
Hybrid opportunity at
GustoAI/IT Controls Engineer, Enterprise Applications
Gusto provides products like payroll, health insurance, 401(k) plans, and HR services to help more than 500,000 small businesses operate smoothly. The company is currently hiring…
Career Tools
About This Role
Gusto provides products like payroll, health insurance, 401(k) plans, and HR services to help more than 500,000 small businesses operate smoothly. The company is currently hiring an IT Controls Engineer for its Enterprise Applications group on a full-time, hybrid basis in San Francisco. In this senior individual contributor position, you will oversee, develop, and scale IT General Controls across critical enterprise platforms including NetSuite, Workday, and Salesforce. Serving as the…
Job Description
Gusto provides products like payroll, health insurance, 401(k) plans, and HR services to help more than 500,000 small businesses operate smoothly. The company is currently hiring an IT Controls Engineer for its Enterprise Applications group on a full-time, hybrid basis in San Francisco.
In this senior individual contributor position, you will oversee, develop, and scale IT General Controls across critical enterprise platforms including NetSuite, Workday, and Salesforce. Serving as the primary contact for compliance and audit readiness, you will partner closely with teams across Internal Audit, IT, Security, and Finance to maintain SOX 404 compliance.
This role is ideal for a seasoned controls professional who wants to push beyond traditional manual methods by pioneering automation and artificial intelligence to create continuous, intelligent compliance workflows. You will evaluate internal AI use cases, manage segregation of duties, guide audit lifecycles, and govern application changes while minimizing manual effort.
Responsibilities
- Design and operate ITGCs for enterprise applications covering logical access, change management, SDLC, computer operations, and segregation of duties
- Lead the first-line control environment by embedding controls directly into operational workflows alongside application owners and engineers
- Drive the segregation of duties strategy through role design reviews, conflict remediation, mitigating controls, and ongoing monitoring tooling
- Manage the audit lifecycle as the main liaison with internal audit, external audit, and the SOX PMO for walkthroughs, evidence gathering, and deficiency remediation
- Build AI-native continuous controls monitoring using LLM-based evidence review and automated anomaly surveillance
- Oversee the risk posture and controls for internal AI and automation initiatives by reviewing use cases and establishing validation expectations
- Run access governance processes including provisioning workflows, user access reviews, and privileged access management
- Govern application change management protocols for in-scope systems, ensuring proper approvals and release evidence
- Mature the compliance program through control consolidation and the shift toward automated and preventive controls
Requirements
- 10 or more years of professional background in IT controls, audit, or enterprise applications governance
- Hands-on operational experience within the first line of defense managing controls across NetSuite, Workday, or Salesforce
- Extensive knowledge of SOX 404, COSO, COBIT, and ITGC frameworks
- Demonstrated history of guiding external audit engagements from the management side
- Experience building and deploying AI-augmented control mechanisms, LLM reviewers, or automated anomaly detection
Qualifications
- Professional certifications such as CISA, CISSP, CIA, CPA, or equivalent credentials
- Familiarity with compliance frameworks like SOC 1 and 2, ISO 27001, NIST CSF, and PCI DSS
- Public company experience or IPO readiness background
Core Skills
Benefits
- Competitive base salary
- Company benefits
- Equity in the form of restricted stock units
Frequently Asked Questions
What is the employment type for this position?
This is a full-time, senior individual contributor role.
Where is the job located and is it remote?
The position is based in San Francisco with a hybrid work schedule. Employees based in San Francisco are expected to work from the office approximately two to three days per week.
What is the salary range for this role?
The target cash compensation for the San Francisco location ranges from $245,000 to $265,000 per year, with final offers determined by factors such as candidate experience and expertise.
What core technical background is required?
Candidates must have at least 10 years of experience in IT controls, audit, or enterprise applications governance, including hands-on work with NetSuite, Workday, or Salesforce, alongside deep expertise in SOX 404 and ITGC frameworks.
Sample Interview Questions
AI-generated questions tailored to this specific role — a preview of the full practice set.

