StubHub

Staff Governance, Risk and Compliance Analyst

StubHub · New York, NY
New York, NY was $200K–$250K Closed
Applications are closed for this role. It was originally posted 2026-08-13. It’s no longer accepting applicants — see roles StubHub is still hiring for →, or browse the live openings below.
Salary
$200K–$250K
Type
Full-time
Experience
7+ yr

StubHub is on a mission to redefine the live event experience on a global scale. Whether someone is looking to attend their first event or their hundredth, we’re here to delight them all the way from the moment they start looking for a ticket until they step through the gate. The same goes for our sellers. From fans selling a single ticket to the promoters of a worldwide stadium tour, we want StubHub to be the safest, most convenient way to offer a ticket to the millions of fans who browse our platform around the world.

As p art of the  GRC  org anization,  t he  GRC Staff Analyst typically acts as the central coordinator between Engineering , Finance ,  and  Internal Audit , ensuring that control owners execute controls while driving audit readiness and continuous improvement across the SOX program.   This is a hands-on individual contributor  role,   and this person  will report to  the  Director of Engineering and GRC ,  defin ing   our  control  imp lementation  strategy and  owning  its execution across  compliance  framework s  we  operate .

Location: Hybrid (3 days in office/2 days remote) – New York, NY

What You'll Do:

  • SOX Program Ownership & Audit Management
  • Serve as the primary SOX point of contact for Technology Operations and FinTech.
  • Own the end-to-end SOX calendar, including planning, testing, control execution, evidence collection, remediation, and reporting.
  • Partner with Internal Audit, External Audit, Finance, GRC, and Technology leadership throughout the SOX lifecycle.
  • Coordinate walkthroughs, control demonstrations, auditor requests, and quarterly and annual testing activities.
  • Own SOX scoping, risk assessments, control design and implementation, and remediation tracking.
  • Maintain the inventory of SOX-relevant systems, applications, infrastructure, and control owners.
  • Track findings and observations through remediation and validate corrective actions with control owners.
  • IT Controls & Governance
  • Oversee the design, execution, and documentation of ITGCs, IT Application Controls, and IT dependencies across:
  • User and privileged access management
  • Joiner/Mover/Leaver processes
  • Change management and production deployments
  • Computer operations, backup, and recovery
  • Program development and SDLC
  • Reports, system interfaces, and segregation of duties
  • Develop and maintain control narratives, process and data flows, SOPs, risk-control matrices, and supporting documentation.
  • Monitor control performance and proactively identify potential deficiencies before audit testing.
  • Evaluate new systems, technologies, and business initiatives for SOX impact and required control changes.
  • Maintain a centralized risk register with clear ownership and prioritization across the technology stack.
  • Risk, Compliance & Continuous Improvement
  • Perform risk assessments for changes affecting financial systems and IT controls.
  • Assess emerging technology and regulatory risks and determine their impact on the control environment.
  • Embed compliance-by-design principles into how teams build and ship products and technology.
  • Drive standardization and automation across controls, evidence collection, and GRC workflows.
  • Establish clear accountability, escalation paths, and governance structures.
  • Maintain policies that satisfy applicable compliance and security requirements.
  • Reduce audit effort through improved processes, documentation, tooling, and automation.
  • Cross-Functional Leadership & Reporting
  • Partner closely with Finance, Internal Audit, External Audit, Information Security, Engineering, FinTech, and Product.
  • Build a strong compliance culture by helping teams understand the “why” behind requirements and driving stakeholder adoption.
  • Develop dashboards and KPIs covering control execution, audit readiness, evidence timeliness, deficiencies, remediation progress, and repeat findings.
  • Prepare and present executive-level updates on testing progress, risks, deficiencies, and remediation status to Technology leadership.

What You've Done:

  • 7+ years of experience managing a SOX program or external audit program, ideally within a pre-IPO or newly public environment.
  • Deep understanding of SOX 404 ITGCs and strong working knowledge of PCAOB standards, COSO, and SOX 302/404 requirements.
  • Experience in a global marketplace, e-commerce, ticketing, or other high-transaction-volume environment with multi-entity international operations.
  • Strong knowledge of identity governance, access controls, change management, control design, and remediation.
  • Experience working with Big 4 external auditors.
  • Excellent project and stakeholder management skills, with the ability to influence across Engineering, Finance, Audit, and business teams.
  • Strong analytical, documentation, and executive communication skills.

Preferred Qualifications:

  • CISA, CIA, CISSP, AAIA, AAIR, or similar certification.
  • Experience supporting a company through IPO readiness or the transition to being publicly traded.
  • Familiarity with COBIT, COSO, and NIST.
  • Familiarity with modern cloud, data, and engineering environments and GRC tooling.

What We Offer:

  • Accelerated Growth Environment: Immerse yourself in an environment designed for swift skill and knowledge enhancement, where you have the autonomy to lead experiments and tests on a massive scale.
  • Top Tier Compensation Package: Enjoy a rewarding compensation package that includes enticing stock incentives, aligning with our commitment to recognizing and valuing your contributions.
  • Flexible Time Off: Embrace a healthy work-life balance with unlimited Flex Time Off, providing you the flexibility to manage your schedule and recharge as needed.
  • Comprehensive Benefits Package: Prioritize your well-being with a comprehensive benefits package, featuring 401k, and premium Health, Vision, and Dental Insurance options.

The anticipated gross base pay range is below for this role. Actual compensation will vary depending on factors such as a candidate’s qualifications, skills, experience, and competencies. Base annual salary is one component of StubHub’s total compensation and competitive benefits package, which includes equity, 401(k), paid time off, paid parental leave, and comprehensive health benefits.

Salary Range
$200,000 — $250,000 USD

About Us

StubHub is the world’s leading marketplace to buy and sell tickets to any live event, anywhere. Through StubHub in North America and viagogo, our international platform, we service customers in 195 countries in 33 languages and 49 available currencies. With more than 300 million tickets available annually on our platform to events around the world -- from sports to music, comedy to dance, festivals to theater -- StubHub offers the safest, most convenient way to buy or sell tickets to the most memorable live experiences. Come join our team for a front-row seat to the action.

For California Residents: California Job Applicant Privacy Notice found  here

We are an equal opportunity employer and value diversity on our team. We do not discriminate on the basis of race, color, religion, sex, national origin, gender, sexual orientation, age, disability, veteran status, or any other legally protected status.

P
Head of Total Rewards
New York, NY
People & HR
$250K–$350K
P
Senior Product Manager - Marketplace Quality
New York, NY Hybrid
Product
$175K–$270K
P
Senior Product Manager - Seller Experience
New York, NY Hybrid
Product
$175K–$270K
See all live roles at StubHub →
B
Governance, Risk and Compliance Analyst
Babel Street Reston, VA
Operations
$80K–$125K
C
Information Security Risk and Compliance Analyst
CarGurus Boston, MA
Operations
$84K–$106K
F
Senior Technology Governance, Risk & Compliance (GRC) Analyst
FanDuel Group New York, NY
Operations
$138K–$173K
O
Corporate Governance, Risk, and Compliance Analyst
Onebrief United States Remote
Operations
$160K–$200K
See all Operations roles →
Applications closed