IT Risks & Control Manager

IT Risks & Control Manager

Full-Time 70000 - 90000 £ / year (est.) Home office (partial)
Nebius

At a Glance

  • Tasks: Lead IT risk and controls for cutting-edge AI cloud technology.
  • Company: Join Nebius, a leader in AI cloud infrastructure with a global presence.
  • Benefits: Enjoy competitive pay, career growth, and a flexible work environment.
  • Other info: Be part of a fast-paced, innovative culture that values bold thinking.
  • Why this job: Make a meaningful impact on the future of AI while working with top talent.
  • Qualifications: 8+ years in IT risk and controls; tech-savvy with strong communication skills.

The predicted salary is between 70000 - 90000 £ per year.

About Nebius

Nebius is leading a new era in cloud infrastructure for the global AI economy.

We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.

Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.

Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel.

Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.

The role

Nebius isseekinga IT Risk & Controls Managerto act as an embedded risk partnertoour engineering and technology organizations.

You will help scale and strengthen a modern IT SOX andcontrolsframework across Nebius’scustom-built AI cloud platform, infrastructure, corporate technologyenvironmentand other systems supporting financial reporting.

This role goes beyond traditional IT audit testing.

You will work directly with engineering leaders, system owners, Finance, Internal Controlsand external auditors toidentifyrisk, design scalable controls, improve evidence quality, driveremediationand embed compliance into the way our technology organizationsoperate.

The successful candidate will combine deep IT risk andcontrolsexpertisewith meaningful in-house technology experience.

You must be equally comfortable discussing technical control design with engineers, explaining risk implications to businessleadersand aligning audit expectations with external assurance providers.

Your responsibilities will include

  • Act as the risk and controls partner for an assigned technology organization or system portfolio, developing a detailed understanding of its architecture, operations, risksand financial-reporting dependencies.
  • Own and continuously improve the relevant IT risk and control framework, including system scoping, risk assessment, RCM and control-catalogue maintenance, documentationand control ownership.
  • Lead IT SOX readiness for assigned systems, including walkthrough preparation, evidence-quality review, testing coordination, issueevaluationand remediation oversight.
  • Partner with engineering, platform, infrastructure, securityand corporate IT teams to design and implement scalable controls that address risk while supporting operational efficiency.
  • Design, assess and enhance ITGCs across areas such as user access, privileged access, segregation of duties, change management, SDLC, system operations, incidentmanagementand third-party services.
  • Assess IT application controls, automated controls and IT-dependent business controls, including the completeness and accuracy of system-generated information used in business-process controls.
  • Evaluate how business controls depend on systems, integrations, configurations, reports and underlying ITGCs, and work with both business and IT control owners to resolve gaps.
  • Apply risk and controls thinking to modern engineering practices, including cloud infrastructure, Dev Ops, CI/CD, repositories, deployment processes, containerizedenvironmentsand audit logging.
  • Lead the assessment and remediation of control gaps arising from new systems, major technology transformations, platform changes, integrationsand acquisitions.
  • Review third-party assurance reports anddeterminethe impact of vendor controls and complementary user-entity controls on the Nebiuscontrol environment.
  • Maintain effective working relationships with external auditors and advisers, aligning onaudit scope, evidence expectations, testing approaches, reliance opportunities, timelines and issue resolution.
  • Translate complex technical risks and auditor requirements into practical guidance for engineering and system owners.
  • Use data analytics, automation, continuousmonitoringand AI-assisted tools to improve control coverage, evidencequalityand the efficiency of the IT SOX program.
  • Contribute to the development of IT controlsmethodology, standards, tooling, training, reporting and the broader Risk Partner operating model.
  • Provide clear, concise updates on control health, audit readiness, deficiencies and remediation progress to senior technology and Finance stakeholders.

We expect you to have

  • A degree in Information Systems, Computer Science, Engineering, Accounting, Finance or a related discipline, or equivalent professional experience.
  • At least eight years of progressive experience in IT risk, IT controls, IT SOX, technology assurance, ITauditor a closely related area.
  • Meaningful in-house technology or corporate ownership experience isrequired.

Big Four or consulting experience is valuable when combined withsubsequentin-house responsibility, but an exclusively advisory or external-audit background will not be sufficient.

  • Experience working in a first-line technology, engineering, systemsor IT operations role, or as an embedded in-house risk partner supporting a technology organization.
  • Hands-on experience in an engineering-led technology, cloud, Saa S, platformor digital-product environment.
  • Strong practical knowledge of SOX 404, ITGCs, IT application controls, automated controls, COSOand COBIT.
  • Demonstrated experience with control design, implementation, monitoring, evidence review, audit readiness, issueevaluationand remediation.
  • Practical understanding of modern technology environments, including cloud infrastructure, IAM, Dev Ops, CI/CD, SDLC, software repositories, deployment practices, systemintegrationsand container orchestration such as Kubernetes.
  • Experience connecting business-process controls to supporting systems, automated controls, IPEs/IUCsand underlying IT dependencies.
  • The ability to communicate effectively with engineers, technical leaders, Financestakeholdersand external auditors.
  • Strong judgment and the confidence to challenge control owners while developing practical, scalable solutions.
  • A highly autonomous and hands-on approach, with the ability tooperateeffectively in an evolving environment with incomplete processes and competing priorities.
  • Strong written and verbal English.
  • The ability to work effectively across international time zones and travel when needed to build relationships with key technology and audit stakeholders.

