A leading Automotive Finance company in Irvine, CA is seeking an IT GRC Manager for a 6+ month contract role.
Position Description
Supports execution of IT Governance, Risk, Compliance, and Controls activities across governance processes, risk management, audit readiness, IT controls, vendor oversight, and quality management. This contractor provides execution capacity to maintain the IT controls framework, assess current operational controls, support pre-audit testing, contribute to 2027 IT Risk Assessment activities, and track risk mitigation and remediation.
Working with cross-functional technology teams, this role strengthens governance discipline, improves risk and control visibility, supports audit and regulatory readiness, and drives consistent follow-through on remediation commitments.
________________________________________
Responsibilities
Governance, Risk & Controls Management (30%)
* Support development and maintenance of the enterprise IT controls framework across governance, risk, compliance, infrastructure, and application domains
* Conduct baseline assessments of operational controls to identify gaps, ownership, maturity, and improvement opportunities
* Support the annual IT Risk Assessment process, including risk identification, stakeholder coordination, scoring, documentation, and reporting
* Assist with risk intake, issue tracking, mitigation planning, escalation, closure validation, and maintenance of key governance artifacts
Audit, Compliance & Control Testing Support (25%)
* Support audit evidence collection, review, organization, and submission for internal audit, external audit, KSOX/SOX, and regulatory exams
* Perform pre-audit readiness assessments and operational control testing to identify gaps before formal audit activity begins
* Track Management Action Plans, remediation milestones, recurring findings, and closure evidence
* Partner with control owners to validate remediation effectiveness and standardize testing, evidence collection, and audit readiness reporting
Reporting, Metrics & Executive Materials (20%)
* Develop executive reporting on control maturity, risk assessment results, mitigation progress, audit readiness, and remediation status
* Maintain dashboards, trackers, status reports, committee materials, leadership updates, and board-level summaries
* Analyze recurring themes across findings, control gaps, risks, and remediation activities
* Translate detailed GRC activity into concise insights, decisions needed, and action-oriented recommendations
Process Improvement & GRC Maturity Enablement (15%)
* Document current-state processes and support improved workflows for repeatable governance and control activities
* Standardize templates, playbooks, procedures, stakeholder guidance, and reporting practices
* Support automation opportunities for evidence collection, workflow tracking, notifications, and reporting
* Help reduce manual effort, strengthen accountability, and increase transparency across IT GRC processes
Cross-Functional Collaboration (10%)
* Partner with IT application, infrastructure, cybersecurity, project delivery, vendor management, finance, and audit stakeholders
* Support timely follow-up with control owners, process owners, and remediation teams
* Drive clear communication, issue resolution, and stakeholder alignment across governance and compliance activities
JOB REQUIREMENTS
Work Experience
* 5-8+ years of experience in IT governance, risk management, compliance, audit support, IT controls, or technology operations
* Experience with SOX/KSOX, ITGCs, audit evidence coordination, risk remediation, or control testing preferred
* Experience developing executive reporting, issue trackers, governance documentation, and process improvement materials
* Financial services, regulated industry, or enterprise IT experience preferred
Education, Certification, Training
* Bachelor"s degree in information systems, business, risk management, accounting, cybersecurity, or related field preferred
* CISA, CRISC, CGEIT, COBIT, ITIL, PMP, or related certification preferred but not required
Knowledge, Skills & Abilities
* Proficiency in Excel, PowerPoint, SharePoint, Teams, and workflow/reporting tools
* Strong understanding of IT governance, controls, audit processes, risk management, compliance expectations, ITGCs, COBIT, SOX/KSOX, and audit readiness practices
* Ability to assess operational control effectiveness, identify gaps, support remediation planning, and validate closure
* Ability to organize complex information into clear trackers, summaries, dashboards, and executive-ready materials
* Strong analytical, follow-up, project coordination, written communication, and verbal communication skills
* Ability to manage multiple priorities, deadlines, and cross-functional dependencies across technical and non-technical stakeholders