Auf einen Blick
- Aufgaben: Werde IT-Risiko- und Kontrollmanager und forme die Zukunft der KI-Infrastruktur.
- Unternehmen: Nebius, ein führendes Unternehmen im Bereich Cloud-Infrastruktur für die globale KI-Wirtschaft.
- Vorteile: Wettbewerbsfähige Vergütung, Karrierewachstum, Flexibilität und ein innovatives Team.
- Weitere Informationen: Sei Teil eines schnelllebigen Unternehmens mit echten Entwicklungsmöglichkeiten.
- Warum dieser Job: Gestalte bedeutende KI-Projekte und arbeite in einem dynamischen, internationalen Umfeld.
- Qualifikationen: Mindestens 8 Jahre Erfahrung in IT-Risiken und -Kontrollen, idealerweise in einem technologieorientierten Umfeld.
Das prognostizierte Gehalt liegt zwischen 63000 - 77000 € pro Jahr.
About Nebius
Nebius is leading a new era in cloud infrastructure for the global AI economy.
We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.
Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.
Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel.
Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.
The role
Nebius is seeking a IT Risk & Controls Manager to act as an embedded risk partner to our engineering and technology organizations.
You will help scale and strengthen a modern IT SOX and controls framework across Nebius’s custom-built AI cloud platform, infrastructure, corporate technology environment and other systems supporting financial reporting.
This role goes beyond traditional IT audit testing.
You will work directly with engineering leaders, system owners, Finance, Internal Controls and external auditors to identify risk, design scalable controls, improve evidence quality, drive remediation and embed compliance into the way our technology organizations operate.
The successful candidate will combine deep IT risk and controls expertise with meaningful in-house technology experience.
You must be equally comfortable discussing technical control design with engineers, explaining risk implications to business leaders and aligning audit expectations with external assurance providers.
Your responsibilities will include
- Act as the risk and controls partner for an assigned technology organization or system portfolio, developing a detailed understanding of its architecture, operations, risks and financial-reporting dependencies.
- Own and continuously improve the relevant IT risk and control framework, including system scoping, risk assessment, RCM and control-catalogue maintenance, documentation and control ownership.
- Lead IT SOX readiness for assigned systems, including walkthrough preparation, evidence-quality review, testing coordination, issue evaluation and remediation oversight.
- Partner with engineering, platform, infrastructure, security and corporate IT teams to design and implement scalable controls that address risk while supporting operational efficiency.
- Design, assess and enhance ITGCs across areas such as user access, privileged access, segregation of duties, change management, SDLC, system operations, incident management and third-party services.
- Assess IT application controls, automated controls and IT-dependent business controls, including the completeness and accuracy of system-generated information used in business-process controls.
- Evaluate how business controls depend on systems, integrations, configurations, reports and underlying ITGCs, and work with both business and IT control owners to resolve gaps.
- Apply risk and controls thinking to modern engineering practices, including cloud infrastructure, Dev Ops, CI/CD, repositories, deployment processes, containerized environments and audit logging.
- Lead the assessment and remediation of control gaps arising from new systems, major technology transformations, platform changes, integrations and acquisitions.
- Review third-party assurance reports and determine the impact of vendor controls and complementary user-entity controls on the Nebius control environment.
- Maintain effective working relationships with external auditors and advisers, aligning on audit scope, evidence expectations, testing approaches, reliance opportunities, timelines and issue resolution.
- Translate complex technical risks and auditor requirements into practical guidance for engineering and system owners.
- Use data analytics, automation, continuous monitoring and AI-assisted tools to improve control coverage, evidence quality and the efficiency of the IT SOX program.
- Contribute to the development of IT controls methodology, standards, tooling, training, reporting and the broader Risk Partner operating model.
- Provide clear, concise updates on control health, audit readiness, deficiencies and remediation progress to senior technology and Finance stakeholders.
We expect you to have
- A degree in Information Systems, Computer Science, Engineering, Accounting, Finance or a related discipline, or equivalent professional experience.
- At least eight years of progressive experience in IT risk, IT controls, IT SOX, technology assurance, IT audit or a closely related area.