It will be an added bonus if you have

  • A professional certificationsuch as CISA, CRISC, CISM, CIA, CPAoran equivalentqualification.
  • Experience building or materially transforming an IT SOX or technology-controlsframework in a listed or pre-IPO technology company.
  • Experience in AI infrastructure, cloud platforms, large-scale Saa S, fintech, marketplacesor another engineering-intensive environment.
  • Experience with GRC andaudit-managementtools such as Workiva, Jira, Service Now GRC or similar platforms.
  • Experience with enterprise Saa S and financial systems such as Net Suite, HR platforms, billing systems, procurementtoolsor treasury systems.
  • Experience onboardingacquiredcompanies or newly implemented systems into SOX scope.
  • Experience with control automation, continuous monitoring, dataanalyticsor AI-assisted assurance.
  • Exposure to AI governance, AI/ML control environments or controls supporting AI-enabled development and operations.

Benefits & Perks

  • Competitive compensation
  • Career growth and learning opportunities
  • Flexibility and ownership
  • Collaborative and innovative culture
  • Opportunity to work on impactful AI projects
  • International environment and talented teams

What's it like to work at Nebius

Fast moving- Bold thinking- Constant growth- Meaningful impact- Trust and real ownership- Opportunity to shape the future of AI

Equal Opportunity Statement

Nebius is an equal opportunity employer.

We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment.

We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.

Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire.

If you need accommodations during the application process, please let us know.

#J-18808-Ljbffr

IT Risks & Control Manager employer: Nebius

Nebius is an exceptional employer that fosters a dynamic and innovative work culture, particularly for those in the Remote Field CTO role. With flexible working options in London or remotely, employees benefit from a supportive environment that encourages professional growth and collaboration, while also having the unique opportunity to shape cutting-edge cloud services in the retail sector.

Nebius

Contact Details:

Nebius Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land IT Risks & Control Manager

Join the IT Consultancy Buzz

Get involved in local or virtual IT consultancy meetups and forums. This is where we can rub shoulders with industry professionals, get insights into what Nebius values, and even spot unadvertised opportunities. Don't miss out on these chances to make a name for ourselves in the IT world!

Show Off Your Skills

Create a personal project or case study relevant to the challenges Nebius might face. Use platforms like GitHub or Medium to share your findings. This not only demonstrates our consulting skills but shows a proactive attitude, making us stand out from the crowd when applying for that full-time gig.

Leverage LinkedIn for Connections

Follow and engage with the relevant thought leaders and influencers in IT consultancy on LinkedIn. Share insightful content and join discussions to gain visibility. A well-placed comment or shared article could catch the attention of someone at Nebius!

Direct Apply to Nebius

Let's not forget to apply directly through the Nebius website! Tailor your application to showcase our understanding of their consulting style and how we can contribute to their projects. A personalised approach can make a huge difference in landing that full-time position!

We think you need these skills to ace IT Risks & Control Manager

IT Risk Management
IT Controls
SOX Compliance
Risk Assessment
Control Design
Evidence Review
Data Analytics

Some tips for your application 🫡

Showcase Your Problem-Solving Skills:In IT consulting, it's all about problem-solving, so make sure your CV highlights your analytical skills and any relevant projects you've tackled. Mention specific technologies or methodologies you've used to resolve issues or improve processes; this shows you can think critically and deliver results, which is vital for us at Nebius.

Highlight Relevant Certifications:Certifications like ITIL, PMP, or even specific tech stack qualifications can really make you stand out. Make sure to include these in your CV, as they not only demonstrate your expertise but also your commitment to staying current in the field. We love seeing candidates who are proactive about their professional development!

Tailor Your Cover Letter:Your cover letter is your chance to connect personally with us at Nebius. Share stories about your experiences in IT consulting, and how they shaped your desire to join our team. Mention why you’re excited about this particular role, and how you see yourself contributing to our projects.

Keep It Clear and Concise:We're all busy, so make sure your application is easy to read. Use bullet points for key achievements, and don’t overload us with jargon. A clean, professional layout goes a long way. Remember, the clearer your application, the more likely we are to invite you in for an interview!

How to prepare for a job interview at Nebius

Brush Up on Your Technical Skills

For an IT consulting role, be ready to demonstrate your technical prowess. You might face questions on systems integration, cloud technologies, or even troubleshooting specific software. If you have experience with tools like AWS, Azure, or even specific programming languages, make sure you can talk about them fluently.

Showcase Your Problem-Solving Approach

IT consulting is all about solving problems for clients. Think about how you can illustrate your approach to a past challenge using the STAR method (Situation, Task, Action, Result). It's a great way to show how you tackle complex issues and come up with effective solutions.

Know the Business Impact of IT Solutions

When discussing your experiences, focus not just on the tech solutions you implemented, but also on their business impact. Employers want to see that you can connect IT with organisational goals. Prep examples that highlight how your tech contributions improved efficiency or reduced costs for past clients or projects.

Prepare for Behavioural Questions

Since IT consulting often involves teamwork and client interactions, expect behavioural questions that assess your interpersonal skills. Be prepared with examples that demonstrate your adaptability, communication skills, and how you handle client feedback. Before the interview, think of situations where you worked closely with clients to create effective IT strategies or changes.