Analyst, IT Compliance & Controls

Division: 
IT
Job location: Remote (Canada)
Hours: 
40 hours per week, Monday to Friday 
Employment type: Full Time
Salary:   
85-95K

A little about us
Aurora is proud to be a global leader in the cannabis industry. With a smart strategy, unmatched talent and focus on our long-term success, we believe we have a bright future.


At Aurora, we’re passionate about helping patients improve their lives through high-quality premium medical cannabis under brands they can trust and rely on. Our products, available across Canada, Europe, Australia, and New Zealand, include leading brands like Pedanios, IndiMed, San Raf, Whistler, Greybeard and CraftPlant. 

Our diverse team works passionately across various roles, from manufacturing to corporate positions, and many more, united by our purpose: Opening the World to Cannabis. Enabled by science and empowered by people, for patients and consumers. We collaborate globally, embrace change with courage, stay agile, and treat everyone with compassion. We live our values daily, making a meaningful impact on patients, communities, and our A-Team.

 

Job Summary:
The Analyst, IT Compliance & Controls supports the organization’s IT compliance, risk, and control environment across Canada, Europe, and Australia. This role helps coordinate the design, implementation, documentation, monitoring, and continuous improvement of IT General Controls (ITGCs) and related technology controls.

Working collaboratively across IT and business functions, the Analyst partners with IT leadership, application and control owners, Information Security, Internal Audit, and external auditors to support SOX compliance, regulatory requirements, cybersecurity controls, and operational risk management.

The role also supports control governance across enterprise applications, infrastructure, cloud environments, and ERP systems, including control testing, audit coordination, remediation activities, and ongoing improvements to the organization’s IT control framework.

Sound Interesting? Here is a little more…

 

As the Analyst, IT Compliance & Controls you will…

  • Partner with IT leadership and Business Application Owners to design, implement, document, and operationalize IT General Controls (ITGCs).
  • Serve as a key coordinator for IT control owner activities across multiple technology domains.
  • Ensure assigned controls are executed consistently, monitored regularly, and supported by appropriate evidence.
  • Develop compensating controls where control deficiencies or vendor assurance gaps exist.
  • Maintain IT control documentation, process narratives, risk and control matrices, and operating procedures.
  • Support continuous improvement of the enterprise IT control framework.
  • Coordinate execution of SOX IT General Controls across enterprise applications, infrastructure, cloud platforms, and security operations.
  • Manage control evidence collection and documentation within ServiceNow GRC.
  • Monitor control performance and identify opportunities to improve effectiveness and efficiency.
  • Partner with Internal Audit and external auditors during planning, walkthroughs, testing, evidence requests, and remediation activities.
  • Track audit observations and coordinate remediation activities through successful closure.
  • Collaborate with Business Application Owners to ensure ERP and critical business applications maintain effective security, change management, and operational controls.
  • Review new applications, enhancements, system implementations, and process changes to ensure compliance requirements are incorporated into solution design.
  • Support ERP governance activities, with particular emphasis on financial reporting controls, segregation of duties, user access management, and change management.
  • Experience supporting or administering Sage X3 or similar ERP platforms is highly desirable.

 

You will be setup for success if you have…

  • Bachelor’s degree in Computer Science, Information Systems, Business, Accounting, or a related discipline.
  • 7–10 years of progressive experience in IT compliance, IT risk, SOX compliance, IT audit, internal controls, or IT governance, preferably within a publicly traded or highly regulated organization.
  • Demonstrated experience serving as an IT Control Owner, Control Coordinator, ITGC Program Lead, or in a comparable role with accountability for enterprise IT controls.
  • Experience supporting SOX ITGC programs across enterprise applications, infrastructure, cloud platforms, and security operations.
  • Experience supporting enterprise ERP environments, preferably Sage X3; experience with SAP, Oracle, Microsoft Dynamics, or comparable platforms is also relevant.
  • Experience using ServiceNow GRC or a comparable Governance, Risk and Compliance platform to manage controls, evidence, testing, issues, and remediation activities.
  • Experience working with internal and external auditors throughout audit planning, walkthroughs, testing, evidence collection, and remediation cycles.
  • Experience supporting system implementations, application enhancements, or significant technology changes from a risk and controls perspective.
  • Experience working within multi-jurisdictional or global technology environments is preferred.
  • CISA, CRISC, CIA, CISSP, or a comparable professional certification is preferred.
  •  Big Four, public accounting, consulting, or equivalent IT audit experience is considered an asset.

