Director, Enterprise Risk Management & IT SOX Risk Advisory

HubSpot · Remote - USA · Engineering

Posted 2026-08-06

Apply for this role →

POS-7385

Director, Enterprise Risk Management & IT SOX Risk Advisory

Role Summary

Our mission at HubSpot is to help millions of organizations grow better.

HubSpot's Risk and Internal Audit function is growing in scope and complexity. This Director role owns two of the function's most strategic portfolios: Enterprise Risk Management and IT SOX Risk Advisory, including the expansion of SOX coverage and transformation initiatives.

In this role, you'll lead Enterprise Risk Management (ERM) facilitation across the business, own the risk advisory relationship with Engineering and Finance stakeholders, and provide director-level oversight of IT SOX readiness as HubSpot scales. You'll manage a team of risk professionals and serve as a key voice in executive reporting on technology risk.

What You'll Do

Lead execution of the enterprise risk assessment, including surveys, interviews, and cross-functional facilitation.

Maintain the enterprise risk register and Key Risk Indicator (KRI) reporting cadence.

Synthesize risk inputs from risk owners into executive-ready reporting and recommendations.

Track mitigation plan progress and escalate stalled items to leadership.

Monitor emerging risks—including AI, regulatory, cybersecurity, and macroeconomic trends—and integrate them into the Enterprise Risk Assessment cycle.

Partner with the Head of Risk and Internal Audit to connect Enterprise Risk Assessment outputs to the annual audit plan.

Lead the SOX Risk Advisory portfolio, including pre-implementation reviews, control design guidance, and readiness assessments across key business initiatives.

Own director-level relationships with Finance and Engineering stakeholders across SOX-relevant system changes.

Lead implementations requiring IT audit scoping, control design, and readiness validation.

Apply IT SOX expertise to assess ITGC impacts of system migrations, API changes, and platform builds.

Partner with the IT Internal Audit team and external auditors on scoping and reliance where advisory work intersects.

Manage and develop a team of business and IT risk professionals.

Set quality standards for advisory deliverables and risk documentation.

Allocate team capacity across concurrent advisory workstreams.

Coach advisors on stakeholder management, technical writing, and control design thinking.

What You'll Bring

Required Qualifications

10+ years of experience across IT audit, risk, or advisory.

Bachelor's degree or equivalent experience in Information Systems, Accounting Information Systems, Management Information Systems, Computer Science, or a related field.

Experience facilitating Enterprise Risk Management processes, including leading risk assessments, synthesizing outputs, and presenting findings to leadership.

Deep IT SOX experience, including ITGC design, operating effectiveness testing, deficiency assessment, and external auditor coordination.

Hands-on experience supporting SOX readiness for new systems, ERP implementations, or product features in a technology or SaaS environment.

Track record of managing or mentoring teams in a high-volume, multi-stakeholder environment.

Ability to translate technical IT and SOX observations into business risk language for non-technical executive audiences.

Strong control design expertise with the ability to advise Engineering and Finance stakeholders before implementation, not just after.

Comfortable managing ambiguity across concurrent, fast-moving workstreams.

Collaborative approach that builds credibility with Engineering, Finance, Legal, and Product stakeholders while maintaining appropriate independence.

Executive presence with the ability to deliver leadership updates on risk and advisory themes.

Nice-to-Have Qualifications

Certified Information Systems Auditor (CISA).

Certified Internal Auditor (CIA).

Additional professional certifications related to risk management, governance, or internal audit.

Where You'll Work

Location: Anywhere within the United States

Work location preference: Remote (United States)

Posting: Internal and External

Travel: Minimal travel as needed.

Pay & Benefits

The cash compensation below includes base salary, on-target commission for employees in eligible roles, and annual bonus targets under HubSpot’s bonus plan for eligible roles. In addition to cash compensation, some roles are eligible to participate in HubSpot’s equity plan to receive restricted stock units (RSUs). Some roles may also be eligible for overtime pay. Individual compensation packages are tailored to your skills, experience, qualifications, and other job-related reasons.

This resource will help guide how we recommend thinking about the range you see. Learn more about HubSpot’s compensation philosophy.

Benefits are also an important piece of your total compensation package. Explore the benefits and perks HubSpot offers to help employees grow better.

At HubSpot, fair compensation practices aren’t just about checking off the box for legal compliance. It’s about living out our value of transparency with our employees, candidates, and community.

Annual Cash Compensation Range:

$209,400—$335,000 USD

Apply for this role →

← Back to all jobs