Jobs and Careers
MC

Senior Technology Spec (IT)

McDermott
United Statesfull_timeVerifiedPosted 16 Aug 2026

About the role

Job Overview:

The Senior Technology Specialist (IT) – IT Controls and Compliance is a hands-on compliance and audit professional responsible for supporting the organization's SOX compliance program, ISO certification, IT audits and maintaining an effective IT control environment.

This role works directly with IT, cybersecurity, finance, business process owners, Internal Audit, and external auditors to document controls, perform walkthroughs, validate evidence, execute control testing, support audits, and drive process improvements. The position requires strong communication skills, attention to detail, analytical capabilities, and the ability to build productive working relationships across technical and non-technical teams.

The successful candidate will help ensure IT controls are consistently executed, properly documented, supported by appropriate evidence, and maintained in a manner that supports external audit requirements and overall audit readiness.

Key Tasks and Responsibilities: 
 

SOX Compliance & IT Controls

  • Maintain and continuously improve SOX IT General Controls (ITGCs), IT Application Controls (ITACs), and IT-Dependent Manual Controls (ITDMs) supporting financial reporting.
  • Develop and maintain audit-ready documentation including narratives, process flows, risk and control matrices (RACMs), control procedures, evidence requirements, and testing support materials.
  • Coordinate and perform process walkthroughs with control owners to validate control execution and identify control gaps.
  • Evaluate control design and operating effectiveness across: 
    • Logical Access Management
    • Privileged Access Management
    • Change Management
    • System Development Lifecycle (SDLC)
    • IT Operations
    • Backup & Recovery
    • Disaster Recovery
    • Segregation of Duties (SoD)
    • IT-Dependent Manual Controls (ITDMs)
    • Management Review Controls
  • Assess completeness and accuracy of reports, system-generated data, and evidence used to support key controls.
  • Support annual SOX testing, management assessments, and external audit activities.
  • Assist control owners in addressing deficiencies and strengthening control execution.

     

Audit & Risk Assessments

  • Plan and execute risk-based IT and cybersecurity audits from planning through reporting.
  • Conduct interviews and walkthroughs with technology teams, business stakeholders, and process owners.
  • Perform testing of controls, evaluate supporting evidence, document results, and communicate findings.
  • Develop practical recommendations that improve controls while minimizing unnecessary operational burden.
  • Track audit findings and remediation activities through resolution.

     

Data Analytics & Evidence Review

  • Analyze large data sets using Excel and enterprise reporting tools to support audits, control testing, and risk assessments.
  • Perform user access reviews, role analysis, segregation of duties assessments, exception analysis, sampling, reconciliations, and trend analysis.
  • Validate system populations and report completeness and accuracy used for SOX testing.
  • Identify anomalies, outliers, control failures, and compliance concerns through data analysis.
  • Prepare audit workpapers, testing documentation, management reports, and auditor support packages.

     

Governance & Process Improvement

  • Partner with IT and business stakeholders to improve control processes, documentation quality, and audit readiness.
  • Recommend opportunities to simplify, standardize, and mature governance and compliance activities.
  • Support compliance initiatives aligned with SOX, NIST Cybersecurity Framework, and ISO 27001 requirements.
  • Participate in reviews of third-party assurance reports (SOC reports) and technology risk assessments as assigned.

     

Stakeholder Engagement & Communication

  • Build working relationships with IT, cybersecurity, finance, Internal Audit, external auditors, and control owners.
  • Facilitate control walkthroughs, testing discussions, audit meetings, and remediation workshops.
  • Translate technical risks, control issues, and audit findings into clear business language.
  • Provide practical guidance to stakeholders on compliance requirements and auditor expectations.
  • Influence positive change through collaboration, credibility, and strong communication rather than formal authority.

Essential Qualifications and Education: 
 

  • 8+ years of direct-full-time experience in IT audit, SOX compliance, IT controls, cybersecurit

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

McDermott

View company profile →