Senior Manager of IT Regulatory Compliance

A. O. Smith Corporation - Nashville, TN

Hiring: Senior Manager of IT Regulatory Compliance Company: A. O. Smith Corporation Location: Nashville, TN Job Posted Time: 2026-09-17 02:35:57 Employment Type: Hybrid Target Skills & Keywords : Embedded Systems, Encryption, GDPR, IAM, Regulatory Compliance, Root Cause Analysis, SAP, SOC, Segment About the job Experience: •12+ years of progressive experience in technology risk, IT audit, IT compliance, technology controls, and/or privacy risk and regulatory compliance within complex, global organizations (public accounting and/or global manufacturing preferred) Required Skills: •Lead 2nd-Line SOX IT Compliance Oversight - Own governance and oversight of SOX, ensuring compliance with ICFR requirements and consistent execution across ERPs and supporting technologies (e.g., ITGCs, ITACs, SoD), including control design standards, evidence quality, and remediation governance. •Security-by-Design Oversight across SDLC and Implementations - Provide 2nd‑line oversight across SDLC phases and major system implementations ensuring controls are designed and executed to appropriately mitigate risk, procedures are executed in alignment with internal policies, and security and privacy requirements are appropriately embedded. •Drive Issue Management and Remediation – Assess control deficiencies and compliance findings, govern and drive the identification, root cause analysis, risk acceptance/escalation, and remediation action plan development by partnering with control owners and operations teams. Qualifications: •Bachelor’s degree in Business Administration, Management Information Systems, Computer Science, Cybersecurity, Accounting or a related field; MS or MBA is preferred. •CISA or the ability to obtain within a year is required; additional professional certifications are preferred, such as CISM, CISSP, CIA, CPA, and privacy certifications (e.g., IAPP CIPP/E, CIPP/US, CIPM) •8-12+ years of progressive experience in technology risk, IT audit, IT compliance, technology controls, and/or privacy risk and regulatory compliance within complex, global organizations (public accounting and/or global manufacturing preferred) •Deep expertise in COSO and NIST frameworks (and familiarity with privacy/security standards such as ISO 27001/27701 and common privacy control concepts), including performing audit procedures against standards or assessing and implementing controls •Strong knowledge of IT general and automated controls, ICFR concepts, and control design/testing, plus the ability to translate privacy regulatory obligations (e.g., GDPR, DPDP, PIPL, CCPA/CPRA) into practical, testable technology and process controls •Prior experience with SAP (ECC, BW, GRC, ECP, S/4HANA) and understanding configuration and best practices •Demonstrated experience supporting or overseeing SDLC activities and system implementations •Proven ability to operate effectively in a global, matrixed organization •Effective and impactful executive-level communication and presentation skills; able to influence outcomes and drive decisions across IT, Security, Legal/Privacy, Finance, and the business •Strong judgment and risk prioritization capabilities Compensation: •Competitive benefits and rewards package Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!