Director, IT Governance, Risk & Compliance
CMC Rebar
it's what's inside that counts
_______________________________
There’s more to CMC than our products and the buildings, structures, and roads they go into. At CMC, it’s the people inside our recycling centers, fabrication plants, manufacturing facilities, steel mills and offices that make us who we are as a company. Our success comes from finding, retaining, and supporting the highest quality talent by offering:
- Day 1 Benefits Coverage with low cost Medical, Vision, Dental
- Day 1 Paid-time Off and Vacation
- 4.5% Company Match 401(k) plan
- $500 Annual Company-paid Lifestyle Benefit
- Competitive Compensation and Bonuses
- Company-paid Life and Disability Insurance
- Employee Stock Purchase Plan
- Training and Advancement Opportunities
Why This Job
CMC provides an excellent opportunity to learn the steel, construction reinforcement and ground stabilization industries and to grow in your career. Whether you will spend your day brainstorming in an office cubicle, operating a crane, running manufacturing equipment or troubleshooting technical obstacles, at CMC, you’ll get the training and support from your team that you need to excel in your role and reach your full potential.
What You'll Do
- Lead the continued maturation of CMC's IT Governance, Risk & Compliance program and define the next phase of its maturity strategy
- Establish consistent governance standards, accountability models, decision rights, and control ownership across technology functions
- Strengthen control design, policy management, compliance monitoring, and standard artifacts, with rigor proportionate to financial, regulatory, cybersecurity, and operational risk
- Drive alignment among business objectives, technology strategy, compliance requirements, and risk management priorities
- Promote a culture of accountability, operational discipline, and continuous improvement in which compliance is embedded in day-to-day delivery
- Serve as the primary IT leadership interface for Internal Audit, external auditors, and compliance stakeholders
- Improve audit readiness through standardized evidence management, documentation practices, remediation governance, control monitoring, request intake, and clear closure criteria
- Partner with technology and business leaders to proactively address audit findings, improve evidence quality, and reduce recurring deficiencies and late-cycle surprises
- Provide executive-level insight on governance maturity, compliance performance, control effectiveness, remediation aging, evidence quality, and emerging risk
- Ensure compliance activities improve operations and control effectiveness rather than simply satisfy audit requirements, while maintaining the distinction between management ownership and independent assurance
- Oversee ITGC and SOX compliance across access management, change management, computer operations, interfaces, key reports, and technology-dependent controls
- Establish and execute annual approach to IT SOX scoping in collaboration with Internal Audit and management stakeholders
- Direct governance for SAP access, segregation of duties, privileged access, Firefighter / emergency access, user access reviews, and SAP GRC capabilities
- Establish a risk-based method to prioritize deficiencies by financial reporting exposure, regulatory impact, cybersecurity risk, and operational complexity
- Partner with IT, Finance, Internal Audit, Cybersecurity, and business stakeholders to support effective governance, compliance, and control execution
- Support business units and control owners in identifying IT control gaps
- Provide training and guidance to IT control owners and business unit managers on SOX requirements, control objectives, and best practices
- Implement a repeatable evidence operating model with standardized repositories, request ownership, naming conventions, quality checks, retention requirements, and closure criteria
- Drive timely, sustainable remediation of deficiencies and validate that corrective actions are designed, implemented, documented, and testable
- Establish dashboards and metrics that show control effectiveness, exceptions, remediation progress, audit demand, and recurring failure patterns
- Identify opportunities to automate controls, evidence collection, access reviews, monitoring, and reporting through SAP GRC and other enabling technologies
- Use lessons learned from audits and control failures to improve processes, training, system design, and accountability
- Work with management to evaluate control evidence against quality standards prior to submitting it to auditors
- Identify control deficiencies and recommend remediation plans in collaboration with Internal Audit
What You'll Need
- 12+ years of progressive experience in IT audit, technology risk, governance, compliance, cybersecurity assurance, or related disciplines, including at least 5 years leading managers or senior professional teams
- Proven experience leading and maturing an IT audit, technology compliance, governance, or technology risk organization within a large, complex enterprise
- Prior Big 4 public accounting or external audit experience serving large companies is strongly preferred, with direct responsibility for IT audit, SOX ITGC, controls assurance, or technology risk engagements
- Deep knowledge of SOX ITGCs, control design and testing, risk assessment, deficiency evaluation, remediation, audit evidence, and management reporting
- Strong working knowledge of enterprise applications and infrastructure controls, including SAP security, segregation of duties, privileged access, change management, computer operations, interfaces, and key reports
- Demonstrated success improving audit readiness, strengthening control environments, reducing repeat findings, and advancing compliance program maturity beyond tactical audit response
- Executive-level communication and stakeholder management skills, including the ability to influence across IT, Finance, Internal Audit, external auditors, and business leadership
- CISA certification strongly preferred. CPA, CIA, CRISC, or other relevant certification is a plus
- Experience with SAP S/4HANA, SAP GRC, ServiceNow GRC / IRM, Workiva, Archer, MetricStream, or comparable governance and compliance platforms
- Knowledge of commonly used frameworks and requirements such as COBIT, COSO, NIST CSF, ISO 27001, SOC reporting, CMMC, NIS2, and AI governance
Your Education
- Bachelor's degree in Information Systems, Accounting, Finance, Cybersecurity, Business, or a related field. MBA preferred
We are CMC, a Fortune 500® company at the leading edge of our industry. Our construction reinforcement and steel products have supported construction projects and structures around the world. The secret to our success? We’ve built our legacy by assembling a team of innovators and doers to tackle some of the most challenging construction reinforcement problems facing our world for more than 100 years — and we’re just getting started.
