Together We Innovate. Together We Change.
Are you an experienced technology risk and compliance leader ready to make a significant impact on how technology controls protect the integrity of a major enterprise? Join us as Senior Manager, Technology and Security Compliance and take the lead in strengthening our Sarbanes-Oxley and IT General Controls framework while modernizing how technology risk and compliance are managed across the organization! You’ll shape a controls program that is critical to financial reporting and enterprise risk management, influence key decisions with senior leaders, and drive meaningful improvements across Technology and Cybersecurity. You’ll also build and lead a high-performing team that helps set the standard for technology compliance across the enterprise. This position is in Richmond, VA with a hybrid work schedule. We will consider a remote working option for the ideal applicant.
In this role, you’ll provide both strategic direction and day-to-day leadership across IT systems and security controls, audit readiness, issue remediation, and continuous improvement. You’ll engage closely with Technology, Information Security, Financial Operations, Internal Audit, External Audit, and business stakeholders to strengthen compliance and effectively manage technology risk. We’re looking for a leader with deep SOX and ITGC expertise, a strong understanding of technology risk and security controls, and the executive presence to provide focused program leadership and influence senior stakeholders.
What you will be doing:
- Leading the SOX/ITGC controls team in planning, coordinating, and delivering technology control activities across the annual SOX lifecycle, while establishing clear roles, expectations, development plans, and accountability for quality execution.
- Overseeing ITGC control design, control ownership alignment, evidence requirements, testing readiness, deficiency evaluation, issue remediation, management responses, and validation of corrective actions.
- Establishing consistent standards, procedures, and quality expectations for control documentation, evidence collection, testing support, audit coordination, and remediation governance.
- Driving continuous improvement of the SOX/ITGC control environment through simplification, automation, control rationalization, stronger accountability, improved reporting, and risk-based prioritization.
- Coordinating SOX and ITGC activities across Technology, Cybersecurity, Finance, Internal Audit, External Audit, application owners, control owners, and business partners to maintain audit readiness and alignment.
- Guiding control owners in strengthening control design, clarifying operating expectations, improving evidence quality, identifying root causes, resolving recurring control gaps, and integrating controls with broader technology risk practices.
- Translating control risks, audit findings, remediation needs, testing status, control health, and readiness concerns into clear executive communications and decision points while presenting key risk themes to senior leaders and governance forums.
We want you to have:
- Bachelor’s degree in Accounting, Information Systems, Cybersecurity, Computer Science, Finance, or a related field; Master’s degree preferred.
- 10+ years of progressive experience in SOX compliance, ITGCs, IT audit, technology risk, internal audit, compliance, or related disciplines, including demonstrated experience leading SOX/ITGC activities.
- 5+ years of leadership experience managing controls teams, audit programs, compliance programs, or multi-functional technology risk initiatives.
- Deep knowledge of SOX 404, ITGCs, automated controls, application controls, control dependency mapping, COSO, audit methodology, deficiency assessment, remediation governance, and management response development.
- Solid understanding of technology operations and security controls that underpin financial reporting, including IAM, PAM, user access reviews, leading system modifications, infrastructure operations, cloud environments, logging, monitoring, backups, and job scheduling.
- Demonstrated ability to establish effective control documentation and evidence standards, coordinate audit and testing activities, manage issue tracking and remediation, improve control execution, and deliver executive-level reporting.
- Validated ability to influence senior team members, lead through ambiguity, guide high-performing teams, and communicate technology control risks and sophisticated compliance matters in a clear, executive-ready manner.
- CISA, CISSP, CISM, CPA, CIA, or equivalent professional certification required; additional credentials such as CRMA, CGEIT, ISO 27001 Lead Auditor, or other relevant security, audit, risk, or governance certifications preferred.
As a People Leader at Altria, you are accountable for both results and the experience of your team. You drive alignment by connecting strategy to daily work, and you model collaboration by embracing diverse perspectives. By creating trust, offering feedback, and leading with authenticity, you help strengthen Altria’s culture and deliver meaningful outcomes.
The starting salary is based on but not limited to experience, knowledge, and qualifications in determining compensation decisions. The Salary Range for this position is: $132,500.00 - $202,100.00.
Why You’ll Love Building Your Career at Altria
At Altria, we believe a great career starts with feeling supported — both at work and in life. Here’s what you’ll find here:
- Work where connection and flexibility meet — enjoy the benefits of in-person collaboration three days a week (Tuesday - Thursday), while maintaining the flexibility to work remotely on Mondays and Fridays. Our hybrid approach empowers you to stay connected, collaborate with colleagues, and manage your schedule in a way that works best for you.
- Own your time — start with 15 days of paid time off, 13 paid holidays, 2 floating holiday days, and a 37.5-hour workweek so you can recharge and live fully.
- A place where you belong — where your ideas are welcomed, your growth is encouraged, and your impact is real.
- Get recognized for your work — annual merit increases and performance bonus.
- A future you can count on — 401(k) matching from day one; plus Deferred Profit Sharing, an annual company contribution in an amount equal to 13%–17% of your base salary.
- Help with your goals — get help with student loan repayment assistance, attend a conference, or gain a new certification with professional development stipends.
- Support for what matters most — comprehensive medical, dental, and vision coverage for you and your family.
- Celebrating your milestones — paid parental and bonding leave for life’s biggest moments.
- Wellness that goes beyond work — programs that care for your whole well-being at whatever stage you are in your life.
- A culture that gives back — paid volunteer days and a shared commitment to making a difference.
At Altria, we offer more than benefits — we offer a career that fits your life, rewards your ambition, and celebrates your impact.
This position is not eligible for sponsorship.