The posting, in CoreWeave's own words
archived Oct 5, 2026CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI labs, startups, and global enterprises, CoreWeave combines superior infrastructure performance with deep technical expertise to accelerate breakthroughs and turn compute into capability. Founded in 2017, CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at www.coreweave.com .
About the Role
This is not a traditional audit-support role. As the Product Manager, IT SOX Compliance, you’ll translate SOX compliance requirements into structured programs, drive accountability across IT process owners, and build the systems and workflows that make compliance scalable. You’ll work closely with the SOX team and IT process owners to ensure controls are designed, reviewed, executed, and evidenced effectively.
Read the full posting ↓
What You’ll Do
Own the end-to-end IT SOX compliance program within the CIO organization, including the IT control inventory covering ITGCs, IT-dependent controls, and automated application controls. Translate SOX compliance requirements into structured programs, processes, and scalable workflows that drive accountability and improve execution. Own control design and documentation, including control narratives, risk and control matrices (RCMs), and supporting procedures, ensuring controls are clearly defined and audit-ready. Partner with IT, Accounting as needed, and the SOX team to ensure new systems and modules are implemented with appropriate SDLC controls before go-live. Review control designs early to identify and mitigate SOX risks before implementation. Partner with IT process owners and control operators to ensure controls are executed consistently and on time. Build and improve the systems, workflows, and reporting used to manage control execution, evidence collection, issue tracking, and compliance visibility. Review control evidence for quality, completeness, and alignment with control requirements before submission to auditors. Manage the full deficiency lifecycle—from root cause analysis through remediation planning, retesting, and escalation—and report control health to IT leadership and the SOX team. Lead root cause analyses for control failures and incidents, track and resolve systemic gaps, and implement and validate remediation plans that drive durable improvements and prevent recurrence.
Who You Are
6+ years of experience in IT audit, IT risk, IT compliance, or a related field, with hands-on IT SOX experience in either a practitioner or oversight capacity. Deep familiarity with IT General Controls (ITGCs), including access management, change management, SDLC, and computer operations, and how they map to financial reporting risk. Experience supporting enterprise business systems such as Workday, Salesforce, NetSuite or SAP, Coupa, and similar platforms. Strong understanding of PCAOB auditing standards, the COSO framework, and COBIT as they apply to IT controls. Demonstrated ability to manage multiple workstreams, deadlines, and stakeholders across engineering, finance, legal, and audit. Experience with GRC platforms such as AuditBoard, ServiceNow GRC, Workiva, or similar tools. Excellent written communication skills, with the ability to produce clear, auditor-ready documentation and translate technical concepts for non-technical stakeholders. Comfortable working in fast-moving, ambiguous environments with a builder’s mindset.