If you’re ready to join a team working to make our industry more sustainable, support the bridges, roadways, buildings and infrastructure that connects our communities, and do meaningful work, you’re ready to join CMC. Apply today and start moving your career — and our world — forward. Let's build a better world!
CMC is committed to providing equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, age, physical or mental disability, national origin, citizenship, military or veteran status, sexual orientation, gender identity and/or expression, genetic information, or other status protected by federal, state or local law.
From Fortune Magazine. © 2025 Fortune Media IP Limited. All rights reserved. Used under license.
$104.9k - $199.07k
...employee-owned consultancy providing actuarial consulting, retirement funding and healthcare financing, enterprise risk management and regulatory compliance, data analytics and business transformation as well as a range of other consulting and technology solutions....SuggestedFull timeWork experience placementRemote workFlexible hours- ...training efforts on how to accurately interpret and use the resultsCollaborate closely with audit methodology specialists, risk, and compliance teams to ensure all AI evaluation flows, metrics, and guardrails actively support firm audit quality standardsAct with integrity...SuggestedH1bLocal area
- Technical Engagement Coordinator for a team working on CICD, DevOps, Chef and Ansible Development etcManaging client relationship, reporting and governanceShould possess excellent experience and awareness of Citi working environment. Someone with experience of managing ...Suggested
- Company DescriptionSonsoft , Inc. is a USA based corporation duly organized under the laws of the Commonwealth of Georgia. Sonsoft Inc. is growing at a steady pace specializing in the fields of Software Development, Software Consultancy and Information Technology Enabled...Suggested
- ...operations in Dallas, TX. This executive role combines strategic oversight with hands-on leadership of origination, servicing, risk management and compliance. The SVP will drive process improvements, technology adoption, and staff development while building strong...Suggested
$70 - $75 per hour
...operations performed by managed service providers to ensure compliance with operational standards. Assess risks and business impacts associated with network and... ..., Disaster Recovery Planning, Infrastructure Governance Preferred Qualifications: Experience in highly...Hourly payContract workTemporary workLocal area- ...exploring innovative ways to do the job. Willingness to consider change and to adapt. Participates and partners with Divisional Directors, Customer Service Technicians, Account Executives and Operations Manager on customer meetings to promote revenue growth, cost...Daily paidFull timeContract workTemporary workWork at officeLocal areaFlexible hoursAfternoon shift
$124.36k - $146.3k
...stakeholders to shape outcome-based product roadmap, product risk, investment areas and success measures.-Drives product... ...priorities-Coordinate with Security, Risk, Audit, and Compliance teams to meet governance and regulatory requirements. -Support platform modernization...Full timeLocal area3 days per week- Job-ID27738195Reference26-06905 Technical Product Manager - Digital Profile Management Credit/Debit Cards Role Summary The Technical Product Manager (TPM) is part of an agile journey team and partners with the Business Line Product Manager to define success, measure outcomes...Work at office3 days per week
$60 - $65 per hour
...automated provisioning and multi-vendor orchestration. Ensure compliance with TMF-compliant APIs and industry standards. 3. Product... ...range of needs of healthcare organizations, including healthcare IT innovation, electronic health record (EHR) implementation & optimizations...Hourly payWork from homeFlexible hoursShift work- ...systems that embed food safety, regulatory compliance, QA standards, and shelf-life... ...validating assumptions, and managing technical risk for formulation, process, and supplier changes... ...and capability assessments• Develop, govern, and maintain technical specifications and...Hourly payWork experience placement
$136.5k - $227.5k
...eCommerce Core Ordering digital products with a focus on; Regulatory & Compliance needs, and the Accounts Payable functionality. This individual... ...timelines, while proactively identifying and mitigating risks. Drives the execution and delivery of a digital product, platform...Full timeH1bWork at officeImmediate start2 days per week$119.8k - $234.7k
...execution plans. Define success criteria, track progress, manage risks, and coordinate Azure engineering teams to deliver high-quality... ...Requirements: Ability to meet Microsoft, customer and/or government security screening requirements are required for this role....Ongoing contractWork at officeLocal area$128k - $245k