- Meaningful in-house technology or corporate ownership experience is required.
Big Four or consulting experience is valuable when combined with subsequent in-house responsibility, but an exclusively advisory or external-audit background will not be sufficient.
- Experience working in a first-line technology, engineering, systems or IT operations role, or as an embedded in-house risk partner supporting a technology organization.
- Hands-on experience in an engineering-led technology, cloud, Saa S, platform or digital-product environment.
- Strong practical knowledge of SOX 404, ITGCs, IT application controls, automated controls, COSO and COBIT.
- Demonstrated experience with control design, implementation, monitoring, evidence review, audit readiness, issue evaluation and remediation.
- Practical understanding of modern technology environments, including cloud infrastructure, IAM, Dev Ops, CI/CD, SDLC, software repositories, deployment practices, system integrations and container orchestration such as Kubernetes.
- Experience connecting business-process controls to supporting systems, automated controls, IPEs/IUCs and underlying IT dependencies.
- The ability to communicate effectively with engineers, technical leaders, Finance stakeholders and external auditors.
- Strong judgment and the confidence to challenge control owners while developing practical, scalable solutions.
- A highly autonomous and hands-on approach, with the ability to operate effectively in an evolving environment with incomplete processes and competing priorities.
- Strong written and verbal English.
- The ability to work effectively across international time zones and travel when needed to build relationships with key technology and audit stakeholders.
It will be an added bonus if you have
- A professional certification such as CISA, CRISC, CISM, CIA, CPA or an equivalent qualification.
- Experience building or materially transforming an IT SOX or technology-controls framework in a listed or pre-IPO technology company.
- Experience in AI infrastructure, cloud platforms, large-scale Saa S, fintech, marketplaces or another engineering-intensive environment.
- Experience with GRC and audit-management tools such as Workiva, Jira, Service Now GRC or similar platforms.
- Experience with enterprise Saa S and financial systems such as Net Suite, HR platforms, billing systems, procurement tools or treasury systems.
- Experience onboarding acquired companies or newly implemented systems into SOX scope.
- Experience with control automation, continuous monitoring, data analytics or AI-assisted assurance.
- Exposure to AI governance, AI/ML control environments or controls supporting AI-enabled development and operations.
Benefits & Perks
- Competitive compensation
- Career growth and learning opportunities
- Flexibility and ownership
- Collaborative and innovative culture
- Opportunity to work on impactful AI projects
- International environment and talented teams
What's it like to work at Nebius
Fast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI
Equal Opportunity Statement
Nebius is an equal opportunity employer.
We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment.
We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.
Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire.
If you need accommodations during the application process, please let us know.
IT Risks & Control Manager Arbeitgeber: Nebius
Nebius ist ein hervorragender Arbeitgeber, der eine dynamische und innovative Arbeitsumgebung bietet, in der Mitarbeiter die Möglichkeit haben, an bedeutenden KI-Projekten zu arbeiten. Mit einem starken Fokus auf Karrierewachstum, Flexibilität und einer kollaborativen Kultur fördert Nebius die persönliche und berufliche Entwicklung seiner Mitarbeiter. Die internationale Ausrichtung und das talentierte Team bieten zudem einzigartige Vorteile, um in einem sich schnell entwickelnden Bereich wie der Cloud-Infrastruktur für die globale KI-Wirtschaft erfolgreich zu sein.
StudySmarter Expertenrat🤫
Wir sind der Meinung, dass du so IT Risks & Control Manager erhalten könntest
✨Netzwerken in der IT-Community
In der IT-Consulting-Welt sollten wir regelmäßig auf Veranstaltungen wie Tech-Meetups oder Konferenzen gehen. Hier können wir nicht nur unser Netzwerk erweitern, sondern auch direkt mit potenziellen Arbeitgebern ins Gespräch kommen und unser Interesse an einer Vollzeitstelle zeigen.
✨Online-Foren und Gruppen nutzen
Sich in Online-Foren und Communities wie Stack Overflow oder LinkedIn-Gruppen umzusehen, kann uns helfen, Insider-Tipps zu erhalten und Informationen über offene Stellen in der IT-Beratung zu sammeln. Vergiss nicht, aktiv zu werden und Fragen zu stellen oder dein Wissen zu teilen – das erhöht unsere Sichtbarkeit!
