Now hiring

Senior Technology Spec (IT) @ McDermott External Career Site

USOnsiteFull-timeJob reference 26003947
Apply with ResuMinder

Opens on the employer's site

About this role

Our ingenuity fuels daily life. Together, we’ve forged some of the most trusted partnerships across the energy value chain to make what was once just an idea a reality: laying subsea infrastructure thousands of feet below sea level, installing platforms hundreds of miles from shore, using our expertise to design and build offshore wind infrastructure, and reshaping the onshore landscape to deliver the energy products the world needs safely and sustainably.

For more than 100 years, we've been making the impossible possible. Today, we're driving the energy transition with more than 30,000 of the brightest minds across 54 countries.

Job Overview: The Senior Technology Specialist (IT) – IT Controls and Compliance is a hands-on compliance and audit professional responsible for supporting the organization's SOX compliance program, ISO certification, IT audits and maintaining an effective IT control environment. This role works directly with IT, cybersecurity, finance, business process owners, Internal Audit, and external auditors to document controls, perform walkthroughs, validate evidence, execute control testing, support audits, and drive process improvements. The position requires strong communication skills, attention to detail, analytical capabilities, and the ability to build productive working relationships across technical and non-technical teams. The successful candidate will help ensure IT controls are consistently executed, properly documented, supported by appropriate evidence, and maintained in a manner that supports external audit requirements and overall audit readiness.

Key Tasks and Responsibilities: SOX Compliance & IT Controls

• Maintain and continuously improve SOX IT General Controls (ITGCs), IT Application Controls (ITACs), and IT-Dependent Manual Controls (ITDMs) supporting financial reporting. • Develop and maintain audit-ready documentation including narratives, process flows, risk and control matrices (RACMs), control procedures, evidence requirements, and testing support materials. • Coordinate and perform process walkthroughs with control owners to validate control execution and identify control gaps. • Evaluate control design and operating effectiveness across: • Logical Access Management • Privileged Access Management • Change Management • System Development Lifecycle (SDLC) • IT Operations • Backup & Recovery • Disaster Recovery • Segregation of Duties (SoD) • IT-Dependent Manual Controls (ITDMs) • Management Review Controls

• Assess completeness and accuracy of reports, system-generated data, and evidence used to support key controls. • Support annual SOX testing, management assessments, and external audit activities. • Assist control owners in addressing deficiencies and strengthening control execution.

Audit & Risk Assessments

• Plan and execute risk-based IT and cybersecurity audits from planning through reporting. • Conduct interviews and walkthroughs with technology teams, business stakeholders, and process owners. • Perform testing of controls, evaluate supporting evidence, document results, and communicate findings. • Develop practical recommendations that improve controls while minimizing unnecessary operational burden. • Track audit findings and remediation activities through resolution.

Data Analytics & Evidence Review

• Analyze large data sets using Excel and enterprise reporting tools to support audits, control testing, and risk assessments. • Perform user access reviews, role analysis, segregation of duties assessments, exception analysis, sampling, reconciliations, and trend analysis. • Validate system populations and report completeness and accuracy used for SOX testing. • Identify anomalies, outliers, control failures, and compliance concerns through data analysis. • Prepare audit workpapers, testing documentation, management reports, and auditor support packages.

Governance & Process Improvement

• Partner with IT and business stakeholders to improve control processes, documentation quality, and audit readiness. • Recommend opportunities to simplify, standardize, and mature governance and compliance activities. • Support compliance initiatives aligned with SOX, NIST Cybersecurity Framework, and ISO 27001 requirements. • Participate in reviews of third-party assurance reports (SOC reports) and technology risk assessments as assigned.

Stakeholder Engagement & Communication

• Build working relationships with IT, cybersecurity, finance, Internal Audit, external auditors, and control owners. • Facilitate control walkthroughs, testing discussions, audit meetings, and remediation workshops. • Translate technical risks, control issues, and audit findings into clear business language. • Provide practical guidance to stakeholders on compliance requirements and auditor expectations. • Influence positive change through collaboration, credibility, and strong communication rather than formal authority.

Essential Qualifications and Education:

• 8+ years of direct-full-time experience in IT audit, SOX compliance, IT controls, cybersecurity governance, or internal controls. • Bachelor’s degree in Information Systems, IT, Cybersecurity, Computer Science, Accounting Information Systems, Business, or a related field, Experience Pathway: Equivalent direct, full-time, hands-on experience specialized in SOX and IT audits in lieu of a degree. • 8+ years of experience supporting: • SOX compliance • IT audit • IT controls • Internal controls • Technology compliance programs

• Demonstrated experience performing 5 of the following: • ITGC testing • ITAC testing • ITDM testing • Management Review Control assessments • Risk assessments • Audit execution • Control effectiveness reviews • Deficiency remediation support

• Strong understanding of: • SOX 404 • Internal Control over Financial Reporting (ICFR) • IT General Controls • Identity & Access Management • Change Management • ERP and Financial Reporting Systems • Cybersecurity Controls

• Advanced Microsoft Excel skills including pivot tables, reconciliations, data analysis, exception reporting, and audit sampling. • Excellent written, verbal, facilitation, interviewing, and relationship management skills. • Ability to work independently while managing multiple concurrent audits, reviews, and compliance initiatives.

Preferred Qualifications and Education:

• CISA certification is strongly preferred. • Additional certifications such as CISSP, CRISC, CIA, CISM, CGRC, or ITIL are desirable. • Experience supporting SOX readiness, IPO readiness, or public-company compliance programs. • Experience with large-scale ERP environments. • Experience with ServiceNow, AuditBoard, Workday, Azure, SailPoint, or similar enterprise platforms. • Experience working within engineering, construction, energy, EPC, manufacturing, or industrial environments. • Experience supporting global technology organizations across multiple geographic regions and third-party service providers. #LI-CA1 #LI-DNI #Dice

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores