Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 3
Audit @ 3
CI/CD @ 3
Change Management
Compliance
DevOps @ 3
FinTech @ 3
Hiring @ 3
Jira @ 3
Kubernetes @ 3
Machine Learning
NetSuite @ 3
Networking
Reporting @ 3
Security
ServiceNow @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Nebius is building a full-stack AI cloud platform for developers and enterprises, covering data and model training through production deployment. The company operates across cloud infrastructure, compute, storage, networking, and applied AI.
The IT Risk & Controls Manager will act as an embedded risk partner to engineering and technology organizations. The role will help scale and strengthen a modern IT SOX and controls framework across Nebius's AI cloud platform, infrastructure, corporate technology environment, and systems supporting financial reporting. The position involves working with engineering leaders, system owners, Finance, Internal Controls, and external auditors to identify risk, design scalable controls, improve evidence quality, drive remediation, and embed compliance into technology operations.
Responsibilities
- Act as the risk and controls partner for an assigned technology organization or system portfolio, developing an understanding of its architecture, operations, risks, and financial-reporting dependencies.
- Own and continuously improve the IT risk and control framework, including system scoping, risk assessment, risk and control matrices, control-catalogue maintenance, documentation, and control ownership.
- Lead IT SOX readiness for assigned systems, including walkthrough preparation, evidence-quality review, testing coordination, issue evaluation, and remediation oversight.
- Partner with engineering, platform, infrastructure, security, and corporate IT teams to design and implement scalable controls.
- Design, assess, and enhance IT general controls across user access, privileged access, segregation of duties, change management, SDLC, system operations, incident management, and third-party services.
- Assess IT application controls, automated controls, and IT-dependent business controls, including the completeness and accuracy of system-generated information.
- Evaluate dependencies between business controls and systems, integrations, configurations, reports, and underlying IT general controls.
- Apply risk and controls principles to cloud infrastructure, DevOps, CI/CD, repositories, deployment processes, containerized environments, and audit logging.
- Lead the assessment and remediation of control gaps arising from new systems, technology transformations, platform changes, integrations, and acquisitions.
- Review third-party assurance reports and assess the impact of vendor controls and complementary user-entity controls.
- Maintain relationships with external auditors and advisers, aligning on audit scope, evidence expectations, testing approaches, timelines, and issue resolution.
- Translate technical risks and auditor requirements into practical guidance for engineering and system owners.
- Use data analytics, automation, continuous monitoring, and AI-assisted tools to improve control coverage, evidence quality, and IT SOX program efficiency.
- Contribute to IT controls methodology, standards, tooling, training, reporting, and the broader Risk Partner operating model.
- Provide updates on control health, audit readiness, deficiencies, and remediation progress to senior technology and Finance stakeholders.
Requirements
- Degree in Information Systems, Computer Science, Engineering, Accounting, Finance, or a related discipline, or equivalent professional experience.
- At least eight years of progressive experience in IT risk, IT controls, IT SOX, technology assurance, IT audit, or a closely related area.
- Meaningful in-house technology or corporate ownership experience. Big Four or consulting experience is valuable when combined with subsequent in-house responsibility, but an exclusively advisory or external-audit background is not sufficient.
- Experience in a first-line technology, engineering, systems, or IT operations role, or as an embedded in-house risk partner supporting a technology organization.
- Hands-on experience in an engineering-led technology, cloud, SaaS, platform, or digital-product environment.
- Strong practical knowledge of SOX 404, ITGCs, IT application controls, automated controls, COSO, and COBIT.
- Experience with control design, implementation, monitoring, evidence review, audit readiness, issue evaluation, and remediation.
- Practical understanding of cloud infrastructure, IAM, DevOps, CI/CD, SDLC, software repositories, deployment practices, system integrations, and container orchestration such as Kubernetes.
- Experience connecting business-process controls to supporting systems, automated controls, IPEs/IUCs, and underlying IT dependencies.
- Ability to communicate effectively with engineers, technical leaders, Finance stakeholders, and external auditors.
- Strong judgment and confidence to challenge control owners while developing practical, scalable solutions.
- Highly autonomous and hands-on approach, with the ability to work in an evolving environment with incomplete processes and competing priorities.
- Strong written and verbal English.
- Ability to work across international time zones and travel when needed.
Preferred Qualifications
- Professional certification such as CISA, CRISC, CISM, CIA, CPA, or equivalent.
- Experience building or materially transforming an IT SOX or technology-controls framework in a listed or pre-IPO technology company.
- Experience in AI infrastructure, cloud platforms, large-scale SaaS, fintech, marketplaces, or another engineering-intensive environment.
- Experience with GRC and audit-management tools such as Workiva, Jira, ServiceNow GRC, or similar platforms.
- Experience with enterprise SaaS and financial systems such as NetSuite, HR platforms, billing systems, procurement tools, or treasury systems.
- Experience onboarding acquired companies or newly implemented systems into SOX scope.
- Experience with control automation, continuous monitoring, data analytics, or AI-assisted assurance.
- Exposure to AI governance, AI/ML control environments, or controls supporting AI-enabled development and operations.
Compensation
The base compensation range is $120,000–$180,000 USD. Actual compensation will be determined based on experience, skills, qualifications, hiring level, and geographic location.
Benefits
- Competitive compensation
- Career growth and learning opportunities
- Flexibility and ownership
- Collaborative and innovative culture
- Opportunity to work on impactful AI projects
- International environment and talented teams
Nebius is an equal opportunity employer committed to an inclusive and diverse workplace. Applicants must be authorized to work in the country in which they apply and must provide proof of employment eligibility as a condition of hire.