HubSpot Jobs

Director, Enterprise Risk Management & IT SOX Risk Advisory

Remote - USAFull timeDirector$209,400 - $335,000 / yearPosted 3 days ago
Apply on HubSpot Jobs →

Sign into see who you know at HubSpot Jobs.

POS-7385   Director, Enterprise Risk Management & IT SOX Risk Advisory Role Summary Our mission at HubSpot is to help millions of organizations grow better. HubSpot's Risk and Internal Audit function is growing in scope and complexity. This Director role owns two of the function's most strategic portfolios: Enterprise Risk Management and IT SOX Risk Advisory, including the expansion of SOX coverage and transformation initiatives. In this role, you'll lead Enterprise Risk Management (ERM) facilitation across the business, own the risk advisory relationship with Engineering and Finance stakeholders, and provide director-level oversight of IT SOX readiness as HubSpot scales. You'll manage a team of risk professionals and serve as a key voice in executive reporting on technology risk. What You'll Do Lead execution of the enterprise risk assessment, including surveys, interviews, and cross-functional facilitation. Maintain the enterprise risk register and Key Risk Indicator (KRI) reporting cadence. Synthesize risk inputs from risk owners into executive-ready reporting and recommendations. Track mitigation plan progress and escalate stalled items to leadership. Monitor emerging risks—including AI, regulatory, cybersecurity, and macroeconomic trends—and integrate them into the Enterprise Risk Assessment cycle. Partner with the Head of Risk and Internal Audit to connect Enterprise Risk Assessment outputs to the annual audit plan. Lead the SOX Risk Advisory portfolio, including pre-implementation reviews, control design guidance, and readiness assessments across key business initiatives. Own director-level relationships with Finance and Engineering stakeholders across SOX-relevant system changes. Lead implementations requiring IT audit scoping, control design, and readiness validation. Apply IT SOX expertise to assess ITGC impacts of system migrations, API changes, and platform builds. Partner with the IT Internal Audit team and external auditors on scoping and reliance where advisory work intersects. Manage and develop a team of business and IT risk professionals. Set quality standards for advisory deliverables and risk documentation. Allocate team capacity across concurrent advisory workstreams. Coach advisors on stakeholder management, technical writing, and control design thinking. What You'll Bring Required Qualifications 10+ years of experience across IT audit, risk, or advisory. Bachelor's degree or equivalent experience in Information Systems, Accounting Information Systems, Management Information Systems, Computer Science, or a related field. Experience facilitating Enterprise Risk Management processes, including leading risk assessments, synthesizing outputs, and presenting findings to leadership. Deep IT SOX experience, including ITGC design, operating effectiveness testing, deficiency assessment, and external auditor coordination. Hands-on experience supporting SOX readiness for new systems, ERP implementations, or product features...