 

Bonus Points if you have….

  • Knowledge of applicable regulatory, privacy, cybersecurity, and control frameworks, including SOX/C-SOX, NIST Cybersecurity Framework, CIS Controls, ISO 27001, PCI-DSS, GDPR/PIPEDA, and other relevant regulatory requirements.
  • Strong knowledge of IT General Controls (ITGCs), IT risk management, internal control principles, and technology governance practices
  • Strong analytical and risk assessment skills, with the ability to evaluate control design and effectiveness, identify gaps, and recommend appropriate remediation or compensating controls.
  • Ability to interpret compliance and control requirements and translate them into practical, sustainable IT processes and controls.
  • Strong audit coordination skills, including the ability to support walkthroughs, testing, evidence requests, issue management, and remediation activities.
  • Strong technical writing and documentation skills, including the development and maintenance of process narratives, risk and control matrices, procedures, and control evidence.
  • Strong problem-solving and professional judgment when assessing technology risks, control deficiencies, and remediation options.
  • Ability to communicate complex risk and compliance requirements clearly to both technical and non-technical stakeholders.
  • Strong collaboration and stakeholder management skills, with the ability to work effectively across IT, Information Security, Finance, Internal Audit, and business functions.
  • Strong organizational and prioritization skills, with the ability to manage multiple compliance activities, audit requests, and remediation initiatives across competing deadlines.
  • High attention to detail and accuracy in control execution, documentation, evidence management, and compliance reporting.

Why you’ll love working at Aurora

  • Flexibility: you will enjoy a flexible work environment that is the perfect blend of work and fun! You will be empowered to achieve work-life balance with flexible hours, remote work options, meeting-free-Friday-afternoons and more!  
  • Total Rewards: we will motivate you to go above and beyond with a competitive salary, professional development opportunities, company SWAG, team activities and modern technology. 
  • Team: we are a diverse and global team of cannabis enthusiasts, energetic innovators, fitness gurus, caring parents, foodies and more, with a collective passion to nurture an inclusive environment that helps you grow and provide people better days with cannabis. 

Next steps
Apply today by submitting your resume through our website. Apply today by submitting your resume through our website. You can expect your application to be reviewed by our Talent Acquisition Team and not an AI software/system.  We we will contact you if we see a fit via email.

Think you’re the ideal candidate but you don’t meet all the requirements? Apply anyways. We would love to review your application to see if you’re the right fit or find you an alternative opportunity.  Not the role for you? Share this posting with your network while subscribing to our Talent Community to learn more about upcoming opportunities (hot tip: if you are an Aurora employee, take advantage of the employee referral program by sharing this posting with someone in your network! If they are the successful candidate, you may be eligible for a bonus!).  

Diversity, Equity, Inclusion, Belonging and Accessibility

At Aurora, we are proud to foster and celebrate a diverse community of professionals! We take pride in nurturing an inclusive culture that empowers our people to be their authentic selves, celebrate their differences and love where they work.

Our diverse community combined with our inclusive culture, is what sets us apart in the industry and equips our A-Team with superpowers – and this is why, we encourage all candidates to apply for job opportunities regardless of race, national origin, colour, religion, age, gender identity or expression, sexual orientation, marital and family status, disability, or any other identifying characteristic.

We value the unique skills and experience each person brings to Aurora and are committed to creating and maintaining an accessible environment. We are committed to the requirements of the Accessibility for Ontarians with Disabilities Act so if you require accommodation during the hiring process, please let our Human Resources team know by contacting us at hr.services@auroramj.com


Job Segment: Compliance, ERP, Internal Audit, Testing, Risk Management, Legal, Finance, Technology