Staff Governance, Risk and Compliance Analyst

StubHubNew York, NY
$200,000 - $250,000Hybrid

About The Position

As part of the GRC organization, the GRC Staff Analyst typically acts as the central coordinator between Engineering, Finance, and Internal Audit, ensuring that control owners execute controls while driving audit readiness and continuous improvement across the SOX program. This is a hands-on individual contributor role, and this person will report to the Director of Engineering and GRC, defining our control implementation strategy and owning its execution across compliance frameworks we operate.

Requirements

  • 7+ years of experience managing a SOX program or external audit program, ideally within a pre-IPO or newly public environment.
  • Deep understanding of SOX 404 ITGCs and strong working knowledge of PCAOB standards, COSO, and SOX 302/404 requirements.
  • Experience in a global marketplace, e-commerce, ticketing, or other high-transaction-volume environment with multi-entity international operations.
  • Strong knowledge of identity governance, access controls, change management, control design, and remediation.
  • Experience working with Big 4 external auditors.
  • Excellent project and stakeholder management skills, with the ability to influence across Engineering, Finance, Audit, and business teams.
  • Strong analytical, documentation, and executive communication skills.

Nice To Haves

  • CISA, CIA, CISSP, AAIA, AAIR, or similar certification.
  • Experience supporting a company through IPO readiness or the transition to being publicly traded.
  • Familiarity with COBIT, COSO, and NIST.
  • Familiarity with modern cloud, data, and engineering environments and GRC tooling.

Responsibilities

  • Serve as the primary SOX point of contact for Technology Operations and FinTech.
  • Own the end-to-end SOX calendar, including planning, testing, control execution, evidence collection, remediation, and reporting.
  • Partner with Internal Audit, External Audit, Finance, GRC, and Technology leadership throughout the SOX lifecycle.
  • Coordinate walkthroughs, control demonstrations, auditor requests, and quarterly and annual testing activities.
  • Own SOX scoping, risk assessments, control design and implementation, and remediation tracking.
  • Maintain the inventory of SOX-relevant systems, applications, infrastructure, and control owners.
  • Track findings and observations through remediation and validate corrective actions with control owners.
  • Oversee the design, execution, and documentation of ITGCs, IT Application Controls, and IT dependencies across: User and privileged access management, Joiner/Mover/Leaver processes, Change management and production deployments, Computer operations, backup, and recovery, Program development and SDLC, Reports, system interfaces, and segregation of duties.
  • Develop and maintain control narratives, process and data flows, SOPs, risk-control matrices, and supporting documentation.
  • Monitor control performance and proactively identify potential deficiencies before audit testing.
  • Evaluate new systems, technologies, and business initiatives for SOX impact and required control changes.
  • Maintain a centralized risk register with clear ownership and prioritization across the technology stack.
  • Perform risk assessments for changes affecting financial systems and IT controls.
  • Assess emerging technology and regulatory risks and determine their impact on the control environment.
  • Embed compliance-by-design principles into how teams build and ship products and technology.
  • Drive standardization and automation across controls, evidence collection, and GRC workflows.
  • Establish clear accountability, escalation paths, and governance structures.
  • Maintain policies that satisfy applicable compliance and security requirements.
  • Reduce audit effort through improved processes, documentation, tooling, and automation.
  • Partner closely with Finance, Internal Audit, External Audit, Information Security, Engineering, FinTech, and Product.
  • Build a strong compliance culture by helping teams understand the “why” behind requirements and driving stakeholder adoption.
  • Develop dashboards and KPIs covering control execution, audit readiness, evidence timeliness, deficiencies, remediation progress, and repeat findings.
  • Prepare and present executive-level updates on testing progress, risks, deficiencies, and remediation status to Technology leadership.

Benefits

  • Accelerated Growth Environment
  • Top Tier Compensation Package
  • Unlimited Flex Time Off
  • 401k
  • Health Insurance
  • Vision Insurance
  • Dental Insurance
  • paid parental leave
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service