Job Information
American Tower Senior Manager, IT Risk Controls & Sox Governance in Boston, Massachusetts
The Team
We are seeking a Senior Manager, IT Risk Controls & Sox Governance to join American Tower’s Information Systems Department. The Information Systems team is responsible for global strategic planning for all IT systems. This role is a key member of the IT Governance organization and serves as a second line function responsible for the design, oversight, and governance of information security controls, IT risk management practices, and IT general controls (ITGCs) that support American Tower’s SOX, ICFR, and broader regulatory obligations.
This role provides leadership over a team responsible for IT risk and control governance and partners closely with IT Operations, Finance, Internal Audit, and business stakeholders to ensure controls are appropriately designed, consistently executed by control owners, and auditable across American Tower’s global technology environment. This position is responsible for governance, risk assessment, remediation oversight, policy and standards development, and audit coordination, all in accordance with enterprise risk management guidelines and regulatory requirements.
What You Need to Succeed
Bachelor's degree in Information Systems, Computer Science, Accounting, Risk Management, or a related field.
Master’s degree in Business Administration, Information Technology, Supply or a related field of study, or equivalent experience preferred.
Demonstrated experience supporting SOX and ICFR in a publicly traded company.
Prior people management or team leadership experience.
Strong understanding of IT general controls, risk frameworks, and audit requirements.
Experience in a global or highly regulated environment.
Familiarity with GRC platforms and automated control monitoring.
Professional certifications (e.g., CISA, CISSP, CRISC, CPA) a plus.
Strong analytical, problem-solving, and communication skills with a proven ability to drive change and influence stakeholders.
While performing the role, you will need to lift up to 25lbs.
Approximately 25% of travel may be required in support of the position’s responsibilities.
Strong organization, planning, and project management skills; ability to prioritize tasks for self and team to meet requirements and deadlines.
Ability to work with different functional groups and levels of employees to effectively and professionally achieve results.
Strong leadership skills: ability to drive and motivate team to achieve results.
What You Can Offer Us
• Lead the design, standardization, and ongoing oversight of IT risk management and IT general control frameworks supporting SOX, ICFR, and financial reporting integrity.
• Conduct and oversee IT risk and control assessments to identify design gaps, emerging risks, and control enhancement opportunities.
• Ensure IT control frameworks are scalable, consistent, and aligned with global governance standards.
• Serve as the primary IT governance liaison for Internal Audit and External Audit related to IT SOX matters.
• Support SOX scoping, control design discussions, audit coordination, and management responses.
• Oversee IT SOX remediation activities, including issue tracking, root cause analysis support, and validation of management action plans in coordination with Internal Audit.
• Own and maintain IT risk, security, and control policies, standards, and governance documentation.
• Provide governance oversight for key control domains, including access management, change management, logical security, and technology operations.
• Ensure policies and standards align with regulatory expectations and enterprise risk management objectives.
• Provide governance oversight of the access management control framework, including policy, standards, and risk assessments.
• Ensure appropriate separation of duties between access provisioning, approval, and review activities.
• Provide advisory oversight for changes to in scope applications and infrastructure to ensure alignment with approved change management controls and SOX requirements.
• Oversee IT risk and control governance for cloud platforms and third party applications in scope for financial reporting.
• Partner with third party risk management, procurement, and legal teams to ensure technology risks are identified and addressed appropriately.
• Partner with IT Operations, Finance, Internal Audit, Cybersecurity, and business leaders to drive consistent understanding of IT risk and control expectations.
• You are responsible for the recruitment, performance management, and career development for your team. You’ll also be expected to cultivate a collaborative team dynamic that enables us to meet our business objectives.
• Other duties as assigned.
American Tower is a global digital infrastructure company serving customers through tower sites and other real estate solutions that support connectivity and opportunity, focused on achieving our vision of Building a More Connected World. Our success is rooted in the potential of our people and the power of local teams at our offices and sites across 25 countries.
We are one of the largest global Real Estate Investment Trusts (REITs) and a publicly traded (NYSE:AMT), Fortune 500 Company headquartered in Boston, Massachusetts. The next decade will be an exciting time as we evolve our infrastructure to meet tomorrow’s needs and position our people to elevate their impact, their potential, and our shared success. Come grow your career with us!
For more information about how American Tower is building a more connected world, visit americantower.com
American Tower is proud to be an equal opportunity employer and will not discriminate against an applicant or employee based on age, sex, sexual orientation, gender identity, race, color, creed, religion, national origin or ancestry, citizenship, marital status, familial status, disability, military or veteran status, genetic information, pregnancy, reproductive decisions, or any other characteristic protected under applicable law.
American Tower is committed to fair and equitable compensation practices. Placement within the salary range is based on a variety of factors, including relevant experience, skills, certifications, job level, and location. For U.S.-based candidates only, please see the base salary range for this position listed below. This position is also eligible for annual bonus, and annual equity award and participation in the Employee Stock Purchase Plan (ESPP). For candidates outside of the U.S., salary and benefits are based upon local market practice.
American Tower also offers a comprehensive benefits package, which includes healthcare coverage, a 401(k) savings plan, paid time off, company holidays, sick leave, parental leave, and access to an Employee Assistance Program focused on mental and financial wellness, please click here (https://www.americantower.com/us/careers/benefits) to learn more.
Requisition ID : 2500