Manage the annual SOX compliance plan, including scoping, risk assessment, and maintenance of the master testing calendar.
Lead walkthroughs with process owners; develop and maintain narratives, flowcharts, and risk‑control matrices (RCMs).
Execute and review detailed testing of key manual, automated, ITGC, and entity‑level controls; ensure work‑paper quality meets PCAOB standards.
Evaluate control deficiencies, perform root‑cause analyses, determine severity, and partner with owners to design and track remediation plans to closure.
Develop and maintain dashboards and metrics to communicate SOX status, testing progress, and remediation trends to stakeholders and the Audit Committee.
Administer the enterprise GRC platform (e.g., Workiva, OneTrust): manage workflows, evidence repositories, and continuous‑monitoring capabilities.
Coordinate external‑audit requests, align testing strategies, and negotiate sample rationalization to minimize business disruption.
Advise control owners on design enhancements, segregation‑of‑duties conflicts, and automation opportunities (e.g., RPA, analytics).
Maintain a common control framework mapping SOX controls to other standards (COSO, COBIT) and related compliance requirements.
Provide SOX training and promote a culture of compliance, continuous improvement, and agile practices across finance, IT, and business operations.
Lead SOX impact assessments for M&A integrations, new system implementations, and other significant business changes.
Mentor and review work of junior staff and co‑sourced partners, ensuring consistency and high quality across the SOX program.
Requirements
Bachelor’s degree in Accounting, Finance, Information Systems, or a related field; Master’s degree a plus.
7+ years of combined SOX, internal audit, or Big 4 assurance/advisory experience with hands‑on exposure to ITGCs and automated controls.
CPA, CIA, CISA, or similar professional credential strongly preferred.
Deep knowledge of COSO framework, PCAOB guidance, and leading ERP/Cloud platforms (Workday, Salesforce, Zuora, GitHub).
Proficiency with GRC/ICFR tools (Workiva, OneTrust, or similar) and data‑analytics platforms (e.g., Power BI, Tableau, SQL).
Demonstrated ability to analyze complex processes, manage multiple priorities, and drive projects to completion under tight deadlines.
Excellent written and verbal communication skills; able to translate technical control concepts for finance and non‑technical audiences and present to executives.
Proven ability to influence cross‑functional stakeholders, mentor team members, and uphold high ethical standards.