SOX & Internal Controls Compliance IT Manager, CoStar Group - Arlington, VA
Job in
Arlington, Arlington County, Virginia, 22201, USA
Listed on 2026-08-12
Listing for:
CoStar Group, Inc.
Full Time
position Listed on 2026-08-12
Job specializations:
-
IT/Tech
Cybersecurity, IT Business Analyst, IT Consultant, Information Security & Data Protection
Job Description & How to Apply Below
SOX & Internal Controls Compliance IT Manager – CoStar Group
Location:
Arlington, VA | In office, Monday-Friday
The SOX & Internal Controls Compliance IT Manager supports Sarbanes-Oxley (“SOX”) compliance, internal controls, and enterprise risk management (“ERM”) assessments. The role involves implementing SOX compliance programs, executing tests to validate operating effectiveness, and coordinating with IT and Information Security to align financial systems with cybersecurity standards.
Responsibilities- Support SOX compliance, internal controls, and ERM assessments.
- Assist with implementing SOX compliance programs, including risk assessments, system scoping, walkthroughs, and documentation of end‑to‑end technology processes.
- Document and assess the design and effectiveness of key IT general controls (ITGC) and IT application controls (ITAC). Execute testing to validate the operating effectiveness of controls.
- Evaluate control deficiencies to determine impact and significance, and identify and implement remediation plans.
- Summarize and document results of work performed, including management reporting.
- Execute internal controls and IT risk management activities to support risk initiatives.
- Ensure robust IT General Controls over logical access management, role‑based security, segregation of duties, change management, system interfaces, data integrity, and configuration controls.
- Oversee periodic user access reviews and segregation of duties analyses.
- Coordinate with IT and Information Security to align financial systems governance with enterprise cybersecurity standards.
- Assess technology risks and internal control solutions associated with ERP, SaaS, IT infrastructure, and cloud platforms.
- Create and deliver presentations on technical concepts, project work plans, delivery approach, milestones, and results to key stakeholders.
- Deliver efficient and effective approaches to implement and assess risks related to information security and change management.
- Implement data analytics to enhance approaches to internal control assessments.
- Work effectively across technology, accounting, finance, and operations groups within the company.
- Bachelor’s degree in Information Systems, Accounting, Finance, or a related field from an accredited, not‑for‑profit, in‑person college/university.
- 7–8+ years of professional services experience with IT risk management and internal controls.
- Track record of commitment to prior employers.
- One or more of the following risk‑related certifications preferred: CPA, CIA, CISA, or CISSP.
- Deep knowledge of SOX compliance and PCAOB requirements, SOX 404, COSO framework, ITGCs, segregation of duties architecture, ERP and financial systems governance.
- Experience implementing and assessing controls over highly automated business processes.
- Knowledge of emerging technology risks (cloud computing, agile development, cybersecurity, privacy) and best practices for authentication, authorization, and change management.
- Ability to manage and prioritize assignments while meeting deadlines and maintaining attention to detail.
- Excellent analytical, problem‑solving, and critical‑thinking skills to assess complex IT risks and identify appropriate control enhancements.
- Exceptional verbal and written communication skills, with the ability to effectively communicate technical concepts to non‑technical stakeholders.
- Experience in a publicly traded company ($1B+ revenue) or Big 4 experience required.
- 7–8+ years of experience in IT auditing, IT compliance, or IT risk management, preferably within a large organization or a public accounting firm.
- Knowledge and application of IT controls and governance frameworks such as SOC 1/2, COBIT, NIST (CSF, 800‑53, 800‑171), ITIL, ISO 27001/2.
- Experience on ERP applications such as Oracle Cloud.
- Proven experience in executing technology audits, including evaluating IT general controls, application controls, and data integrity.
- Global, multi‑entity experience preferred.
- Comprehensive healthcare coverage: medical, vision, dental, prescription drug, life, legal, and supplementary insurance.
- Virtual and in‑person mental health…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×