...and a minimum of three days per week in the office, which will be set by your manager. Employees are responsible for maintaining compliance with hybrid work policies.Scheduled Weekly Hours40Equal Employment OpportunityVerizon is an equal opportunity employer. We evaluate...Full timeTemporary workPart timeWork experience placementWork at officeWork from homeShift work3 days per week- ...project management, business analysis, backlog governance, quality assurance coordination, and AI-... ...business and technology solutions. It sits at the critical connection point between... ...updates to ensure milestones are met and risks are mitigated Establish and evolve Agile...Casual workWork at officeWork visa
$111.9k - $158k
...Functional Technical Leadership: Serve as the central technical bridge across enterprise architecture, engineering, security, and governance teams to translate complex technical discussions into epics, stories, and executable engineering work. Architecture & Scale:...Local areaFlexible hours- ...Position HighlightsThe Director of Revenue Integrity provides... ...-wide charge capture governance, charge reconciliation,... ...strategy, charge compliance, clinical documentation... ..., finance, compliance, IT, coding, billing, and revenue... ..., Audit, and Risk Management. Lead and oversee...Full timeLocal areaRemote workMonday to Friday
$155k - $233k
...consolidate, modernize, or retire. As Director of Application Lifecycle... ...-wide effort to simplify and govern the application landscape,... ...reduce cost, redundancy, and risk while protecting critical operations... ...experience in IT strategy, application portfolio...Full timeContract workWork at office$195.42k - $370.53k
...KPMG is currently seeking a Director, Private Equity IT M&A -Due Diligence and... ...analysis, identify keytechnology risks, value creation levers,... ...; establish and manage governance frameworks forvalue creation... ...regarding KPMG's compliance with federal, state and local...H1bLocal area- Pioneer your career! Körber is the home for passionate people who innovate, collaborate and love what they do. Entrepreneurial spirit is our joint DNA. We develop future technologies and support talents to deploy their skills and reach their full potential. Together, we...Permanent employmentFull timeImmediate startVisa sponsorshipWork visa
$195.42k - $370.53k
...KPMG is currently seeking a Director Insurance IT M&A - Due Diligence,... ...platforms; identify key IT risks,opportunities, and investments... ...Establish and manage program governance frameworks,ensuring disciplined... ..., claims, finance, and compliance functions Facilitate strategic...H1bLocal area- ...Deep understanding of dealership operations, including rental fleets, depreciation strategies, RPO programs, and regulatory/safety compliance. Leadership Capability: Proven success leading multidisciplinary, geographically dispersed teams and building a high-...
- ...The Director of Loss Prevention is responsible for safeguarding company assets, reducing... ...field and operational teams to maintain compliance and drive results consistently across the... ...strategies to minimize shrink and reduce risk through strong operational compliance...Local areaHome office
- ...industry-specific requirements:Financial Services: security, compliance, auditabilityCommunications: real-time processing, high availabilityMarTech... ...decisions across teams without formal authority5. Standards, Governance & Continuous ImprovementEstablish and enforce architecture...Full time
- ...paced environment where speed, accuracy, compliance, and consistency are critical? Welcome... ...technical dependencies, and mitigate launch risks. Maintain adherence to email and SMS... ...requirements, deliverability best practices, data governance standards, and internal review processes...Full timeWork at officeLocal areaMonday to Friday
$100k - $125k
Job Description Job Description Job Title: HVAC Technical Training Manager Location: Irving, TX Pay: $100,000 to $125,000 per year Schedule: Monday to Friday (40 to 50 hours per week) About Us: We are the largest privately owned residential HVAC company...Weekly payFull timeTemporary workTraineeshipMonday to Friday$113.36k - $165.22k
...construction-related mobile property and specialized inland marine risks. Evaluate complex new and renewal business, apply sound... ...selection.Maintain complete underwriting documentation and ensure compliance with underwriting guidelines and authority levels.Collaborate with...Full timeFor contractorsWork at officeLocal area$204.44k - $324.99k
...in Advisory.KPMG is currently seeking a Director in Technology for our Consulting practice... ..., including accuracy, hallucination risk, data access, human-in-the-loop controls... ...using REST/SOAP web services, and ensure compliance with HIPAA, HITRUST, and other healthcare...H1bLocal area- ...DescriptionSika Corporation is looking for an experienced Technical Director to join its growing Insulation team in the Dallas, TX area. The... ...sales potential and opportunities against associated potential risks, the Technical Director helps ensure the Insulation Division’s...Work at officeLocal areaWorldwide
- ...engineering workstreams, proactively mitigating risks, tracking dependencies, and removing... ...SDLC, release management, and delivery governance, with demonstrated success managing... ...contains further information regarding KPMG's compliance with federal, state and local...H1bLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, IT Governance, Risk & Compliance. Be the first to apply!



