Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

CMC

Director, IT Governance, Risk & Compliance

Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
85
out of 100
Average of individual scores

Were these scores useful?

Job Description

it's what's inside that counts_______________________________ There's more to CMC than our products and the buildings, structures, and roads they go into. At CMC, it's the people inside our recycling centers, fabrication plants, manufacturing facilities, steel mills and offices that make us who we are as a company. Our success comes from finding, retaining, and supporting the highest quality talent by offering: Day 1 Benefits Coverage with low cost Medical, Vision, Dental

Day 1 Paid-time Off and Vacation

4.5% Company Match 401(k) plan

$500 Annual Company-paid Lifestyle Benefit

Competitive Compensation and Bonuses

Company-paid Life and Disability Insurance

Employee Stock Purchase Plan

Training and Advancement Opportunities Why This Job CMC provides an excellent opportunity to learn the steel, construction reinforcement and ground stabilization industries and to grow in your career. Whether you will spend your day brainstorming in an office cubicle, operating a crane, running manufacturing equipment or troubleshooting technical obstacles, at CMC, you'll get the training and support from your team that you need to excel in your role and reach your full potential.

What You'll Do

Lead the continued maturation of CMC's IT Governance, Risk & Compliance program and define the next phase of its maturity strategy

Establish consistent governance standards, accountability models, decision rights, and control ownership across technology functions

Strengthen control design, policy management, compliance monitoring, and standard artifacts, with rigor proportionate to financial, regulatory, cybersecurity, and operational risk

Drive alignment among business objectives, technology strategy, compliance requirements, and risk management priorities

Promote a culture of accountability, operational discipline, and continuous improvement in which compliance is embedded in day-to-day delivery

Serve as the primary IT leadership interface for Internal Audit, external auditors, and compliance stakeholders

Improve audit readiness through standardized evidence management, documentation practices, remediation governance, control monitoring, request intake, and clear closure criteria

Partner with technology and business leaders to proactively address audit findings, improve evidence quality, and reduce recurring deficiencies and late-cycle surprises

Provide executive-level insight on governance maturity, compliance performance, control effectiveness, remediation aging, evidence quality, and emerging risk

Ensure compliance activities improve operations and control effectiveness rather than simply satisfy audit requirements, while maintaining the distinction between management ownership and independent assurance

Oversee ITGC and SOX compliance across access management, change management, computer operations, interfaces, key reports, and technology-dependent controls

Establish and execute annual approach to IT SOX scoping in collaboration with Internal Audit and management stakeholders

Direct governance for SAP access, segregation of duties, privileged access, Firefighter / emergency access, user access reviews, and SAP GRC capabilities

Establish a risk-based method to prioritize deficiencies by financial reporting exposure, regulatory impact, cybersecurity risk, and operational complexity

Partner with IT, Finance, Internal Audit, Cybersecurity, and business stakeholders to support effective governance, compliance, and control execution

Support business units and control owners in identifying IT control gaps

Provide training and guidance to IT control owners and business unit managers on SOX requirements, control objectives, and best practices

Implement a repeatable evidence operating model with standardized repositories, request ownership, naming conventions, quality checks, retention requirements, and closure criteria

Drive timely, sustainable remediation of deficiencies and validate that corrective actions are designed, implemented, documented, and testable

Establish dashboards and metrics that show control effectiveness, exceptions, remediation progress, audit demand, and recurring failure patterns

Identify opportunities to automate controls, evidence collection, access reviews, monitoring, and reporting through SAP GRC and other enabling technologies

Use lessons learned from audits and control failures to improve processes, training, system design, and accountability

Work with management to evaluate control evidence against quality standards prior to submitting it to auditors

Identify control deficiencies and recommend remediation plans in collaboration with Internal Audit

What You'll Need

12+ years of progressive experience in IT audit, technology risk, governance, compliance, cybersecurity assurance, or related disciplines, including at least 5 years leading managers or senior professional teams

Proven experience leading and maturing an IT audit, technology compliance, governance, or technology risk organization within a large, complex enterprise

Prior Big 4 public accounting or external audit experience serving large companies is strongly preferred, with direct responsibility for IT audit, SOX ITGC, controls assurance, or technology risk engagements

Deep knowledge of SOX ITGCs, control design and testing, risk assessment, deficiency evaluation, remediation, audit evidence, and management reporting

Strong working knowledge of enterprise applications and infrastructure controls, including SAP security, segregation of duties, privileged access, change management, computer operations, interfaces, and key reports

Demonstrated success improving audit readiness, strengthening control environments, reducing repeat findings, and advancing compliance program maturity beyond tactical audit response

Executive-level communication and stakeholder management skills, including the ability to influence across IT, Finance, Internal Audit, external auditors, and business leadership

CISA certification strongly preferred. CPA, CIA, CRISC, or other relevant certification is a plus

Experience with

SAP S/4HANA, SAP

GRC, ServiceNow GRC / IRM, Workiva, Archer, MetricStream, or comparable governance and compliance platforms

Knowledge of commonly used frameworks and requirements such as

COBIT, COSO, NIST CSF, ISO 27001, SOC

reporting, CMMC, NIS2, and AI governance

Your Education

Bachelor's degree in Information Systems, Accounting, Finance, Cybersecurity, Business, or a related field. MBA preferred

We are CMC, a Fortune 500® company at the leading edge of our industry. Our construction reinforcement and steel products have supported construction projects and structures around the world. The secret to our success? We've built our legacy by assembling a team of innovators and doers to tackle some of the most challenging construction reinforcement problems facing our world for more than 100 years — and we're just getting started. If you're ready to join a team working to make our industry more sustainable, support the bridges, roadways, buildings and infrastructure that connects our communities, and do meaningful work, you're ready to join CMC. Apply today and start moving your career — and our world — forward. Let's build a better world! CMC is committed to providing equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, age, physical or mental disability, national origin, citizenship, military or veteran status, sexual orientation, gender identity and/or expression, genetic information, or other status protected by federal, state or local law. From Fortune Magazine. © 2025 Fortune Media IP Limited. All rights reserved. Used under license.

Benefits

  • Paid Time Off (PTO)
  • 401(k) Plans
  • Employee Stock Options (ESOs)
  • Health Insurance