Back to jobs
New

Security GRC IT Controls Analyst

Austin, TX or Miami, FL

Who We Are 
Bold. Unapologetic. Hardworking. We are building something special.  We transform energy into high-value compute with superior efficiency at scale.  Today that means powering and securing the Bitcoin Network and powering workloads in AI, HPC and other forms of high-value compute. 

Core Scientific is one of the largest bitcoin miners and hosts in North America. Our mission is to accelerate digital innovation by scaling high-value computing rapidly, efficiently, and responsibly. Our proprietary software stack optimizes bitcoin mining, pushes firmware, and monitors all aspects of our operations, ensuring we and our customers generate the highest possible ROI on our hardware investment. 

But what makes us different from others in our industry?  We own and manage our infrastructure.  That puts us in control of our operations and gives us an advantage that translates into higher productivity and efficiency.  It also provides us with the ability to deploy rapidly the innovations developed by our deep-tech team. 

Come join us as we continue our journey and accelerate yours.  We seek smart, creative, collaborative minds, who work hard and fast. 

Intrigued? Then apply and be a part of something truly special at Core Scientific. 

Title 
Security GRC IT Controls Analyst 

Reports To 
Manager, Governance Risk and Compliance (GRC) 

The Job 

We are seeking a detail-oriented and experienced Security GRC IT Controls Analyst to join our team. The ideal candidate will serve a critical role in ensuring the company’s compliance with Sarbanes-Oxley (SOX) and SOC 2 requirements by evaluating, facilitating testing, and leading improvement opportunities associated with IT General Controls (ITGCs). This position involves close collaboration with Security, IT, Finance, and Compliance teams to strengthen the organization’s internal control environment and risk posture. 

Key Responsibilities 

  • IT and Process Compliance Testing: Facilitate ITGC assessments, including testing of access controls, change management, and IT operations, to ensure compliance with SOX and SOC 2 requirements.
  • Risk Assessment: Identify and assess IT risks and control design or operating effectiveness gaps in processes, systems, and infrastructure. Propose remediation strategies to address identified risks.
  • Control Documentation: Develop and maintain documentation of ITGCs, control matrices, unified control frameworks, risk assessments, and testing methodology.
  • Audit Support: Act as a key liaison between internal compliance department, and IT teams to facilitate SOX and SOC 2 testing and address any findings or inquiries.
  • Process Improvement: Collaborate with stakeholders to design, implement, and optimize controls and processes to strengthen IT governance.
  • Monitoring and Reporting: Track remediation efforts, escalate issues as needed, and report control statuses to management.
  • Policy and Procedure Review: Help develop and maintain IT policies, procedures, and standards that align with SOX, SOC 2 and Enterprise Security Compliance objectives.
  • Training and Guidance: Guide business teams on SOX and SOC 2 compliance requirements as well as corporate security policies and best practices. 

Qualifications 

  • Bachelor’s degree in Information Technology, Accounting, Finance, or a related field.
  • Strong analytical skills and ability to dive deep to get to Root Cause.
  • Excellent communication and interpersonal skills
  • 5-10 years of experience in external audit, internal audit, SOX/SOC 2 compliance, IT audit, IT Security or a related IT governance role.
  • Strong understanding of ITGC frameworks and control areas (e.g., access management, change management, backup, recovery, and operations).
  • Experience with SOX 404 compliance testing.
  • Experience working in a BIG 4 firm leading IT compliance assessment initiatives strongly desired
  • Experience managing supply chain risk management programs
  • Certifications (preferred): CRISC, CISA, CISSP, CPA, or similar certifications. 
  • Perform other duties as assigned. 

Technical Skills: 

  • Proficiency in IT systems and/or data center environments
  • Familiarity with GRC tools such as Drata, Archer, ServiceNow, or AuditBoard.  
  • Strong analytical, problem-solving, and project management skills. 
  • Excellent verbal and written communication abilities to effectively collaborate with technical and non-technical stakeholders.
  • Detail-oriented with a commitment to delivering high-quality work within deadlines. 
  • Experience working with external audit partners  

Location:
This role is a full-time, Monday-Friday position and will operate in a hybrid office environment in Austin, TX or Miami FL.  

Physical Demands: 
While performing the duties of this job, the employee is frequently required to sit; stand; walk; use hands; and lift up to 10 pounds. 

Travel: 
Minimal travel may be required. 

 

Create a Job Alert

Interested in building your career at Core Scientific? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Resume/CV

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Core Scientific’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.