Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Manager, IT Risk & Compliance image - Rise Careers
Job details

Manager, IT Risk & Compliance

Why Join Intellia? 

Our mission is to develop curative genome editing treatments that can positively transform the lives of people living with severe and life-threatening diseases. 

Beyond our science, we live our four core values: One, Explore, Disrupt, Deliver and feel strongly that you can achieve more at Intellia. We have a single-minded determination to excel and succeed together. We believe in the power of curiosity and pushing boundaries. We welcome challenging thoughts and imagination to develop innovative solutions. And we know that patients are counting on us to make the promise a reality, so we must maintain high standards and get it done. 

We want all of our people to go beyond what is possible. We aren’t constrained by typical end rails, and we aren’t out to just “treat” people. We’re all in this for something more. We’re driven to cure and motivated for change. Just imagine the possibilities of what we can do together.   

How You Will Achieve More:

The Manager, IT Risk & Compliance, is a key leadership role within the IT organization, responsible for safeguarding information assets and ensuring sustained compliance as the company matures into a public, commercial entity. Reporting to the Sr. Director of GRC, you will act as a strategic bridge between technical IT operations and corporate governance. You will lead the IT Risk Management program with a primary focus on Third-Party Risk Management (TPRM), SOX ITGC compliance, and ISO framework alignment.

This role owns the full lifecycle of supplier risk assessments—with a critical emphasis on high-stakes biotech partners such as CROs and CDMOs—and serves as the primary IT liaison for external auditors. You will partner closely with Finance, Legal, Quality (GxP), Clinical and Commercial stakeholders to embed a unified, risk-aware culture across the organization.

Responsibilities:

Third-Party Risk Management (TPRM):

  • Oversee the security risk lifecycle for all IT suppliers and applications (SaaS, On-Prem, Clinical and Commercial systems). Evaluate security attestations (SOC2, ISO 27001), credentials, and evidence to report on the overall risk posture of the supply chain.

Sustained Compliance (SOX/ISO):

  • Lead the continuous monitoring of IT General Controls (ITGCs) to ensure SOX 404 readiness and ongoing compliance. Partner with Finance, Legal and IT to map controls across ISO and regulatory frameworks, minimizing redundant testing.

Audit Management & Execution:

  • Serve as the primary lead and point of contact for external and internal IT audit cycles (e.g., Year-end SOX testing). Manage the collection of evidence, coordinate walkthroughs, and ensure timely remediation of any identified deficiencies.

Data Privacy Liaison:

  • Partner with Legal and Clinical teams to ensure IT systems and third-party vendors comply with global data privacy regulations (GDPR, CCPA/CPRA, HIPAA). Conduct Privacy Impact Assessments (PIAs) for new systems handling sensitive patient or employee data.

Risk Assessment & Remediation:

  • Perform IT Risk Assessments to identify and remediate threats within internal systems and 3rd-party ecosystems. Maintain the IT Risk Register and track mitigation strategies to completion.

Policy & Governance:

  • Develop and maintain Information Security policies, standards, and Standard Operating Procedures (SOPs) to ensure consistency in IT service delivery, commercial readiness and audit-readiness.

Cross-Functional Collaboration:

  • Act as the primary IT GRC liaison to the Quality Management team. Coordinate integrated risk reporting to ensure IT security vetting (ISO/SOC2) complements clinical/GxP quality auditing.

About You:

  • Risk-to-Business Translation: Exceptional ability to synthesize complex IT, Privacy, and TPRM risks into clear, metrics-based insights that drive informed executive decision-making.
  • Cross-Functional Change Management: A "hands-on" leader capable of building consensus across Clinical, Quality, Legal, Finance and Commercial to drive the cultural shift from R&D to a disciplined, public-company environment.
  • Scalable Control Design: Skill in designing "right-sized" ITGC and Privacy controls that meet SOX/ISO/GDPR standards without hindering the speed of a scaling biotech firm.
  • Audit Defensibility & Rigor: High level of discipline in documentation and evidence collection, ensuring all GRC workflows and vendor assessments are robust enough to withstand external audit.
  • Conflict Resolution & Negotiation: Proven success in resolving cross-functional friction and negotiating security remediation plans with critical third-party partners.
  • Educational Foundation: Bachelor’s degree in information systems, Computer Science, or a related field. Master’s degree is preferred.
  • Core Certifications: CISA, CRISC, CTPRP, or CISM strongly preferred.
  • Note: Candidates without a core certification must be willing to obtain one within 9–12 months of hire.
  • Industry Knowledge (Preferred): Understanding of Life Sciences regulations (GxP, 21 CFR Part 11) or Privacy frameworks (GDPR/CCPA) is highly desirable.
  • Professional Foundation: 4–6 years in IT Risk, Audit, or Compliance; minimum 3 years specifically focused on Information Security domains.
  • Public Company & Scaling Expertise: Direct experience implementing or maturing SOX (ITGC) and ISO 27001 frameworks in a regulated environment (Biotech/Life Sciences preferred).
  • Stakeholder & Audit Management: Proven track record of serving as a primary liaison for internal/external auditors and collaborating with cross-functional partners (Legal, Quality, Finance).
  • Technical Stack: Proficiency with GRC systems (e.g., OneTrust, ServiceNow) and security rating tools (e.g., BitSight, Blackkite).
  • Continuous Monitoring: Experience integrating tools like CrowdStrike into a holistic vendor risk lifecycle.
  • Stationary Work: Ability to remain in a stationary position for extended periods while operating a computer and standard office equipment.
  • High-Volume Communication: Must be able to frequently exchange complex, accurate information with internal stakeholders and external auditors.
  • Analytical Focus: Requires sustained mental concentration to analyze risk data and interpret evolving regulatory requirements.
  • Travel: Minimal travel required (less than 10%), primarily for occasional on-site vendor audits or team offsites.

