FLEX Director, IT Governance, Audit and Compliance
Marriott InternationalAbout the role
JOB SUMMARY
The Director, IT Governance, Audit & Compliance, is a leadership role responsible for serving as the governance, audit and compliance execution arm for IT controls managed under the Technology Experience Center (TEC) organization.
This role works with IT Provision Owners to perform the governance, oversight, and reporting for regulatory controls that align under IT Asset Inventory, Change Management, Software End of Life (EOL) and Hardware Removal. The Director ensures controls are consistently designed, executed, evidenced, and audit ready in alignment with internal policy, regulatory obligations, and external audit requirements.
The Director partners closely with Marriott IT Control Owners, Product Owners, Application Owners, Infrastructure and Application teams, Security, and Risk Management to facilitate quarterly and annual audits. This role will manage a team who will be responsible for coordinating evidence collection, management for remediation of control gaps, and provide clear, compliance reporting to leadership, Internal Audit, and external regulators.
This role requires deep understanding of IT Operations, Software Development Lifecycle, regulatory control frameworks, audit methodology, and process maturity models (e.g., CMMI) and serves as a key advisor to TEC IT Provision Owners and the GIS Compliance Program on compliance risk, control effectiveness, and continuous improvement.
KEY RESPONSIBILITIES:
IT Governance & Regulatory Compliance
· Act as the TEC aligned control execution authority for regulatory IT controls, including Asset Inventory, Change Management, and Software End of Life.
· Work with TEC IT Provision and Control Owners for alignment on policy, standard operating procedures, and control execution requirements.
· Responsible for control design validation, operational execution oversight, and compliance reporting for TEC managed controls.
· Establish and maintain standardized governance processes, control narratives, and operating procedures to ensure consistency and auditability.
· Ensure alignment of TEC controls with enterprise policies, regulatory obligations, and audit expectations.
Audit Management & Evidence Collection
· Lead quarterly and annual audit requirements, supporting Management Testing and external audit requests.
· Coordinate evidence collection, validation, and submission across multiple IT control owners and stakeholders.
· Serve as the primary point of contact for GIS Regulatory and Compliance organization and auditors related to TEC managed controls.
· Track, manage, and report on audit findings, observations, and remediation activities through closure.
Cross Functional Facilitation & Control Ownership
· Facilitate collaboration across TEC IT control owners to ensure timely and accurate control execution.
· Partner with Application, Infrastructure, Security, and Platform teams to operationalize compliance requirements.
· Drive accountability for control gaps, remediation plans, timelines, and ownership.
· Provide clear guidance and education to teams on control intent, expectations, and audit readiness.
Compliance Reporting & Risk Transparency
· Develop and deliver executive level compliance reporting, dashboards, and risk summaries.
· Provide leadership with clear visibility into control health, risk posture, and remediation progress.
· Support regulatory responses with accurate, evidence based narratives and documentation.
Process Maturity & Continuous Improvement
· Identify systemic control weaknesses and lead process improvements to reduce audit risk and operational friction.
· Establish repeatable, scalable compliance oversight processes to support long term regulatory sustainability.
Leadership and Business Acumen
· Lead and develop a compliance focused team responsible for governance execution and audit readiness.
· Establish clear performance expectations aligned to control execution quality, audit outcomes, and risk reduction.
· Partner effectively with senior leaders, control owners, and auditors as a trusted compliance authority.
· Demonstrate sound judgment, discretion, and professionalism when managing regulatory risk and audit interactions.
CANDIDATE PROFILE
Education & Experience
Required
· Bachelor’s degree or equivalent combination of education, certifications, and experience.
· 10+ years of progressive IT leadership experience, with demonstrated owner
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s