Senior Director, IT Governance, Risk and Compliance
Listed on 2026-08-18
-
IT/Tech
IT Business Analyst, Cybersecurity
Who We Are
TKO Group Holdings, Inc. (NYSE: TKO) is a premium sports and entertainment company. TKO owns iconic properties including UFC, the world’s premier mixed martial arts organization; WWE, the global leader in sports entertainment; and P , the world’s premier bull riding organization. Together, these properties reach 1 billion households across 210 countries and territories and organize more than 500 live events year-round, attracting more than three million fans.
TKO also services and partners with major sports rights holders through IMG, an industry‑leading global sports marketing agency; and On Location, a global leader in premium experiential hospitality.
The Senior Director, IT Governance, Risk and Compliance, is responsible for leading and executing core elements of TKO’s IT compliance program, with a focus on SOX and IT General Controls, audit readiness, governance documentation, benchmarking against recognized security frameworks, third‑party assurance, and technical data reconciliation activities. Reporting to TKO’s SVP of IT Business Systems, this role will partner closely with Legal, IT, Security, Internal Audit, Finance, and business stakeholders to strengthen TKO’s control environment, support enterprise compliance obligations, help lead risk management, and drive consistent execution across systems and processes.
This role requires both strategic oversight and hands‑on execution. The successful candidate will bring deep experience in IT compliance and controls, strong technical data management capability, and the ability to operate effectively across a complex environment with disparate systems, inconsistent data structures, and evolving business needs.
- Establish an overall compliance strategy and roadmap which includes selecting and implementing an enterprise Governance, Risk and Compliance platform to automate RCM authoring and drive evidence collection workflows.
- Own prioritization, tracking, and delivery of key compliance initiatives including executive status updates regarding the program status and health
- Provide subject matter expertise and guidance to system leads and business partners on compliance expectations, control execution, documentation standards, and system implementation lifecycle considerations
- Advise and ensure PCI compliance is being sustained by in‑scope business units.
- Oversee internal resources, project‑based support, or cross‑functional contributors in connection with audit preparation, SOC reporting, PCI compliance adherence, and compliance execution.
- Coordination across other risk management stakeholder functions (e.g. Legal, Finance, Internal Audit, Corporate IT, BU level IT organizations) to accomplish the following:
- Support and evolve existing IT Risk Management Program to ensure controls address Technology, Cybersecurity, Data, Resiliency/Recovery, and Emerging (AI, etc.) risks.
- Establish IT compliance requirements
- Identify and eliminate redundant risk management processes and/or controls
- Understand and support the risk management objectives of other risk management functions
- Maintain current inventories of in‑scope systems and applications that are required to support key regulatory requirements (e.g., ICFR), in‑flight IT projects, and relevant stakeholders
- Develop the framework and standards for core IT compliance documentation and templates, including Risk and Control Matrices, process flows, system interface documentation, and remediation plans
- Determine the review criteria and cadence for assessing documentation prepared by system leads and control owners for quality, completeness, and alignment with compliance requirements
- Establish policies, procedures, and governance practices that support effective and sustainable compliance execution
- Act as primary point of contact for IT compliance supporting internal and external audits, including SOX and IT General Controls testing
- Organize, collect, and maintain evidence required for audit requests and management review
- Liaise…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).