Senior Product Manager, Compliance

Weights & Biases Weights & Biases · Data AI · Bellevue, WA +4 · Information Technology

Senior Product Manager, IT SOX Compliance role focused on translating SOX requirements into structured programs, driving accountability, and building scalable compliance systems within the CIO organization. Responsibilities include owning the IT SOX program, managing control inventory, control design and documentation, partnering with teams on new system implementations, reviewing evidence, managing deficiencies, and leading root cause analysis.

What you'd actually do

  1. Own the end-to-end IT SOX compliance program within the CIO organization, maintaining the IT control inventory spanning ITGCs, IT-dependent controls, and automated application controls
  2. Own the control design and documentation, including narratives and risk and control matrices (RCMs), ensuring controls are clearly defined and audit-ready
  3. Partner with IT, Accounting (where needed), and the SOX team to ensure new systems and modules are implemented with appropriate SDLC controls in place prior to go-live; review control designs to identify and mitigate SOX risks
  4. On an ongoing basis, partner with IT process owners and control operators to ensure controls are executed in a timely manner
  5. Review control evidence for quality and completeness before submission to auditors

Skills

Required

  • 8+ years of experience in IT audit, IT risk, IT compliance, or a related field
  • Hands-on IT SOX experience
  • Deep familiarity with IT General Controls (ITGCs) — access management, change management, SDLC, and computer operations
  • Strong understanding of PCAOB auditing standards, COSO framework, and COBIT
  • Demonstrated ability to manage multiple workstreams, deadlines, and stakeholders
  • Experience with GRC platforms (e.g., AuditBoard, ServiceNow GRC, Workiva, or similar)

Nice to have

  • CISA, CISSP, CISM, or CPA certification
  • Experience in a hyperscaler, cloud infrastructure, or high-growth tech environment
  • Proven ability to establish or scale SOX IT compliance programs at newly public or pre-IPO companies

What the JD emphasized

  • IT SOX compliance
  • ITGCs
  • control design
  • documentation
  • root cause analysis
  • remediation plans