
IT Compliance - Manager/Director
Eliassen Group
Job description
Description
Hybrid 3-4 days onsite in Waltham, MA
Our client is a clinical-stage biotechnology company seeking an IT Compliance and Controls Consultant to strengthen governance, documentation, and audit readiness across key systems. The role will partner with IT, business stakeholders, control owners, vendors, and auditors to build and improve SOX, GxP, CSV, SDLC, and ITIL-related controls. The consultant will balance operational responsibilities such as access reviews and evidence collection with project-based initiatives in a regulated life sciences environment.
We can facilitate w2 and corp-to-corp consultants. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.
Rate: $120.00 to $130.00/hr. w2
Responsibilities
-
Maintain a CMDB and related master data.
-
Create and maintain policies and control procedures, including key controls for SOX compliance.
-
Complete periodic testing of internal controls, document exceptions, and oversee remediation plans.
-
Identify and complete baseline testing for key reports for SOX compliance.
-
Create job aids, user guides, and instructional presentations for control owners and participants.
-
Obtain and review SOC 1 reports for key systems, present summaries to stakeholders, and escalate and remediate as appropriate.
-
Create and maintain an IT Key Vendor List and obtain and review SOC 1 and SOC 2 reports as appropriate.
-
Initiate and oversee periodic audits of user access to key systems.
-
Implement and oversee processes for granting, modifying, and terminating user access.
-
Ensure appropriate administrative activity logging and review for key systems.
-
Initiate and oversee system change control procedures, including preservation of key SDLC artifacts.
-
Initiate and oversee periodic reviews of system changes as appropriate.
-
Assist in operationalizing and automating compliance processes.
-
Manage quarterly access review processes and coordinate review calendars with stakeholders.
-
Gather system access and production support reports and distribute for review and approval.
-
Track completion of reviews and maintain supporting documentation and audit trails.
-
Support USDM / ProcessX change control activities and manage quarterly process reviews.
Experience Requirements
-
Knowledge of SOX audit requirements and experience working with SOX auditors.
-
Knowledge of GxP / CSV audit requirements with experience supporting GxP / CSV audits.
-
Knowledge of IT SDLC processes and documentation governance.
-
Knowledge of ITIL processes.
-
Experience with SOC 1 and SOC 2 compliance.
-
Experience with change management and change control processes.
-
Audit support and evidence collection expertise.
-
Ability to work independently and proactively in environments with immature controls.
-
Ability to communicate IT audit requirements to both IT and business stakeholders.
-
Ability to influence change without direct managerial authority.
-
Strong organizational skills and attention to detail.
-
Experience simplifying complex compliance processes and driving stakeholder participation.
-
Nice to have: GxP experience in pharmaceutical or life sciences environments.
Education Requirements
-
Bachelor’s degree in Information Technology, Computer Science, Information Systems, Business, Life Sciences, or a related field required.
-
Equivalent combination of education, training, and relevant professional experience may be considered.
-
Relevant certifications such as CISA, CRISC, CGEIT, ITIL, PMP, or related compliance, audit, or validation credentials are preferred.