Loading jobs…
Loading jobs…
The Trade Desk — New York, England
The Trade Desk is a global technology company and the world’s leading independent platform for digital advertising, with nearly 4,000 employees across more than 30 offices. Our technology helps advertisers reach the right audiences across the open internet — from streaming TV and podcasts to mobile apps, news, and more. Advertising powers the content people love.
By making it more transparent, effective, and responsible, we help support trusted journalism, quality entertainment, and creators worldwide. The world’s brands and agencies rely on us to reach their customers and grow their businesses responsibly. The scale of our platform brings unique technical challenges — from processing massive datasets in real time to building systems that operate reliably on a global scale.
When you work here, your impact is worldwide. We welcome diverse perspectives, encourage curiosity, and build teams that learn from one another. If you’re driven to solve meaningful challenges, we’d love to meet you.
WHAT WE DO: We are looking for a Technology Governance & Risk Senior Analyst to lead and execute our governance and risk management initiatives. This role is central to our broader Technology Governance, Risk and Compliance program, encompassing global frameworks which include Sarbanes-Oxley (SOX), Service Organization Controls (SOC) and essential regional regulations such as California Consumer Privacy Act (CCPA) and Protecting Americans’ Data from Foreign Adversaries Act (PADFA) for cybersecurity. The Senior Analystwill assist with the development, improvement and maintenance of technology governance and risk processes, ensuring cross-functional alignment with our internal frameworks.
This involves technology controls design and implementation, drafting company-wide governance policies, managing risk assessment projects, audit management, and collaborating closely with stakeholders across Engineering, Finance, Legal, and Cybersecurity to advance regional governance initiatives. WHAT YOU WILL BE DOING: Drive the execution and maintenance of the governance and risk program to ensure technology and business processes comply with global and regional cybersecurity
Requirements
, including but not limited to SOX, SOC1, SOC2, CCPA, PADFAA, etc. Execute the full GRC process, including leading risk assessments, issues analysis, controls monitoring, control design, control implementation, policy administration, and implementing corrective actions. Partner with stakeholders to continuously track relevant updates, designs, changes, and trends to ensure compliance.
Communicate complex governance and risk issues and prepare reporting to stakeholders. Conduct periodic internal reviews to ensure that GRC procedures are followed and discuss emerging security and privacy compliance issues with the stakeholders. Perform risk and scoping assessments on design documentation and monitor technology areas to identify gaps, points of improvements, as well as to ensure compliance.
Perform control testing and document test procedures, results, and remediation steps for identified issues as related to compliance efforts. Collaborate with engineering, legal and business teams to address control gaps and ensure timely remediation. Collaborate with teams within cybersecurity to ensure compliance with changes to the control environment and regulatory environment.
WHO YOU ARE
: BS or BA in relevant field (Computer Science, Information Systems, Finance, Economics, Accounting) Certifications such as CISSP, CISM, CISA, CIA and/or CIPP preferred 4+ years of experience in technology risk management, governance, compliance, internal audit, information security, or related operational role. Big 4 experience preferred. Industry experience in high-technology companies with complex technology environments.
Experience with SOX, SOC, NIST, and ISO frameworks implementation. Proven ability to design and implement ITGCs and automated controls. Strong organizational skills and ability to wor