SOX Tech Risk and IAM Lead
Listed on 2026-07-19
-
IT/Tech
Cybersecurity, Information Security
This position requires Daily Office Presence (5 days a week) in the listed location(s). No relocation assistance is provided.
Join AT&T and reimagine the communications and technologies that connect the world. Our Chief Security Office ensures that our assets are safeguarded through truthful transparency, enforce accountability and master cybersecurity to stay ahead of threats. Bring your bold ideas and fearless risk-taking to redefine connectivity and transform how the world shares stories and experiences that matter. When you step into a career with AT&T, you won’t just imagine the future-you’ll create it.
AT&T will not hire any applicants for this position who require employer sponsorship now or in the future.
KeyRoles and Responsibilities
This is an individual contributor position with no direct reports.
Lead the identification, assessment, and mitigation of technology risks across the organization.
Develop and maintain risk frameworks, policies, and procedures aligned with industry best practices.
Develop and enforce Identity and Access Management (IAM) policies and procedures to ensure compliance with SOX requirements.
Oversee the control environment for multiple IAM platforms (such as SailPoint, Cyber Ark, Active Directory, Azure AD), ensuring seamless integration with governance, risk, and compliance (GRC) tools and supporting the organization’s overall security and compliance objectives.
Drive coordination and program management for initiatives impacting SOX scope, including new scope, technology process and control changes and optimization.
Serve as an end-to-end process and IT control expert advising control and process owners on SOX requirements, risk assessment, control design, and optimization strategies.
Participate in walkthroughs for high-risk areas and changes to help ensure readiness and control design effectiveness.
Evaluate process and control changes, evaluate risk, business process transformations, advise on new initiatives for SOX impact, and provide clear, actionable recommendations
Oversee the documentation of control narratives and perform control testing
Collaborate with technical and business stakeholders to support the deficiency evaluation process including root cause analysis, impact assessment, management action plan development, remediation monitoring and validation.
Oversee the development and execution of cybersecurity controls, including access management, vulnerability management, incident response, and data protection.
Partner with process owners and control owners to drive awareness and understanding of SOX requirements and protocols, control design requirements, and enterprise control strategy.
Develop and review new and updated testing procedures to ensure control evidence and scope are sufficient and aligned with risk.
Stay current on cyber threats, regulatory requirements, and control frameworks (e.g., NIST, ISO 27001).
5+ years of experience in Internal Audit, SOX Compliance, Risk Advisory, and/or Public Accounting.
Bachelor's or Master's degree in Computer Science, Computer Engineering, Information Systems, or related field (preferred).
Professional certifications preferred: CISA, CRISC, CISSP, CPA, CIA, AWS Certified Cloud Practitioner (or higher).
Strong knowledge of SOX IT General Controls (ITGCs), technology risk, financial reporting risk, PCAOB requirements, and internal controls.
Experience leading SOX readiness, automation, and transformation initiatives.
Deep understanding of Identity and Access Management (IAM) principles, standards, and frameworks including NIST 800-53, ISO 27001, and CIS Controls.
Hands-on experience assessing and implementing IAM controls across complex technology environments.
Strong knowledge of cloud platforms (AWS, Azure, GCP) and their IAM capabilities.
Extensive experience with SailPoint, Cyber Ark, and Delinea, including Privileged Access Management (PAM), process documentation, and SOX control design.
Experience with IT Security Audits, Cloud Engineering, and IAM governance.
Familiarity with applying Artificial Intelligence (AI) or Machine Learning (ML) techniques in cybersecurity contexts (e.g., anomaly detection,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).