Find Jobs
Find Jobs Near You – Available Work in Your Location
Director, IT Governance, Risk & Compliance
Job Description
it's what's inside that counts_______________________________ There's more to CMC than our products and the buildings, structures, and roads they go into. At CMC, it's the people inside our recycling centers, fabrication plants, manufacturing facilities, steel mills and offices that make us who we are as a company. Our success comes from finding, retaining, and supporting the highest quality talent by offering: Day 1 Benefits Coverage with low cost Medical, Vision, Dental
Day 1 Paid-time Off and Vacation
4.5% Company Match 401(k) plan
$500 Annual Company-paid Lifestyle Benefit
Competitive Compensation and Bonuses
Company-paid Life and Disability Insurance
Employee Stock Purchase Plan
Training and Advancement Opportunities Why This Job CMC provides an excellent opportunity to learn the steel, construction reinforcement and ground stabilization industries and to grow in your career. Whether you will spend your day brainstorming in an office cubicle, operating a crane, running manufacturing equipment or troubleshooting technical obstacles, at CMC, you'll get the training and support from your team that you need to excel in your role and reach your full potential.
What You'll Do
Lead the continued maturation of CMC's IT Governance, Risk & Compliance program and define the next phase of its maturity strategy
Establish consistent governance standards, accountability models, decision rights, and control ownership across technology functions
Strengthen control design, policy management, compliance monitoring, and standard artifacts, with rigor proportionate to financial, regulatory, cybersecurity, and operational risk
Drive alignment among business objectives, technology strategy, compliance requirements, and risk management priorities
Promote a culture of accountability, operational discipline, and continuous improvement in which compliance is embedded in day-to-day delivery
Serve as the primary IT leadership interface for Internal Audit, external auditors, and compliance stakeholders
Improve audit readiness through standardized evidence management, documentation practices, remediation governance, control monitoring, request intake, and clear closure criteria
Partner with technology and business leaders to proactively address audit findings, improve evidence quality, and reduce recurring deficiencies and late-cycle surprises
Provide executive-level insight on governance maturity, compliance performance, control effectiveness, remediation aging, evidence quality, and emerging risk
Ensure compliance activities improve operations and control effectiveness rather than simply satisfy audit requirements, while maintaining the distinction between management ownership and independent assurance
Oversee ITGC and SOX compliance across access management, change management, computer operations, interfaces, key reports, and technology-dependent controls
Establish and execute annual approach to IT SOX scoping in collaboration with Internal Audit and management stakeholders
Direct governance for SAP access, segregation of duties, privileged access, Firefighter / emergency access, user access reviews, and SAP GRC capabilities
Establish a risk-based method to prioritize deficiencies by financial reporting exposure, regulatory impact, cybersecurity risk, and operational complexity
Partner with IT, Finance, Internal Audit, Cybersecurity, and business stakeholders to support effective governance, compliance, and control execution
Support business units and control owners in identifying IT control gaps
Provide training and guidance to IT control owners and business unit managers on SOX requirements, control objectives, and best practices
Implement a repeatable evidence operating model with standardized repositories, request ownership, naming conventions, quality checks, retention requirements, and closure criteria
Drive timely, sustainable remediation of deficiencies and validate that corrective actions are designed, implemented, documented, and testable
Establish dashboards and metrics that show control effectiveness, exceptions, remediation progress, audit demand, and recurring failure patterns
Identify opportunities to automate controls, evidence collection, access reviews, monitoring, and reporting through SAP GRC and other enabling technologies
Use lessons learned from audits and control failures to improve processes, training, system design, and accountability
Work with management to evaluate control evidence against quality standards prior to submitting it to auditors
Identify control deficiencies and recommend remediation plans in collaboration with Internal Audit
What You'll Need
12+ years of progressive experience in IT audit, technology risk, governance, compliance, cybersecurity assurance, or related disciplines, including at least 5 years leading managers or senior professional teams
Proven experience leading and maturing an IT audit, technology compliance, governance, or technology risk organization within a large, complex enterprise
Prior Big 4 public accounting or external audit experience serving large companies is strongly preferred, with direct responsibility for IT audit, SOX ITGC, controls assurance, or technology risk engagements
Deep knowledge of SOX ITGCs, control design and testing, risk assessment, deficiency evaluation, remediation, audit evidence, and management reporting
Strong working knowledge of enterprise applications and infrastructure controls, including SAP security, segregation of duties, privileged access, change management, computer operations, interfaces, and key reports
Demonstrated success improving audit readiness, strengthening control environments, reducing repeat findings, and advancing compliance program maturity beyond tactical audit response
Executive-level communication and stakeholder management skills, including the ability to influence across IT, Finance, Internal Audit, external auditors, and business leadership
CISA certification strongly preferred. CPA, CIA, CRISC, or other relevant certification is a plus
Experience with
SAP S/4HANA, SAP
GRC, ServiceNow GRC / IRM, Workiva, Archer, MetricStream, or comparable governance and compliance platforms
Knowledge of commonly used frameworks and requirements such as
COBIT, COSO, NIST CSF, ISO 27001, SOC
reporting, CMMC, NIS2, and AI governance
Your Education
Bachelor's degree in Information Systems, Accounting, Finance, Cybersecurity, Business, or a related field. MBA preferred
We are CMC, a Fortune 500® company at the leading edge of our industry. Our construction reinforcement and steel products have supported construction projects and structures around the world. The secret to our success? We've built our legacy by assembling a team of innovators and doers to tackle some of the most challenging construction reinforcement problems facing our world for more than 100 years — and we're just getting started. If you're ready to join a team working to make our industry more sustainable, support the bridges, roadways, buildings and infrastructure that connects our communities, and do meaningful work, you're ready to join CMC. Apply today and start moving your career — and our world — forward. Let's build a better world! CMC is committed to providing equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, age, physical or mental disability, national origin, citizenship, military or veteran status, sexual orientation, gender identity and/or expression, genetic information, or other status protected by federal, state or local law. From Fortune Magazine. © 2025 Fortune Media IP Limited. All rights reserved. Used under license.
Benefits
- Paid Time Off (PTO)
- 401(k) Plans
- Employee Stock Options (ESOs)
- Health Insurance