Title: Director, IT Governance, Risk & Compliance
Irving, TX, US, 75039
it's what's inside that counts
_______________________________
There’s more to CMC than our products and the buildings, structures, and roads they go into. At CMC, it’s the people inside our recycling centers, fabrication plants, manufacturing facilities, steel mills and offices that make us who we are as a company. Our success comes from finding, retaining, and supporting the highest quality talent by offering:
- Day 1 Benefits Coverage with low cost Medical, Vision, Dental
- Day 1 Paid-time Off and Vacation
- 4.5% Company Match 401(k) plan
- $500 Annual Company-paid Lifestyle Benefit
- Competitive Compensation and Bonuses
- Company-paid Life and Disability Insurance
- Employee Stock Purchase Plan
- Training and Advancement Opportunities
Why This Job
CMC provides an excellent opportunity to learn the steel, construction reinforcement and ground stabilization industries and to grow in your career. Whether you will spend your day brainstorming in an office cubicle, operating a crane, running manufacturing equipment or troubleshooting technical obstacles, at CMC, you’ll get the training and support from your team that you need to excel in your role and reach your full potential.
What You'll Do
- Lead the continued maturation of CMC's IT Governance, Risk & Compliance program and define the next phase of its maturity strategy
- Establish consistent governance standards, accountability models, decision rights, and control ownership across technology functions
- Strengthen control design, policy management, compliance monitoring, and standard artifacts, with rigor proportionate to financial, regulatory, cybersecurity, and operational risk
- Drive alignment among business objectives, technology strategy, compliance requirements, and risk management priorities
- Promote a culture of accountability, operational discipline, and continuous improvement in which compliance is embedded in day-to-day delivery
- Serve as the primary IT leadership interface for Internal Audit, external auditors, and compliance stakeholders
- Improve audit readiness through standardized evidence management, documentation practices, remediation governance, control monitoring, request intake, and clear closure criteria
- Partner with technology and business leaders to proactively address audit findings, improve evidence quality, and reduce recurring deficiencies and late-cycle surprises
- Provide executive-level insight on governance maturity, compliance performance, control effectiveness, remediation aging, evidence quality, and emerging risk
- Ensure compliance activities improve operations and control effectiveness rather than simply satisfy audit requirements, while maintaining the distinction between management ownership and independent assurance
- Oversee ITGC and SOX compliance across access management, change management, computer operations, interfaces, key reports, and technology-dependent controls
- Establish and execute annual approach to IT SOX scoping in collaboration with Internal Audit and management stakeholders
- Direct governance for SAP access, segregation of duties, privileged access, Firefighter / emergency access, user access reviews, and SAP GRC capabilities
- Establish a risk-based method to prioritize deficiencies by financial reporting exposure, regulatory impact, cybersecurity risk, and operational complexity
- Partner with IT, Finance, Internal Audit, Cybersecurity, and business stakeholders to support effective governance, compliance, and control execution
- Support business units and control owners in identifying IT control gaps
- Provide training and guidance to IT control owners and business unit managers on SOX requirements, control objectives, and best practices
- Implement a repeatable evidence operating model with standardized repositories, request ownership, naming conventions, quality checks, retention requirements, and closure criteria
- Drive timely, sustainable remediation of deficiencies and validate that corrective actions are designed, implemented, documented, and testable
- Establish dashboards and metrics that show control effectiveness, exceptions, remediation progress, audit demand, and recurring failure patterns
- Identify opportunities to automate controls, evidence collection, access reviews, monitoring, and reporting through SAP GRC and other enabling technologies
- Use lessons learned from audits and control failures to improve processes, training, system design, and accountability
- Work with management to evaluate control evidence against quality standards prior to submitting it to auditors
- Identify control deficiencies and recommend remediation plans in collaboration with Internal Audit
What You'll Need
- 12+ years of progressive experience in IT audit, technology risk, governance, compliance, cybersecurity assurance, or related disciplines, including at least 5 years leading managers or senior professional teams
- Proven experience leading and maturing an IT audit, technology compliance, governance, or technology risk organization within a large, complex enterprise
- Prior Big 4 public accounting or external audit experience serving large companies is strongly preferred, with direct responsibility for IT audit, SOX ITGC, controls assurance, or technology risk engagements
- Deep knowledge of SOX ITGCs, control design and testing, risk assessment, deficiency evaluation, remediation, audit evidence, and management reporting
- Strong working knowledge of enterprise applications and infrastructure controls, including SAP security, segregation of duties, privileged access, change management, computer operations, interfaces, and key reports
- Demonstrated success improving audit readiness, strengthening control environments, reducing repeat findings, and advancing compliance program maturity beyond tactical audit response
- Executive-level communication and stakeholder management skills, including the ability to influence across IT, Finance, Internal Audit, external auditors, and business leadership
- CISA certification strongly preferred. CPA, CIA, CRISC, or other relevant certification is a plus
- Experience with SAP S/4HANA, SAP GRC, ServiceNow GRC / IRM, Workiva, Archer, MetricStream, or comparable governance and compliance platforms
- Knowledge of commonly used frameworks and requirements such as COBIT, COSO, NIST CSF, ISO 27001, SOC reporting, CMMC, NIS2, and AI governance
Your Education
- Bachelor's degree in Information Systems, Accounting, Finance, Cybersecurity, Business, or a related field. MBA preferred
We are CMC, a Fortune 500® company at the leading edge of our industry. Our construction reinforcement and steel products have supported construction projects and structures around the world. The secret to our success? We’ve built our legacy by assembling a team of innovators and doers to tackle some of the most challenging construction reinforcement problems facing our world for more than 100 years — and we’re just getting started.
If you’re ready to join a team working to make our industry more sustainable, support the bridges, roadways, buildings and infrastructure that connects our communities, and do meaningful work, you’re ready to join CMC. Apply today and start moving your career — and our world — forward. Let's build a better world!
CMC is committed to providing equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, age, physical or mental disability, national origin, citizenship, military or veteran status, sexual orientation, gender identity and/or expression, genetic information, or other status protected by federal, state or local law.
From Fortune Magazine. © 2025 Fortune Media IP Limited. All rights reserved. Used under license.
Nearest Major Market: Irving
Nearest Secondary Market: Dallas