Director, IT Governance, Risk & Compliance
CMC Rebar
it's what's inside that counts
_______________________________
There’s more to CMC than our products and the buildings, structures, and roads they go into. At CMC, it’s the people inside our recycling centers, fabrication plants, manufacturing facilities, steel mills and offices that make us who we are as a company. Our success comes from finding, retaining, and supporting the highest quality talent by offering:
- Day 1 Benefits Coverage with low cost Medical, Vision, Dental
- Day 1 Paid-time Off and Vacation
- 4.5% Company Match 401(k) plan
- $500 Annual Company-paid Lifestyle Benefit
- Competitive Compensation and Bonuses
- Company-paid Life and Disability Insurance
- Employee Stock Purchase Plan
- Training and Advancement Opportunities
Why This Job
CMC provides an excellent opportunity to learn the steel, construction reinforcement and ground stabilization industries and to grow in your career. Whether you will spend your day brainstorming in an office cubicle, operating a crane, running manufacturing equipment or troubleshooting technical obstacles, at CMC, you’ll get the training and support from your team that you need to excel in your role and reach your full potential.
What You'll Do
- Lead the continued maturation of CMC's IT Governance, Risk & Compliance program and define the next phase of its maturity strategy
- Establish consistent governance standards, accountability models, decision rights, and control ownership across technology functions
- Strengthen control design, policy management, compliance monitoring, and standard artifacts, with rigor proportionate to financial, regulatory, cybersecurity, and operational risk
- Drive alignment among business objectives, technology strategy, compliance requirements, and risk management priorities
- Promote a culture of accountability, operational discipline, and continuous improvement in which compliance is embedded in day-to-day delivery
- Serve as the primary IT leadership interface for Internal Audit, external auditors, and compliance stakeholders
- Improve audit readiness through standardized evidence management, documentation practices, remediation governance, control monitoring, request intake, and clear closure criteria
- Partner with technology and business leaders to proactively address audit findings, improve evidence quality, and reduce recurring deficiencies and late-cycle surprises
- Provide executive-level insight on governance maturity, compliance performance, control effectiveness, remediation aging, evidence quality, and emerging risk
- Ensure compliance activities improve operations and control effectiveness rather than simply satisfy audit requirements, while maintaining the distinction between management ownership and independent assurance
- Oversee ITGC and SOX compliance across access management, change management, computer operations, interfaces, key reports, and technology-dependent controls
- Establish and execute annual approach to IT SOX scoping in collaboration with Internal Audit and management stakeholders
- Direct governance for SAP access, segregation of duties, privileged access, Firefighter / emergency access, user access reviews, and SAP GRC capabilities
- Establish a risk-based method to prioritize deficiencies by financial reporting exposure, regulatory impact, cybersecurity risk, and operational complexity
- Partner with IT, Finance, Internal Audit, Cybersecurity, and business stakeholders to support effective governance, compliance, and control execution
- Support business units and control owners in identifying IT control gaps
- Provide training and guidance to IT control owners and business unit managers on SOX requirements, control objectives, and best practices
- Implement a repeatable evidence operating model with standardized repositories, request ownership, naming conventions, quality checks, retention requirements, and closure criteria
- Drive timely, sustainable remediation of deficiencies and validate that corrective actions are designed, implemented, documented, and testable
- Establish dashboards and metrics that show control effectiveness, exceptions, remediation progress, audit demand, and recurring failure patterns
- Identify opportunities to automate controls, evidence collection, access reviews, monitoring, and reporting through SAP GRC and other enabling technologies
- Use lessons learned from audits and control failures to improve processes, training, system design, and accountability
- Work with management to evaluate control evidence against quality standards prior to submitting it to auditors
- Identify control deficiencies and recommend remediation plans in collaboration with Internal Audit
What You'll Need
- 12+ years of progressive experience in IT audit, technology risk, governance, compliance, cybersecurity assurance, or related disciplines, including at least 5 years leading managers or senior professional teams
- Proven experience leading and maturing an IT audit, technology compliance, governance, or technology risk organization within a large, complex enterprise
- Prior Big 4 public accounting or external audit experience serving large companies is strongly preferred, with direct responsibility for IT audit, SOX ITGC, controls assurance, or technology risk engagements
- Deep knowledge of SOX ITGCs, control design and testing, risk assessment, deficiency evaluation, remediation, audit evidence, and management reporting
- Strong working knowledge of enterprise applications and infrastructure controls, including SAP security, segregation of duties, privileged access, change management, computer operations, interfaces, and key reports
- Demonstrated success improving audit readiness, strengthening control environments, reducing repeat findings, and advancing compliance program maturity beyond tactical audit response
- Executive-level communication and stakeholder management skills, including the ability to influence across IT, Finance, Internal Audit, external auditors, and business leadership
- CISA certification strongly preferred. CPA, CIA, CRISC, or other relevant certification is a plus
- Experience with SAP S/4HANA, SAP GRC, ServiceNow GRC / IRM, Workiva, Archer, MetricStream, or comparable governance and compliance platforms
- Knowledge of commonly used frameworks and requirements such as COBIT, COSO, NIST CSF, ISO 27001, SOC reporting, CMMC, NIS2, and AI governance
Your Education
- Bachelor's degree in Information Systems, Accounting, Finance, Cybersecurity, Business, or a related field. MBA preferred
We are CMC, a Fortune 500® company at the leading edge of our industry. Our construction reinforcement and steel products have supported construction projects and structures around the world. The secret to our success? We’ve built our legacy by assembling a team of innovators and doers to tackle some of the most challenging construction reinforcement problems facing our world for more than 100 years — and we’re just getting started.
