---
title: Sr Director, IT Internal Controls & Risk Compliance
description: McGraw Hill is hiring for the Sr Director, IT Internal Controls & Risk Compliance
  role. See the full description and apply.
type: job
url: https://www.foundrole.com/jobs/sr-director-it-internal-controls-and-risk-compliance-at-mcgraw-hill-01a0d41a-fdca-7afb-9cec-796f39d66b27
date: 2026-09-28T14:26:13Z
og_description: Join McGraw Hill as Sr Director, IT Internal Controls & Risk Compliance. Pays
  $124K–$215K per year. Full-time, remote role.
og_image: https://www.foundrole.com/og/1mtxvn.png
breadcrumbs:
  - label: Home
    url: https://www.foundrole.com/
  - label: Search
    url: https://www.foundrole.com/jobs
---

| | |
|---|---|
| **Company** | McGraw Hill |
| **Location** | Remote |
| **Salary** | $124K/yr - $215K/yr |
| **Type** | Full Time |
| **Posted** | Sep 24, 2026 |

## Remote check

**Fully remote: passed our check.** The role itself is remote, with no recurring office days, travel under 10%, no on-site duties and no end date on the remote setup.

- "This is a remote position open to applicants authorized to work for any employer within the United States."

**Where you can work from:** United States
## Description

Overview  

**Build the Future**  
At McGraw Hill, we are dedicated to delivering digital learning experiences that transform education for learners and educators. Our focus is on creating seamless, impactful products that truly benefit our users while supporting growth and collaboration across teams. We foster a culture that values innovation, teamwork, and a balance between career growth and personal well-being.

**How can you make an impact?**

The Sr. Director, IT Internal Controls & Risk Compliance for the Digital Enterprise Solutions (DES) organization leads the company’s Sarbanes-Oxley (SOX) compliance implementation and establishes a scalable and sustainable IT control and governance framework appropriate for our dynamic environment. This role serves as the primary IT lead for SOX compliance, partnering with DES leadership, Finance, Internal Audit, and External Audit to design, document, test, remediate, and standardize controls across a complex landscape including McGraw Hilll’s digital products, Oracle ERP, data and analytics environment, and multiple in-scope financial and operational applications. The ideal candidate leverages deep IT audit experience, strong technical understanding of complex multi-system environments, and exceptional leadership skills to drive compliance and mature our IT governance program, evolving beyond initial SOX implementation into broader risk management leadership.

**This is a remote position open to applicants authorized to work for any employer within the United States.**

**What You'll Do:**

1. **Audit Execution and Risk Assessment**: Plan and develop audit scope for complex assessments including SOX and SOC2 audits; participate in end-to-end engagements from planning through risk assessment, execution, reporting, issue validation, and follow-up; apply a robust understanding of business and IT risks and how controls address these risks. Provide advisory support to Internal Audit on operational or non‑SOX IT audits as needed.
2. **Internal Controls & Remediation**: Provide guidance to control owners on designing and implementing effective controls, ensure timely remediation of deficiencies, recommend improvements; design and implement controls for new entities and evolving business processes; support SOX readiness initiatives and system implementations to embed business, IT, and automated controls appropriately.
3. **SOX and Compliance Expertise**: Apply strong knowledge of SOX requirements, internal control frameworks (COSO, COBIT, NIST), and risk assessment principles to identify control gaps, assess risks, and recommend practical, business-focused solutions; effectively communicate SOX control concepts, audit findings, and remediation expectations to process owners and management, including senior leadership
4. **IT Controls Implementation & Sustainment**: Lead evaluation and implementation of IT General Controls—including user access provisioning/deprovisioning and periodic reviews, segregation of duties considerations, change management and release controls, and operations controls (interfaces, batch processing, backups, monitoring); assess and document controls across complex application landscapes such as digital products, Oracle ERP, legacy/custom, and SaaS; maintain comprehensive risk & control matrices, narratives, and system architecture documentation; partner with Finance and other stakeholders to identify IT-dependent controls and support audit walkthroughs and testing.
5. **Program Development & Sustainability**: Participate in the building of an enterprise IT risk and compliance program beyond initial SOX implementation; maintain an inventory of in-scope applications, infrastructure, and related risks; align IT risk management with enterprise and DES risk initiatives; support development of IT policies and standards, and the creation of metrics for executive, Committee, and Audit reporting; integrate recognized governance frameworks and establish sustainable compliance monitoring processes.
6. **Collaboration & Coordination**: Coordinate audit activities with external auditors to maximize efficiency, leverage work performed, and minimize disruption to the business; build strong relationships across DES, IT, Finance, Internal Audit, and business partners; collaborate effectively to partner across functions and stakeholders.

**Who You Are:**

- 10+ years of progressive experience in IT audit, IT risk management, or SOX compliance within a complex corporate environment.
- Proven track record in planning and executing internal, SOX (Business & IT), operational, and IT audits
- Experience supporting SOX implementations or major control transformations preferred
- Experience working with PCAOB‑regulated auditors
- Familiarity with audit management tools
- Big 4 or equivalent public‑company experience preferred
- Advanced understanding of internal control frameworks and risk assessment methodology
- Exceptional leadership, communication, problem-solving, critical thinking, and stakeholder management capabilities
- Ability to coach and guide control owners; demonstrated ability to build consensus and work across a matrixed organization.

**Why work for us?**

The work you do at McGraw Hill will be work that matters. We are collectively building experiences that will help shape the future of education. Play your part and experience a sense of fulfilment that will inspire you to even greater heights.

The pay range for this position is between $124,000 - $215,000 annually. However, base pay offered may vary depending on job-related knowledge, skills, experience, and location. An annual bonus plan may be provided as part of the compensation package, in addition to a full range of medical and/or other benefits, depending on the position offered. Click [here](https://mheducation.icims.com/icims2/servlet/icims2?module=AppInert&action=download&id=261211&hashed=1059640477 "https://mheducation.icims.com/icims2/servlet/icims2?module=AppInert&action=download&id=261211&hashed=1059640477") to learn more about our benefit offerings.

McGraw Hill recruiters always use a “@mheducation.com” email address and/or from our Applicant Tracking System, iCIMS. Any variation of this email domain should be considered suspicious. Additionally, McGraw Hill recruiters and authorized representatives will never request sensitive information in email.

51248
## Skills

- Open Web Application Security Project (Owasp)
- IT Audit
- Stakeholder Management
- Control Objectives for Information and Related Technology
- IT Risk Management
- Audit Reporting
- Sustainability
- Data Backup
- Problem Solving
- Planning
- Internal Auditing
- Deployment Strategy
- IT General Controls
- Critical Thinking
- Risk Management
- Sustainment
- Collaboration
- Compliance Monitoring
- Internal Controls
- Segregation of Duties
- Auditing
- Oracle E-Business Suite
- Coordinating
- Identity And Access Management
- Systems Architecture
- Leadership
- Public Company Accounting Oversight Board (Pcaob)
- Software as a Service (SaaS)
- Consensus Algorithms
- Communication
- Change Management
- Batch Processing
- Governance
- Deprovisioning
- Sarbanes-Oxley (Sox) Compliance
- COSO Framework
- Program Development

## How to Apply

[Apply for this position](https://www.foundrole.com/jobs/sr-director-it-internal-controls-and-risk-compliance-at-mcgraw-hill-01a0d41a-fdca-7afb-9cec-796f39d66b27?utm_source=ai_markdown)

## Related

- [Browse all companies](https://www.foundrole.com/companies?utm_source=ai_markdown)