Risk Analyst
Listed on 2026-07-17
-
Finance & Banking
Financial Compliance, Auditor Accountant -
Accounting
Financial Compliance, Auditor Accountant
Senior Risk Management Professional – SOX Controls, Oversight & Advisory
Location:
Atlanta, GA Salary-$100k with benefits. Onsite and fulltime only Certifications in relevant areas are good to have, such as: CISA CPA CIA
The Senior Risk Management Professional will be responsible for defining, designing, independently reviewing, and strengthening SOX Information Technology controls across the organization. This role demands deep expertise in SOX control design and operating effectiveness, deficiency management, evidence validation, audit support, and remediation advisory. The role functions as an independent second line assurance ("watch the watchers"), providing oversight over control design, execution, testing quality, audit readiness, and ensuring SOX compliance KPIs are strictly met.
Key ResponsibilitiesSOX Controls Design, Review & Oversight Define, design, review, and independently assess SOX Information Technology controls. Perform detailed reviews of existing controls to identify:
Control design gaps or inadequacies Misalignment between risks and controls Ineffective, redundant, or unsustainable controls Evaluate Design Effectiveness (DE) to ensure controls sufficiently address identified SOX risks. Assess Operating Effectiveness (OE) to identify:
Execution inconsistencies Control failures Tool, automation, or manual dependency gaps Independent Control Review & Evidence Validation (Watcher Role) Act as an independent reviewer of control execution, testing approaches, and conclusions performed by control owners or first line teams. Perform rigorous SOX evidence validation, ensuring:
Evidence completeness, accuracy, and relevance Proper period coverage and traceability Alignment to control objectives and audit expectations Identify OE gaps, testing weaknesses, documentation gaps, and unsupported conclusions and recommend corrective actions. Ensure evidence quality meets external audit defensibility standards. Audit Query, Observation & Issue Management Actively support internal and external audit queries, walkthroughs, and information requests. Review audit questions and observations for technical accuracy and risk relevance.
Support management in drafting clear, risk based responses to audit observations. Assess audit observations to determine:
True control deficiencies vs documentation gaps Root causes and systemic issues Track and monitor audit observations through closure. Deficiency Assessment & Root Cause Analysis Identify and assess SOX control deficiencies, including:
Design deficiencies Operating effectiveness deficiencies Evidence and documentation deficiencies Perform detailed root cause analysis covering people, process, system, and governance aspects. Evaluate deficiency severity and potential impact in coordination with stakeholders and auditors.
Remediation & Preventive Advisory Provide remediation advisory support to ensure corrective actions are:
Risk aligned Sustainable Preventive in nature Recommend enhancements or necessary adaptations to controls based on:
Audit feedback Repeated deficiencies Changes in systems, processes, or compliance expectations Review remediation evidence and validate effective closure of deficiencies. Ensure remediation actions meet audit expectations and prevent future recurrence.
SOX Compliance Governance & KPI Management Ensure SOX compliance KPIs are strictly met, including but not limited to:
Timely execution of controls Quality and completeness of evidence On time audit responses Closure of audit observations and deficiencies within agreed timelines Monitor SOX performance metrics and highlight risks or slippages proactively. Drive continuous improvement in SOX control maturity and audit readiness.
Stakeholder & Control Owner Engagement Work closely with Control Owners, IT teams, and business stakeholders. Provide guidance, challenge control execution constructively, and promote accountability. Improve SOX awareness, execution discipline, and documentation practices across teams. Act as a trusted advisor to leadership on SOX risk posture and control effectiveness.
Required Skills & CompetenciesExtensive expertise in SOX Information Technology controls Strong mastery of Design Effectiveness and Operating Effectiveness evaluations Proven experience in detailed control reviews, OE gap analysis, and evidence validation Strong capability in audit support, observation management, and remediation advisory Ability to operate independently in a second line / oversight role Excellent analytical, communication, and stakeholder management skills
Education, Experience & CertificationsBachelor's degree in Information Systems, Accounting, Finance, Risk Management, or related field 8–12+ years of experience in SOX compliance, IT risk management, internal audit, or controls advisory
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).