Senior Manager, Technology & Security Compliance (52000007)

Altria Client Services LLC
  • Richmond, VA
  • Full-time
  • Autofill and Review
5 days ago

Job Description

Together We Innovate. Together We Change.
Are you an experienced technology risk and compliance leader ready to make a significant impact on how technology controls protect the integrity of a major enterprise? Join us as Senior Manager, Technology and Security Compliance and take the lead in strengthening our Sarbanes-Oxley and IT General Controls framework while modernizing how technology risk and compliance are managed across the organization! You'll shape a controls program that is critical to financial reporting and enterprise risk management, influence key decisions with senior leaders, and drive meaningful improvements across Technology and Cybersecurity. You'll also build and lead a high-performing team that helps set the standard for technology compliance across the enterprise. This position is in Richmond, VA with a hybrid work schedule. We will consider a remote working option for the ideal applicant.In this role, you'll provide both strategic direction and day-to-day leadership across IT systems and security controls, audit readiness, issue remediation, and continuous improvement. You'll engage closely with Technology, Information Security, Financial Operations, Internal Audit, External Audit, and business stakeholders to strengthen compliance and effectively manage technology risk. We're looking for a leader with deep SOX and ITGC expertise, a strong understanding of technology risk and security controls, and the executive presence to provide focused program leadership and influence senior stakeholders.
What you will be doing:
  • Leading the SOX/ITGC controls team in planning, coordinating, and delivering technology control activities across the annual SOX lifecycle, while establishing clear roles, expectations, development plans, and accountability for quality execution.
  • Overseeing ITGC control design, control ownership alignment, evidence requirements, testing readiness, deficiency evaluation, issue remediation, management responses, and validation of corrective actions.
  • Establishing consistent standards, procedures, and quality expectations for control documentation, evidence collection, testing support, audit coordination, and remediation governance.
  • Driving continuous improvement of the SOX/ITGC control environment through simplification, automation, control rationalization, stronger accountability, improved reporting, and risk-based prioritization.
  • Coordinating SOX and ITGC activities across Technology, Cybersecurity, Finance, Internal Audit, External Audit, application owners, control owners, and business partners to maintain audit readiness and alignment.
  • Guiding control owners in strengthening control design, clarifying operating expectations, improving evidence quality, identifying root causes, resolving recurring control gaps, and integrating controls with broader technology risk practices.
  • Translating control risks, audit findings, remediation needs, testing status, control health, and readiness concerns into clear executive communications and decision points while presenting key risk themes to senior leaders and governance forums.
We want you to have:
  • Bachelor's degree in Accounting, Information Systems, Cybersecurity, Computer Science, Finance, or a related field; Master's degree preferred.
  • 10+ years of progressive experience in SOX compliance, ITGCs, IT audit, technology risk, internal audit, compliance, or related disciplines, including demonstrated experience leading SOX/ITGC activities.
  • 5+ years of leadership experience managing controls teams, audit programs, compliance programs, or multi-functional technology risk initiatives.
  • Deep knowledge of SOX 404, ITGCs, automated controls, application controls, control dependency mapping, COSO, audit methodology, deficiency assessment, remediation governance, and management response development.
  • Solid understanding of technology operations and security controls that underpin financial reporting, including IAM, PAM, user access reviews, leading system modifications, infrastructure operations, cloud environments, logging, monitoring, backups, and job scheduling.
  • Demonstrated ability to establish effective control documentation and evidence standards, coordinate audit and testing activities, manage issue tracking and remediation, improve control execution, and deliver executive-level reporting.
  • Validated ability to influence senior team members, lead through ambiguity, guide high-performing teams, and communicate technology control risks and sophisticated compliance matters in a clear, executive-ready manner.
  • CISA, CISSP, CISM, CPA, CIA, or equivalent professional certification required; additional credentials such as CRMA, CGEIT, ISO 27001 Lead Auditor, or other relevant security, audit, risk, or governance certifications preferred.

Numbers & Facts

LocationRichmond, VA
Job TypeFull-time

Skills

  • Accountingunmatched
  • Auditingunmatched
  • Automationunmatched
  • CISA - Certified Information Systems Auditorunmatched
  • CISM - Certified Information Security Managerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Certified Public Accountant (CPA)unmatched
  • Cloud Computingunmatched
  • Committee of Sponsoring Organizations of the Treadway Commission (COSO)unmatched
  • Communication Skillsunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Continuous Improvementunmatched
  • Corrective Actionunmatched
  • Cross-Functionalunmatched
  • Document Managementunmatched
  • Documentation Standardsunmatched
  • Establish Prioritiesunmatched
  • External Auditunmatched
  • Financeunmatched
  • Financial Auditunmatched
  • Financial Operationsunmatched
  • Financial Reportingunmatched
  • ISO (International Organization for Standardization)unmatched
  • Information Technology & Information Systemsunmatched
  • Information Technology/Systems Auditunmatched
  • Internal Auditunmatched
  • Internet Securityunmatched
  • Leadershipunmatched
  • Maintain Complianceunmatched
  • Operations Security (OPSEC)unmatched
  • Organizational Development/Managementunmatched
  • Process Improvementunmatched
  • Program Controlunmatched
  • Quality Controlunmatched
  • Quality Managementunmatched
  • Regulatory Complianceunmatched
  • Riskunmatched
  • Risk Managementunmatched
  • Root Cause Analysisunmatched
  • SOX 404unmatched
  • Sarbanes-Oxley Act (SOX)unmatched
  • Security Auditingunmatched
  • Security Complianceunmatched
  • Strategic Planningunmatched
  • Team Lead/Managerunmatched
  • Technical Deliveryunmatched
  • Technical Leadershipunmatched
  • Technical Operationsunmatched
  • Test Requirementsunmatched
  • Testingunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder