; develop associated verification... ..., assess control and process‑protection... ...another U.S. government agency (e.g.,... ...to ensure compliance with NNSA...SeniorPart timeRemote workWork from homeWorldwideRelocation packageFlexible hours$84k - $118.11k
...advisory, tax and assurance firm, providing... ...in the areas of risk and advisory? If... ...Consumer Regulatory Compliance Senior Consultant! Our Risk... ...of risk, governance and regulatory compliance... ..., and internal controls. You crave the... ...compliance risks associated with areas such as...SeniorWork experience placementLocal areaWorldwide- ...Job Title: IT Compliance Analyst Location: Tempe, AZ Division: Operations... ...ensure the processes and associated controls for the compliance... ...reduce overall compliance risk across the organization. This... ...the evaluation, testing, and assurance criteria for security architectures...Remote work
- Endologix is seeking a Sr. Design Assurance Engineer in Eden Prairie, MN to drive design control, V&V, and risk management across flagship product lines. You will own design history files, support regulatory submissions, and collaborate with R&D and manufacturing to ensure...Senior
- ...program. Position Overview: The Senior Compliance Systems Analyst supports... ...disclosures, documents, and related controls. Conduct first-pass... ...leadership regarding status, issues, risks, and recommendations for... ..., legal support, quality assurance, or a related field....SeniorTemporary work
- ...Charlottesville, VA seeks a Principal Quality Assurance Engineer to lead quality activities... ...supplier quality, validations, design controls, and risk management while mentoring QA staff... ...and operations. You will ensure compliance with regulatory requirements, perform...Senior
$110k - $190k
...role provides senior level support to... ..., US Functions IT, as well as Managing... ..., objective assurance over the design... ...IT and Data Governance practices, governance... ...of internal controls. It supports... ...related continuous risk monitoring,... ...Management and Compliance).Accountable to...SeniorFull timeFlexible hoursShift work- Medasource is seeking an IT GRC Analyst to join the IT Security and Governance team on a 6-month contract-to-hire basis, remote within the USA. The role focuses on governance, risk, and compliance across HIPAA, SOC 2, and NIST, collaborating with IT, Security, Privacy,...Remote jobContract work
- ...Job Description Job Title: QA Lead / Senior Quality Assurance Engineer Location: NJ or STL (Hybrid... ...test coverage. Establish and govern QA processes, standards, and best practices... ...LoadRunner. ~ Knowledge of version control systems, particularly Git . ~...SeniorContract work
- Euronet is seeking a Compliance Controls & Quality Assurance Officer to join its Compliance team in Athens. You will enhance monitoring, quality assurance, governance, and risk assessment across an international payments environment, ensuring high standards of compliance...
- ...requirements and changes to data sources to ensure timely regulatory compliance.· Review Federal Reserve SR letters to ensure compliance... ...strong collaborative relationships with Business Unit Controllers, data providers, and the Information Technology Group to ensure...SeniorWork at office
- ...Marmon Holdings, Inc. through MicroAire Surgical Instruments LLC is seeking a Principal Quality Assurance Engineer. This senior role leads QA for new medical devices and supports existing products, coordinating CAPA, audits, and supplier quality while mentoring QA staff...Senior
$119k - $218.3k
Position Summary Senior Consultant - Risk, Regulatory, & Licensing - Digital... ..., design, and deploy controls across the digital asset... ...up-to-date perspectives on compliance obligations and industry best... ...lifecycle events, and associated process flows.Deep understanding...SeniorWork at office$97.9k - $179.5k
...change comes risk. As a Risk Technology... ...and process controls transformation... ...integrity, governance, risk, and... ...monitoring, and IT risk management... ...Governance, Risk and Compliance (GRC) space,... ...motivated Senior Associate, focused on... ...of services in assurance, consulting, tax...SeniorWork experience placementSummer holidayFlexible hours- Capital One seeks a Principal Analyst in Capital Markets & Risks in McLean, VA to lead SOX advisory and end-to-end risk... ...executives to identify risks and remediation actions, driving control improvements and governance across financial reporting. The role requires 3+ years in...Senior
- ...impact every day. About The Role We are seeking a Senior Compliance Specialist to strengthen and protect our controlled substance compliance program through Customer... ...activities. In this role, you'll evaluate customer risk, conduct investigations, support regulatory...SeniorTemporary workRemote work
- ...multidisciplinary R&D Systems Security Engineer for the Nuclear Enterprise Assurance program, to lead secure product realization for high-... ..., hardware, software, cybersecurity, and counterintelligence to mitigate subversion risks and #J-18808-Ljbffr Koitecc SolutionsSenior
- Farmers Group Inc. seeks an Internal Controls Testing Manager - IT to lead IT controls testing, drive MAR/SOX compliance, and manage a team of testers and auditors. The role... ...financial controls. A strategic partner to senior leadership, you will shape testing strategy...Senior
- Ahold Delhaize USA is seeking a Senior Manager, Governance & Controls to lead the design, execution, and evolution of the finance and ESG control environment. You will partner with external auditors and senior leadership to strengthen controls, improve audit efficiency,...Senior
$55 - $80 per hour
...IT GRC Analyst Remote, USA Compensation... ...care services to seniors across assisted... ...IT Security and Governance team on a 6-month... ...s IT Governance, Risk, and Compliance (GRC) program, focusing... ..., and control monitoring. This... ...planning, testing, and associated governance activities...Hourly payFull timeContract workWork at officeImmediate startRemote workFlexible hours- Jobtailor, based in the United States, seeks a senior accounting professional to oversee all aspects of financial reporting, controls, and governance. This role ensures accuracy and... ...reconciliations, and guides regulatory compliance and technical accounting positions. You...Senior
- ...coordinates with engineers, clients, construction managers, subcontractors and vendors to deliver automation systems across multiple controllers, HMIs, workstations and servers. You will lead design phases from programming through construction administration, mentor junior...SeniorFor subcontractor
- Fidelity is seeking an Audit Senior Analyst to join the Risk Management team. This role is onsite in Covington, KY, Merrimack, NH, or Smithfield,... ...Fidelity Corporate Audit to drive improvements in internal controls and business performance. Ideal candidates have 3-5 years...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Governance, Risk, and Compliance Senior Associate, IT Controls & Assurance. Be the first to apply!
- risk consultant Brooklyn, NY
- risk analyst Brooklyn, NY
- senior quantitative risk analyst Brooklyn, NY
- operational risk consultant Brooklyn, NY
- it risk analyst Brooklyn, NY
- risk officer Brooklyn, NY
- third party risk analyst Brooklyn, NY
- transaction risk analyst Brooklyn, NY
- operational risk specialist Brooklyn, NY
- hr compliance coordinator Brooklyn, NY