If you’re ready to join a team working to make our industry more sustainable, support the bridges, roadways, buildings and infrastructure that connects our communities, and do meaningful work, you’re ready to join CMC. Apply today and start moving your career — and our world — forward. Let's build a better world!
CMC is committed to providing equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, age, physical or mental disability, national origin, citizenship, military or veteran status, sexual orientation, gender identity and/or expression, genetic information, or other status protected by federal, state or local law.
From Fortune Magazine. © 2025 Fortune Media IP Limited. All rights reserved. Used under license.
$119.77k - $140.9k
...outcome-based product roadmap, product risk, investment areas and success measures.Drives... ...debt reduction, defect remediation, governance needs, and operational stability.Lead enterprise... ...data quality, lineage, controls, and compliance.Drive proactive risk management by...SuggestedFull timeWork at officeLocal area3 days per week$104.9k - $199.07k
...employee-owned consultancy providing actuarial consulting, retirement funding and healthcare financing, enterprise risk management and regulatory compliance, data analytics and business transformation as well as a range of other consulting and technology solutions....SuggestedFull timeWork experience placementRemote workFlexible hours- ...training efforts on how to accurately interpret and use the resultsCollaborate closely with audit methodology specialists, risk, and compliance teams to ensure all AI evaluation flows, metrics, and guardrails actively support firm audit quality standardsAct with integrity...SuggestedH1bLocal area
- US Anesthesia Partners is seeking a Director of Financial Reporting & Technical Accounting to lead the company’s consolidated reporting, disclosures, and technical accounting governance. You will drive audit readiness, policy development, and process improvements across...Suggested
- Company DescriptionSonsoft , Inc. is a USA based corporation duly organized under the laws of the Commonwealth of Georgia. Sonsoft Inc. is growing at a steady pace specializing in the fields of Software Development, Software Consultancy and Information Technology Enabled...Suggested
$170k - $300k
...consumers, corporations, governments, and institutions with... ...Regulatory Reporting. It also drives the modernization... ...- Fraud Domain (Director, C15) is a senior technology... ...across architecture, risk, and controls, bringing... ...Operations, Risk, and Compliance leads to translating...Full timeWork at office- ...installation procedures, troubleshooting guides, and safety protocols for internal teams and external customersCreate, update, and govern technical documentation and learning content to ensure accuracy, version control, accessibility, consistency, and alignment with current...Permanent employmentWork at officeImmediate start
- ...operations in Dallas, TX. This executive role combines strategic oversight with hands-on leadership of origination, servicing, risk management and compliance. The SVP will drive process improvements, technology adoption, and staff development while building strong...
- Technical Engagement Coordinator for a team working on CICD, DevOps, Chef and Ansible Development etcManaging client relationship, reporting and governanceShould possess excellent experience and awareness of Citi working environment. Someone with experience of managing ...
