About this role
Come join the Intuit GRC organization! We are looking for an innovative professional to join a world class team.
Intuit's GRC function is transforming from manual, check-the-box compliance to an AI-native operating model — audit evidence pipelines, automated control testing, and agentic workflows that give auditors and executives leverage instead of busywork. We're looking for a motivated, technically fluent Senior Technical Compliance Manager who can sit at the intersection of compliance domain expertise and engineering execution: someone who understands SOC 1/2, access reviews, and control testing well enough to translate those requirements into concrete engineering tasks, and who can partner directly with engineers (or build the automation themselves) to ship it.
This is not a traditional risk-assessment TCM role. The Senior TCM, GRC AI Innovation owns the requirements-to-delivery bridge for our AI-driven audit and compliance tooling — defining what 'correct' looks like for an automated control test, specifying data/evidence requirements, validating pipeline output against audit standards, and working hands-on with engineering to close gaps. You will have the opportunity to reimagine how compliance work gets done at Intuit, working boundarylessly across GRC, engineering, and internal audit.
Responsibilities
Responsibilities:
- Translate compliance and audit requirements (SOC 1/2, ISO 27001, access reviews, PBC evidence cycles, internal controls) into clear, engineering-ready specifications and acceptance criteria
- Partner directly with engineers building GRC automation and AI pipelines — reviewing designs, validating outputs against audit/control standards, and flagging compliance risk before it ships
- Own end-to-end delivery of prioritized GRC AI initiatives: evidence pipelines, automated control testing, workpaper generation, audit dashboards
- Serve as the compliance subject matter expert in engineering design discussions, ensuring automation reflects the actual control intent, not just a literal reading of the requirement
- Validate AI-generated audit artifacts (workpapers, evidence mappings, control testing results) for accuracy, defensibility, and auditor-readiness
- Identify opportunities to automate manual GRC processes; scope, prioritize, and drive them through to production
- Define metrics for pipeline health, evidence coverage, and audit-readiness; report progress to GRC leadership
- Build and maintain a working knowledge of the internal controls environment, evidence sources, and prior-year workpapers well enough to spot when automated output is wrong
- Promote a culture of AI-forward, evidence-based compliance across the GRC organization
Qualifications
- BA/BS in Engineering, Computer Science, Information Systems, Accounting, or equivalent
- 5+ years of experience in technical compliance, IT audit, SOC 1/2, or GRC roles, with direct exposure to control testing and audit evidence
- Demonstrated ability to translate compliance/audit requirements into engineering specifications — you can read a control objective and tell an engineer exactly what the automation needs to check
- Comfortable working directly with engineers on design and requirements; enough technical fluency to review scripts, data pipelines, or automation logic without needing it re-explained
- Familiarity with AI/LLM-based tooling (Claude, ChatGPT, agentic workflows) and genuine interest in applying it to compliance and audit work
- Working knowledge of SOC 1/2, ISO 27001, PCI DSS, NIST 800-53, or SOX 302/404 control frameworks
- Experience validating or QA'ing automated or AI-generated outputs against a defined standard (audit, engineering, or otherwise)
- Strong program management skills — able to scope initiatives, sequence work, and drive cross-functional delivery without heavy oversight
- Self-motivated, comfortable with ambiguity, able to operate in a 'boil the lake' mode where thorough is the default, not the exception
- Excellent written and verbal communication; able to represent both the compliance and engineering side of a decision to leadership
- Certifications such as CISA, CRISC, or CISSP preferred, not required
- Location: Atlanta, San Diego, New York, Mountain View,
Intuit provides a competitive compensation package with a strong pay for performance rewards approach. This position may be eligible for a cash bonus, equity rewards and benefits, in accordance with our applicable plans and programs (see more about our compensation and benefits at Intuit®: Careers | Benefits ). Pay offered is based on factors such as job-related knowledge, skills, experience, and work location. To drive ongoing fair pay for employees, Intuit conducts regular comparisons across categories of ethnicity and gender.
The expected base pay range for this position is:
Mountain View, CA $151,000- $204,500
San Diego, CA $136,000- $184,000