IT Risks & Control Manager
Listed on 2026-08-05
-
IT/Tech
Cybersecurity
About Nebius:
Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.
Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.
Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.
The roleNebius isseekingaIT Risk & Controls Managerto act as an embedded risk partnertoour engineering and technology organizations.
You will help scale and strengthen a modern IT SOX andcontrolsframework across
Nebius’scustom-built AI cloud platform, infrastructure, corporate technologyenvironmentand other systems supporting financial reporting.
This role goes beyond traditional IT audit testing. You will work directly with engineering leaders, system owners, Finance, Internal Control sand external auditors toidentifyrisk, design scalable controls, improve evidence quality, driveremediationand embed compliance into the way our technology organizations operate.
The successful candidate will combine deep IT risk andcontrolsexpertisewith meaningful in-house technology experience. You must be equally comfortable discussing technical control design with engineers, explaining risk implications to businessleadersand aligning audit expectations with external assurance providers.
Your responsibilities will include:- Act as the risk and controls partner for an assigned technology organization or system portfolio, developing a detailed understanding of its architecture, operations,risksand financial-reporting dependencies.
- Own and continuously improve the relevant IT risk and control framework, including system scoping, risk assessment, RCM and control-catalogue maintenance,documentation and control ownership.
- Lead IT SOX readiness for assigned systems, including walkthrough preparation, evidence-quality review, testing coordination, issueevaluationand remediation oversight.
- Partner with engineering, platform, infrastructure,security and corporate IT teams to design and implement scalable controls that address risk while supporting operational efficiency.
- Design, assess and enhance ITGCs across areas such as user access, privileged access, segregation of duties, change management, SDLC, system operations, incidentmanagementand third-party services.
- Assess IT application controls, automated controls and IT-dependent business controls, including the completeness and accuracy of system-generated information used in business-process controls.
- Evaluate how business controls depend on systems, integrations, configurations, reports and underlying ITGCs, and work with both business and IT control owners to resolve gaps.
- Apply risk and controls thinking to modern engineering practices, including cloud infrastructure, Dev Ops, CI/CD, repositories, deployment processes, containerizedenvironmentsand audit logging.
- Lead the assessment and remediation of control gaps arising from new systems, major technology transformations, platform changes,integrations and acquisitions.
- Review third-party assurance reports anddeterminethe impact of vendor controls and complementary user-entity controls on the Nebiuscontrol environment.
- Maintain effective working relationships with external auditors and advisers,aligning onaudit scope, evidence expectations, testing approaches, reliance opportunities, timelines and issue resolution.
- Translate complex technical risks and auditor requirements into practical guidance for engineering and system owners.
- Use data analytics, automation, continuousmonitoringand AI-assisted tools to improve control coverage, evidencequalityand the efficiency of the IT SOX program.
- Contribute to the development of IT controls methodology, standards, tooling, training, reporting and the broader…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).