IT Governance, Risk and Compliance Engineer Job in Chicago, IL:
Hybrid Position in Chicago
Contract To Hire
Pay Range: $60-75.00 per hour
Please no 3 rd
party or c2c candidates
Our client is seeking a Senior Associate in IT Governance Risk and Compliance to join their Cybersecurity and Compliance team. This role plays a key part in supporting the company’s SOX and IT compliance program by evaluating the design and operating effectiveness of IT controls, supporting control owners in consistent SOX adoption, and executing select compliance-owned controls.
The Senior IT GRC Associate will work closely with the company’s IT, Security and Finance departments, as well as its parent company’s teams, Internal Audit, and External Auditors to help maintain a strong, sustainable, and audit-ready IT control environment, while also identifying opportunities to improve efficiency and consistency across control execution.
Key Responsibilities of the IT Governance, Risk and Compliance Engineer Job in Chicago, IL:
IT Control Testing & Assurance
- Perform testing of IT General Controls (ITGCs), IT Application Controls (ITACs), and key system-generated reports in accordance with company policy and SOX requirements.
- Evaluate control design and operating effectiveness, develop testing procedures, review evidence, and clearly document results.
- Perform re-testing and validate remediation efforts for control deficiencies.
- Support testing related to enterprise systems.
- Partner with IT and business control owners to support SOX compliance adoption and drive consistency in control execution.
- Provide guidance on documentation standards, evidence expectations, and process improvements.
- Participate in SOX walkthroughs and serve as a key liaison for Internal and External Audit requests.
- Execute and document controls managed by the Cyber and Compliance team, including access reviews, privileged/admin activity reviews, authentication reviews, and key report validations.
- Ensure controls are performed accurately, completely, and on time per defined frequency.
- Review user access provisioning, modifications, and terminations for in-scope systems.
- Assist in monitoring and review of privileged access and administrative activity.
- Identify control gaps, policy deviations, and risks, and recommend remediation or enhancements.
- Maintain audit-ready documentation within GRC tools or designated repositories.
- Help standardize control descriptions, testing approaches, and evidence requirements.
- Identify opportunities to streamline, automate, or improve the effectiveness of controls and compliance processes.
Qualifications of the IT Governance, Risk and Compliance Engineer Job in Chicago, IL:
Required
- Bachelor’s degree in Information Systems, Cybersecurity, Accounting, Finance, or a related field (or equivalent experience).
- 3–5 years of experience in IT GRC, IT audit, SOX compliance, technology risk, or a related role.
- Hands-on experience testing ITGCs and supporting SOX compliance activities.
- Understanding of logical access controls, change management, and IT operations controls.
- Strong analytical skills with attention to detail and sound judgment.
- Ability to clearly communicate control requirements and testing outcomes to both technical and non-technical stakeholders.
- Experience with Microsoft Dynamics 365 Finance and Operations (D365 F&O) control testing or audit support.
- Prior experience executing or testing IT Application Controls (ITACs).
- Familiarity with GRC tools (e.g., AuditBoard, Workiva, Fastpath).
- Working knowledge of identity and access management (IAM) concepts.
- Professional certifications such as CISA, CISM, CRISC, or CIA.
Benefits
Nesco Resource offers a comprehensive benefits package for our associates, which includes a MEC (Minimum Essential Coverage) plan that encompasses Medical, Vision, Dental, 401K, and EAP (Employee Assistance Program) services.
Equal Employment Opportunity
Nesco Resource provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.
CTD116
#LI-TS2