$124.36k - $146.3k
...stakeholders to shape outcome-based product roadmap, product risk, investment areas and success measures.-Drives product... ...priorities-Coordinate with Security, Risk, Audit, and Compliance teams to meet governance and regulatory requirements. -Support platform modernization...Full timeLocal area3 days per week- Job-ID27738195Reference26-06905 Technical Product Manager - Digital Profile Management Credit/Debit Cards Role Summary The Technical Product Manager (TPM) is part of an agile journey team and partners with the Business Line Product Manager to define success, measure outcomes...Work at office3 days per week
- ...and exploring innovative ways to do the job. Willingness to consider change and to adapt. Participates and partners with Divisional Directors, Customer Service Technicians, Account Executives and Operations Manager on customer meetings to promote revenue growth, cost...Daily paidFull timeContract workTemporary workWork at officeLocal areaFlexible hoursAfternoon shift
- ...KPMG is currently seeking a Director, Private Equity IT M&A –Due Diligence and... ...analysis, identify keytechnology risks, value creation levers,... ...; establish and manage governance frameworks forvalue creation... ...regarding KPMG's compliance with federal, state and local...Full timeH1bLocal area
$191.14k - $370.99k
...KPMG is currently seeking a Director, IT TMT M&A - Due Diligence, Integration... ...; identify key IT risks, opportunities, and investments... ...and manage program governance frameworks, ensuring rigorous... ...information regarding KPMG's compliance with federal, state and local...Full timeH1bLocal area$120k - $167k
...Centers of Excellence, with a hybrid work environment.About Gartner IT:Join a world-class team of skilled engineers who build creative... ...project leadership, adept at Product Backlog Refinement, Risk Management, Stakeholder Management, Agile Team Building across multiple...Full timeApprenticeshipImmediate startWork from homeWorldwide- ...project management, business analysis, backlog governance, quality assurance coordination, and AI-... ...business and technology solutions. It sits at the critical connection point between... ...updates to ensure milestones are met and risks are mitigated Establish and evolve Agile...Casual workWork at officeWork visa
- ...The Director, Employment & Labor Compliance leads the company's strategy for employment law compliance across... ...laws, minimizes legal and financial risk, and builds compliance programs suited... ...Compliance Strategy & Governance Develop and maintain the company's...Minimum wageContract workLocal area
- ...roadmap, scope, milestones, dependencies, risks, and issues Coordinate Engineering,... ...cross-functional resolution Manage program governance, resources, timelines, and stakeholder communications... ...Ensure delivery meets security, compliance, quality, and regulatory requirements...Full timeImmediate start
- ...interconnectivity. Define API contracts and authentication mechanisms for automated provisioning and multi-vendor orchestration. Ensure compliance with TMF-compliant APIs and industry standards. 3. Product Execution & Delivery Oversee end-to-end feature execution, ensuring...Work from homeFlexible hours
$204.44k - $324.99k
...Advisory. KPMG is currently seeking a Director in Technology for our Consulting... ...guardrails, including accuracy, hallucination risk, data access, human-in-the-loop controls... ...using REST/SOAP web services, and ensure compliance with HIPAA, HITRUST, and other...Full timeH1bLocal area$128k - $245k
...and a minimum of three days per week in the office, which will be set by your manager. Employees are responsible for maintaining compliance with hybrid work policies.Scheduled Weekly Hours40Equal Employment OpportunityVerizon is an equal opportunity employer. We evaluate...Full timeTemporary workPart timeWork experience placementWork at officeWork from homeShift work3 days per week$75k - $95k
...planning, execution, monitoring, and delivery of technical programs and projects. Define program goals, scope, milestones, dependencies, risks, and success metrics. Develop and maintain integrated project schedules, roadmaps, and release plans. Coordinate cross-functional...- ...vendors including planning, execution, and successful delivery for Fraud Book Of work Identify, assess, track, and mitigate issues and risks at multiple levels by establishing success metrics Guide stakeholders and engineering teams in making informed trade-off decisions,...
- ...coordinate cross-functional programs, manage dependencies and risks, and ensure successful delivery of AI/ML and Generative AI solutions... ...timely delivery of program milestones. Establish program governance, status reporting, communication plans, and executive-level...3 days per week
- ...Accreditation Readiness Behavioral Health Compliance Efficiency and Effectiveness... ...Life Safety Infection Prevention Risk Management Regulatory Auditing Policy... ...surveys State licensing inspections Governing Body reporting Requirements: Required...For contractorsWeekend workAfternoon shift
$137.13k - $172.87k
Blue Yonder Job Title:Director, Indirect TaxLocation:US-RemoteDallas or Scottsdale... ...indirect tax reconciliations, tax engine governance, and related compliance processes.This is a hands-on... ...leadership, Tax Technology, Finance, IT, Revenue, Billing, Procurement, local...Full timeLocal areaRemote workFlexible hours$156.36k - $296.88k
...communities.The RoleJoin Kyndryl as a Director of AI Governance you will unlock the power of data to drive... ...gain valuable insights and manage the compliance of important AI capabilities.Data & AI... ..., and access control. Compliance & Risk Management: Partner with the Chief...Minimum wageFull timeLocal area- Pioneer your career! Körber is the home for passionate people who innovate, collaborate and love what they do. Entrepreneurial spirit is our joint DNA. We develop future technologies and support talents to deploy their skills and reach their full potential. Together, we...Permanent employmentFull timeImmediate startVisa sponsorshipWork visa
- ...industry-specific requirements:Financial Services: security, compliance, auditabilityCommunications: real-time processing, high availabilityMarTech... ...decisions across teams without formal authority5. Standards, Governance & Continuous ImprovementEstablish and enforce architecture...Full time
- ...Manufacturing teams. Track RFQs, quotations, samples, design-ins, qualifications, wins/losses, an production ramps and communicate risks or changes to management. Product & Technical Scope The role may support a broader portfolio of thermal-management and...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, IT Governance, Risk & Compliance. Be the first to apply!




