Nebius
IT Risks & Control Manager
Remote work allowed only within certain countries or regions.
Employer listed it 3 weeks ago · Added 2 days ago
Been open since 3 weeks ago, still being checked, but it has been live a while.
Salary
$120,000 to $180,000
Location
Timezone
US East
Contract
Full-time
Experience
Mid
Category
Other
Stated by the employer in the job description
Remote flexibility
Region Restricted
Remote work is allowed, but only for candidates based in United States, Czechia, Germany, Netherlands, Spain, United Kingdom.
What the employer says
- Source listing states candidate location: "Remote - United States, Czech Republic, Germany, Netherlands, Spain, United Kingdom"
- Job description states: "authorized to work in the country in which they apply an"
What Nomaders makes of it
- Timezone overlap with the listed area is often expected
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
About Nebius:
Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.
Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.
Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.
The role
Nebius is seeking a IT Risk & Controls Manager to act as an embedded risk partner to our engineering and technology organizations.
You will help scale and strengthen a modern IT SOX and controls framework across Nebius’s custom-built AI cloud platform, infrastructure, corporate technology environment and other systems supporting financial reporting.
This role goes beyond traditional IT audit testing. You will work directly with engineering leaders, system owners, Finance, Internal Controls and external auditors to identify risk, design scalable controls, improve evidence quality, drive remediation and embed compliance into the way our technology organizations operate.
The successful candidate will combine deep IT risk and controls expertise with meaningful in-house technology experience. You must be equally comfortable discussing technical control design with engineers, explaining risk implications to business leaders and aligning audit expectations with external assurance providers.
Your responsibilities will include:
Act as the risk and controls partner for an assigned technology organization or system portfolio, developing a detailed understanding of its architecture, operations, risks and financial-reporting dependencies.
Own and continuously improve the relevant IT risk and control framework, including system scoping, risk assessment, RCM and control-catalogue maintenance, documentation and control ownership.
Lead IT SOX readiness for assigned systems, including walkthrough preparation, evidence-quality review, testing coordination, issue evaluation and remediation oversight.
Partner with engineering, platform, infrastructure, security and corporate IT teams to design and implement scalable controls that address risk while supporting operational efficiency.
Design, assess and enhance ITGCs across areas such as user access, privileged access, segregation of duties, change management, SDLC, system operations, incident management and third-party services.
Assess IT application controls, automated controls and IT-dependent business controls, including the completeness and accuracy of system-generated information used in business-process controls.
Evaluate how business controls depend on systems, integrations, configurations, reports and underlying ITGCs, and work with both business and IT control owners to resolve gaps.
Apply risk and controls thinking to modern engineering practices, including cloud infrastructure, DevOps, CI/CD, repositories, deployment processes, containerized environments and audit logging.
Lead the assessment and remediation of control gaps arising from new systems, major technology transformations, platform changes, integrations and acquisitions.
Review third-party assurance reports and determine the impact of vendor controls and complementary user-entity controls on the Nebius control environment.
Maintain effective working relationships with external auditors and advisers, aligning on audit scope, evidence expectations, testing approaches, reliance opportunities, timelines and issue resolution.
Translate complex technical risks and auditor requirements into practical guidance for engineering and system owners.
Use data analytics, automation, continuous monitoring and AI-assisted tools to improve control coverage, evidence quality and the efficiency of the IT SOX program.
Contribute to the development of IT controls methodology, standards, tooling, training, reporting and the broader Risk Partner operating model.
Requirements
- ·A professional certification such as CISA, CRISC, CISM, CIA, CPA or an equivalent qualification.
- ·Experience building or materially transforming an IT SOX or technology-controls framework in a listed or pre-IPO technology company.
- ·Experience in AI infrastructure, cloud platforms, large-scale SaaS, fintech, marketplaces or another engineering-intensive environment.
- ·Experience with GRC and audit-management tools such as Workiva, Jira, ServiceNow GRC or similar platforms.
- ·Experience with enterprise SaaS and financial systems such as NetSuite, HR platforms, billing systems, procurement tools or treasury systems.
Benefits
- ·Competitive compensation
- ·Career growth and learning opportunities
- ·Flexibility and ownership
- ·Collaborative and innovative culture
- ·Opportunity to work on impactful AI projects
How to apply
- 1Check the flexibility label above, region restricted, matches where you plan to live and work.
- 2Tailor your CV to the role at Nebius, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 3d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open other roles with comparable remote rules.
Free to apply, no account needed.
$120,000 to $180,000 · You'll be taken to the employer's careers page.