Senior Director, IT Governance, Risk and Compliance

TKONew York, CT
$157,500 - $210,000

About The Position

The Senior Director, IT Governance, Risk and Compliance, is responsible for leading and executing core elements of TKO’s IT compliance program, with a focus on SOX and IT General Controls, audit readiness, governance documentation, benchmarking against recognized security frameworks, third-party assurance, and technical data reconciliation activities. Reporting to TKO’s SVP of IT Business Systems, this role will partner closely with Legal, IT, Security, Internal Audit, Finance, and business stakeholders to strengthen TKO’s control environment, support enterprise compliance obligations, help lead risk management, and drive consistent execution across systems and processes. This role requires both strategic oversight and hands-on execution. The successful candidate will bring deep experience in IT compliance and controls, strong technical data management capability, and the ability to operate effectively across a complex environment with disparate systems, inconsistent data structures, and evolving business needs.

Requirements

  • Bachelor’s degree in Computer Science, Information Systems, Information Security, Accounting, Finance, or a related field
  • 10+ years of significant progressive experience in IT compliance, IT audit, risk management, cybersecurity compliance, or a related governance function
  • Demonstrated experience supporting SOX and IT General Controls in a complex environment
  • Experience developing and enhancing Risk and Control Matrices, process flows, remediation plans, system inventories, and related compliance documentation
  • Strong cross-functional partnership experience with Legal, IT, Security, Internal Audit, Finance, and business stakeholders
  • Strong knowledge of SOX, ITGC, and general compliance frameworks
  • Advanced proficiency in Excel with a strong working knowledge of PowerQuery, SQL, or similar tools preferred
  • Understanding of access management, vendor management, change management, and audit evidence requirements
  • Strong analytical and problem-solving skills with exceptional attention to detail
  • Excellent written and verbal communication skills, including the ability to communicate technical concepts to non-technical stakeholders
  • Strong organizational, project management, and documentation skills
  • High degree of integrity, discretion, and professional judgment
  • Ability to balance strategic priorities with hands-on execution

Nice To Haves

  • Experience supporting compliance activities in connection with mergers and acquisitions
  • Experience managing third-party assurance processes, including SOC report review and evaluation
  • Familiarity with enterprise control frameworks such as NIST and ISO 27001
  • Experience in a public company or similarly regulated environment
  • Knowledge of SAP (S/4) a plus as this is our Enterprise Finance and Accounting ERP
  • Certified Information Systems Auditor (CISA)
  • Certified Information Systems Security Professional (CISSP)
  • Certified in Risk and Information Systems Control (CRISC)

Responsibilities

  • Establish an overall compliance strategy and roadmap which includes selecting and implementing an enterprise Governance, Risk and Compliance platform to automate RCM authoring and drive evidence collection workflows.
  • Own prioritization, tracking, and delivery of key compliance initiatives including executive status updates regarding the program status and health.
  • Provide subject matter expertise and guidance to system leads and business partners on compliance expectations, control execution, documentation standards, and system implementation lifecycle considerations.
  • Advise and ensure PCI compliance is being sustained by in-scope business units.
  • Oversee internal resources, project-based support, or cross-functional contributors in connection with audit preparation, SOC reporting, PCI compliance adherence, and compliance execution.
  • Support and evolve existing IT Risk Management Program to ensure controls address Technology, Cybersecurity, Data, Resiliency/Recovery, and Emerging (AI, etc.) risks.
  • Establish IT compliance requirements.
  • Identify and eliminate redundant risk management processes and/or controls.
  • Understand and support the risk management objectives of other risk management functions.
  • Maintain current inventories of in-scope systems and applications that are required to support key regulatory requirements (e.g., ICFR), in-flight IT projects, and relevant stakeholders.
  • Develop the framework and standards for core IT compliance documentation and templates, including Risk and Control Matrices, process flows, system interface documentation, and remediation plans.
  • Determine the review criteria and cadence for assessing documentation prepared by system leads and control owners for quality, completeness, and alignment with compliance requirements.
  • Establish policies, procedures, and governance practices that support effective and sustainable compliance execution.
  • Act as primary point of contact for IT compliance supporting internal and external audits, including SOX and IT General Controls testing.
  • Organize, collect, and maintain evidence required for audit requests and management review.
  • Liaise with internal stakeholders and auditors to ensure timely and accurate delivery of required materials.
  • Create repeatable processes for the identification, tracking, and remediation of control gaps, deficiencies, and related action plans.
  • Create and support an IT risk assessments, control reviews, and compliance evaluations process.
  • Manage the lifecycle of Service Organization Control reporting.
  • Ensure completion of management evaluation documentation related to third-party controls and reliance.
  • Support assessment of third-party compliance risk in areas such as access management, vendor management, and change management.
  • Partner with IT and Finance colleagues to monitor adherence with internal policies and key metrics regarding control environment activities (e.g. reconciliation activities, data analysis, data hygiene, etc.).
  • As part of the user termination process, work closely with the infrastructure and application system owners to ensure terminations are completed timely and if any are missed (outside the acceptable window), a full look back analysis is conducted and send confirmation materials to internal audit.
  • Establish continuous monitoring processes.
  • Monitor changes in relevant compliance, privacy, and security requirements and support translation of those requirements into practical business processes.
  • Prepare reporting for management regarding compliance status, risks, remediation efforts, and control effectiveness.
  • Collaborate with Internal Audit, financial controls and IT in the development of training materials related to IT compliance, data privacy, and security practices.
  • Support awareness efforts for IT teams and business stakeholders to promote a culture of accountability and compliance.

Benefits

  • health care
  • retirement
  • vacation
  • other paid time off
  • additional offerings
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service