Cyber Security Governance, Risk, and Compliance; GRC
Job in
New York, New York County, New York, 10261, USA
Listed on 2026-07-18
Listing for:
Tenth Revolution Group
Full Time
position Listed on 2026-07-18
Job specializations:
-
IT/Tech
Cybersecurity, IT Business Analyst, IT Consultant, Information Security & Data Protection
Job Description & How to Apply Below
Location: New York
Program Support
- Lead the day-to-day execution of TPG’s SOX IT program, ensuring that manual and automated internal controls supporting financial reporting are designed effectively and operating as intended.
- Scoping & Assessment:
Assist in annual SOX scoping and Risk Assessments to identify critical systems and financial risks. - Audit Coordination:
Act as a primary liaison between TPG and external auditors, internal auditors, and co-sourcing partners to ensure seamless execution and timely delivery of evidence. - Remediation Management:
Identify and evaluate control deficiencies; partner with system owners to design and monitor remediation plans and perform validation testing.
- Vendor Assurance:
Review SOC1/SOC2 reports for third-party service providers, identifying gaps and designing Complementary User Entity Controls (CUECs) to mitigate supply-chain risk. - Policy & Standards:
Support the lifecycle of TPG’s Cybersecurity and Disaster Recovery Policies, ensuring they reflect current regulatory requirements and industry best practices. - Risk & Control Registers:
Maintain and mature TPG’s IT Risk Register and IT Control Register, ensuring they remain living documents that accurately reflect the firm’s risk posture.
- Control Optimization:
Partner with IT and Business stakeholders to enhance IT General Controls (ITGCs) and automated business controls to address emerging risks. - Automation:
Proactively identify opportunities to use GRC tools (e.g., Audit Board) to automate evidence collection and transition from point-in-time testing to continuous control monitoring. - Change Management:
Support and enhance TPG’s Change Control processes to ensure agility without sacrificing security or compliance.
- Bachelors degree or higher.
- 2–4 years of experience in IT Audit, IT Compliance, or Cybersecurity GRC (prior experience at a Big 4 or top-tier consulting firm is a plus).
- Strong understanding of PCAOB standards and the IT SOX compliance lifecycle.
- Familiarity with industry-standard frameworks such as COBIT, NIST CSF, ISO 27001, or ITIL.
- Ability to evaluate complex IT environments and recommend best-in-class controls that balance security with business efficiency.
- Exceptional written and verbal communication skills, with the ability to translate technical risks into business impact for non-technical stakeholders.
- High attention to detail and the ability to manage multiple high-priority work streams in a fast-paced, deadline-driven environment.
- Bachelor’s degree in Cybersecurity, Management Information Systems (MIS), Computer Science, or a related field.
- CISA (Certified Information Systems Auditor) is highly preferred; CISSP, CRISC, or CISM is a plus.
- Experience utilizing Audit Board or similar GRC platforms for workflow management and evidence centralisation.li>
- Prior experience in Financial Services or Alternative Asset Management.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×