#LI-Remote

EEOC Statement: Intellia believes in a diverse environment, and is committed to equal employment opportunity for all its employees and qualified applicants. We do not discriminate in recruitment, hiring, training, promotion or any other employment practices for reasons of race, color, religion, gender, national origin, age, sexual orientation, marital or veteran status, disability, or any other legally protected status. Intellia will make reasonable accommodations for qualified individuals with known disabilities, in accordance with applicable law.

Applications are accepted on a rolling basis, and will continue to be accepted until the position is filled at which point the position will be taken down.

The base salary for this position is expected to range between $146,700.00 - $179,300.00 USD per year.

The salary offered is determined based on a range of factors including, but not limited to, relevant education and training, overall related experience, specialized, rare or in-demand skill sets, internal comparators and other business needs. Upon joining Intellia, your salary will be reviewed periodically and additional factors such as time in role and performance will be considered. Intellia may change the published salary range based on company and market factors.

Additional compensation includes a performance-based annual cash bonus, a new hire equity grant, and eligibility to be considered for annual equity awards the value of which are determined annually at the Company’s discretion.

For more information about Intellia’s benefits, please click here.

Awesome Motive Glassdoor Company Review
4.2 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Awesome Motive DE&I Review
4.4 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of Awesome Motive
Awesome Motive CEO photo
Kartik Mandaville
Approve of CEO

Average salary estimate

$163000 / YEARLY (est.)
min
max
$146700K
$179300K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Awesome Motive logo

What it's like to work at Awesome Motive

Read Reviews
Similar Jobs
Photo of the Rise User
Posted 11 hours ago

Lead PCH’s on-camera brand presence by producing daily short-form content that drives engagement, retention, and viral prize moments.

Photo of the Rise User
Awesome Motive Hybrid No location specified
Posted 10 hours ago

Hercules is hiring a senior/staff SEO Content Writer to lead keyword strategy, produce high-impact long-form content, and optimize it to drive traffic and paid conversions using AI-driven workflows.

Photo of the Rise User

Contribute to healthcare application delivery as an Associate Technical Analyst by converting business needs into clear technical requirements, supporting testing, defect management, and system improvements.

Photo of the Rise User
Posted 9 hours ago

DYOPATH is hiring a SNOC Engineer II (Security) to lead incident detection and response while improving operational reliability across security, network, systems, and cloud in a remote capacity.

Photo of the Rise User

Lead the design, automation, and operational ownership of Harvey’s Microsoft ecosystem (Intune, M365, Entra ID) to deliver secure, scalable device and tenant management across production, development, and demo environments.

Photo of the Rise User
Posted 12 hours ago

Lead Elanco's SAP S/4HANA Settlement Management efforts by designing, implementing, and supporting Condition Contract and Settlement Management solutions that enable Pricing, Rebates, and Master Data capabilities across the business.

Photo of the Rise User
Posted 4 hours ago

Crusoe is seeking a Senior Systems Engineer - IAM to lead Okta-based identity lifecycle, automation, and secure access integrations for its global technology infrastructure in San Francisco.

Posted 10 hours ago

Onsite IT Support role in Cambridge, MA providing first- and second-level support, workstation setup, and ticket resolution for an international IT services firm.

Western Alliance Bank seeks a Principal Engineer II to architect and lead Infrastructure-as-Code and automation strategies for secure, compliant, enterprise-scale Azure environments.

Photo of the Rise User
Posted 10 hours ago

Adoreal is hiring a hands-on Senior Manager of IT & Engineering to build the IT/security function, lead HIPAA compliance, and provide .NET technical leadership in a hybrid US-remote role with preference for candidates near Chicago, IL.

Posted 9 hours ago

Support Kestra’s leadership teams as an AI Enablement Intern by creating tailored training, workshops, and a prompt library to accelerate adoption of M365 Copilot and other generative AI tools.

Senior individual contributor role to design, operate, and lead complex enterprise and cloud networking architectures for a global financial services firm.

Photo of the Rise User
Posted 3 hours ago

Provide Tier 1 technical support across corporate, distribution, and retail channels for Abercrombie & Fitch, resolving incidents, fulfilling requests, and helping associates use supported systems and devices.

Photo of the Rise User
Saalex Hybrid No location specified
Posted 10 hours ago

Saalex seeks experienced Field Service Engineer II candidates to lead installation, sustainment, and troubleshooting of deployed IT and network systems in operational field environments.

Photo of the Rise User
Posted 17 hours ago

Crypto.com's Security Team seeks a Security IT Support Engineer to own endpoint lifecycle, patching, access management, and vulnerability remediation while helping teams adopt AI safely.

SpringRole is the first professional reputation network powered by artificial intelligence and blockchain to eliminate fraud from user profiles. Because SpringRole is built on blockchain and uses smart contracts, it's able to verify work experienc...

739 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 18, 2026
Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!