Governance, Risk, and Compliance Senior Associate, IT Controls & Assurance

WeaverNew York, NY
$82,000 - $100,000Onsite

About The Position

Weaver is seeking a Senior Associate to join their Governance, Risk, and Compliance (GRC) practice, focusing on IT controls and technology assurance. This role will be involved in System and Organization Controls (SOC) 1 and SOC 2 examinations, IT-related Sarbanes-Oxley (SOX) compliance engagements, and other information security and compliance projects. The GRC IT team collaborates with various departments to assess controls, provide recommendations, and ensure high-quality client service. Team members will gain experience across different industries and technologies, developing both technical and engagement management skills. The Senior Associate will lead workstreams, assist in planning, execution, supervision, and completion of engagements. The ideal candidate will possess strong professional judgment, IT controls knowledge, a willingness to review non-IT controls, clear communication skills, and the ability to manage multiple assignments while mentoring junior staff.

Requirements

  • Bachelor’s degree in Accounting, Management Information Systems, Computer Science, or related field
  • 2+ years of experience in professional services or similar field
  • Working knowledge of SOC reporting concepts and applicable attestation standards, including experience supporting SOC 1 and/or SOC 2 engagements
  • Understanding of SOX Section 404, internal control over financial reporting, and how technology risks and controls affect financial reporting
  • Ability to understand business and financial reporting processes, identify relevant technology risks, and connect IT controls to business, reporting, and security objectives
  • Experience reviewing workpapers and supervising, coaching, or informally leading junior team members
  • Strong written and verbal communication skills, including the ability to explain technical control matters to both technical and nontechnical stakeholders.
  • Strong organization, attention to detail, professional skepticism, and the ability to manage multiple priorities and deadlines
  • Ability to appropriately use firm-approved AI and automation tools to improve engagement efficiency, research, documentation, and data analysis while maintaining confidentiality, professional judgment, quality-control requirements, and compliance with firm policies
  • Ability to travel to client locations or Weaver offices as engagement needs require.

Nice To Haves

  • CISA, CPA, CIA, CISSP, CISM, or another relevant certification, or demonstrated progress toward certification
  • Awareness or exposure to relevant frameworks and criteria such as NIST, ISO/IEC 27001, HITRUST, PCI DSS, and other security or compliance standards
  • Experience with audit and GRC platforms such as Fieldguide, AuditBoard, Workiva, Drata, Vanta, or similar tools
  • Experience serving clients in financial services, technology, insurance, healthcare, or other regulated industries.

Responsibilities

  • Execute and help manage SOC 1 and SOC 2 Type 1 and Type 2 examinations, including planning, walkthroughs, risk assessment, control evaluation, testing, documentation, issue evaluation, and report support.
  • Perform IT SOX work over in-scope systems and processes, including IT general controls, automated controls, automated controls, key reports, interfaces, and other technology-dependent controls relevant to internal control over financial reporting.
  • Develop and maintain risk and control matrices (RCMs) during engagement planning, including documenting processes, identifying relevant risks, mapping controls to risks and engagement objectives, and defining appropriate control testing procedures.
  • Evaluate control design and operating effectiveness across logical access, change management, computer operations, cybersecurity, incident management, business continuity, vendor management, and related domains.
  • Develop and review process narratives, system descriptions, risk and control matrices, test plans, workpapers, evidence requests, and client-ready deliverables.
  • Identify exceptions and control gaps, assess their significance, and communicate clear, practical recommendations to engagement leadership and client stakeholders.
  • Coordinate day-to-day client requests, monitor engagement status and budgets, escalate risks promptly, and help keep concurrent projects on schedule.
  • Supervise and coach Associates by reviewing workpapers, providing timely feedback, and reinforcing firm methodology and quality expectations.
  • Support other technology risk, information security, and compliance engagements as business needs arise, which may include readiness assessments, internal audit, regulatory compliance, or controls advisory projects.
  • Contribute to practice development through methodology improvements, knowledge sharing, proposal support, and participation in recruiting and team initiatives.

Benefits

  • medical
  • dental
  • vision
  • disability
  • life insurance
  • 401(k) plan
  • flexible scheduled time off (STO)
  • minimum of 56 hours of sick and safe leave
  • 11 holidays
  • 2 scheduled recharge days
  • in-house CPE and learning opportunities through our internal Learning & Development department
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service