✨Direkt bei Nebius bewerben
Viele Unternehmen, wie Nebius, stemmen ihre Vollzeitstellen bevorzugt über ihre eigenen Karriere-Webseiten. Also, lass uns regelmäßig auf deren Seite vorbeischauen und uns direkt bewerben, statt nur die üblichen Jobportale zu nutzen.
✨Überzeugende Projekte zeigen
Wir sollten unser Portfolio oder relevante Projekte gut sichtbar machen, egal ob das auf Github, persönlich oder auf LinkedIn ist. Bei IT-Consulting-Stellen kommt es oft auf praktische Erfahrungen an, also lass uns zeigen, was wir können!
Wir glauben, dass du diese Fähigkeiten brauchst, um IT Risks & Control Manager mit Bravour zu bestehen
Einige Tipps für deine Bewerbung 🫡
Zeige deine technischen Skills!:In der IT-Beratung zählen deine technischen Kenntnisse und Fähigkeiten. Achte darauf, relevante Programmiersprachen, Tools und Systeme in deinem Lebenslauf aufzulisten. Zeig auch, wenn du Zertifikate hast, die deine Kompetenz unterstützen – das könnte dir einen echten Vorteil verschaffen!
Verstehe die Branche!:Unterstreiche in deinem Anschreiben, dass du ein gutes Verständnis für aktuelle Trends und Herausforderungen in der IT-Branche hast. Zeig, dass du nicht nur die technischen Aspekte beherrschst, sondern auch die Bedürfnisse der Kunden erkennen und lösen kannst!
Deine Projekte zählen!:Falls du bereits an IT-Projekten gearbeitet hast, verlinke diese oder beschreibe sie in deinem Lebenslauf. Praktische Erfahrungen – sei es in Form von Praktika oder privaten Projekten – sind besonders wertvoll in der IT-Beratung. Zeige uns, was du kannst!
Individuelle Bewerbung ist der Schlüssel!:Jede Bewerbung sollte individuell auf Nebius und die ausgeschriebene Position IT Risks & Control Manager zugeschnitten sein. Teile uns mit, warum gerade du eine gute Wahl für unser Team bist. Das zeigt dein Engagement und deine Motivation, die über eine Standardbewerbung hinausgeht.
Wie man sich auf ein Vorstellungsgespräch bei Nebius vorbereitet
✨Technische Vorbereitung ist alles!
Da du dich auf eine Vollzeitstelle in der IT-Beratung bewirbst, solltest du dir wirklich einen Überblick über die wichtigsten Tools und Technologien verschaffen, die in der Branche verwendet werden. Sei bereit, technische Fragen zu beantworten, die sich auf Software-Architektur oder Systemintegration beziehen könnten.
✨Praxisbeispiele parat haben
In der IT-Beratung ist es wichtig, konkrete Beispiele aus deiner bisherigen Erfahrung zu bringen. Überlege dir Projekte, bei denen du erfolgreich einen Kunden beraten hast oder Herausforderungen gelöst hast. Das zeigt, dass du nicht nur theoretisches Wissen hast, sondern auch in der Praxis erfolgreich sein kannst.
✨Soft Skills betonen
Ein großer Teil der IT-Beratung ist die Kommunikation mit Kunden und das Verständnis ihrer Bedürfnisse. Bereite dich darauf vor, über deine zwischenmenschlichen Fähigkeiten zu sprechen, wie du mit herausfordernden Kunden umgehst oder wie du in Teams arbeitest. Das wird den Interviewern zeigen, dass du mehr als nur technisches Wissen mitbringst!
✨Fragen zum Unternehmen vorbereiten
Schau dir spezifisch die Projekte von Nebius an und überlege dir, welche Fragen du dazu stellen möchtest. Zeig Interesse an den aktuellen Herausforderungen, vor denen das Unternehmen steht, und wie du dazu beitragen könntest. Das hebt dich von anderen Bewerbern ab und zeigt, dass du wirklich motiviert bist.