IT GRC SOX Specialist - Regulatory Frameworks
Listed on 2026-09-13
-
IT/Tech
IT Business Analyst, IT Consultant, Cybersecurity, Information Security & Data Protection
AVEVA is creating software trusted by over 90% of leading industrial companies.
Job Title:
IT GRC SOX Specialist |
Location:
London or Cambridge (Hybrid - min 50% office based) |
Employment Type:
Permanent (full-time)
We are seeking an experienced IT SOX Specialist to facilitate the implementation and strengthening of SOX IT controls within the IT function. Further, to help transition IT SOX controls, testing, evidence, and issue management to Riskonnect, recognising the platform is currently in development and may require pragmatic interim processes. Further, this role will help to introduce a robust assurance role in IT to support the SOX framework.
KeyObjectives
- SOX-aligned IT control framework implemented and testing and feedback clearly documented (ITGCs + relevant application controls)
- IT teams trained and confident in operating controls, producing consistent evidence, and supporting walkthroughs/testing.
- Helping to drive a clear, workable SOX operating model for IT (RACI, control calendar, evidence standards, testing approach).
- Riskonnect configured/ready (to the extent possible within the programme) to support IT SOX processes, with interim tooling and migration approach defined.
- Improved audit outcomes (fewer repeat findings, improved first-time pass rates, timely remediation closure).
- IT SOX implementation & control uplift; transition to BAU SOX Assurance
- Support current-state assessment and gap analysis of IT controls against SOX expectations, providing guidance as necessary.
- Test ITGCs and supporting procedures across Access Management, Change Management, IT Operations, SDLC / Release governance.
- Create/refresh control documentation (narratives, flowcharts, RCMs, control procedures, evidence checklists).
- Upskilling and knowledge transfer:
Facilitate structured IT SOX handover to BAU teams using workshops, coaching, playbooks, how to evidence guides as required. - Coach control owners/operators through real deliverables (walkthroughs, evidence collection, testing support).
- Implement sustainable routines: control performance cadence, peer review/quality checks, and audit readiness checkpoints.
- Riskonnect enablement:
Facilitate rollout and manage Control library structure and attributes, RCM mapping (risks - controls - processes - systems), Testing workflow requirements, Issue and remediation tracking as well as reporting and dashboards for IT leadership and audit stakeholders. - Define interim processes for control tracking, evidence storage, and status reporting until Riskonnect is live.
- Audit, testing and stakeholder management:
Support internal / external auditors for IT controls walkthroughs and testing. - Coordinate evidence requests and ensure responses are timely, complete, and consistent with control intent.
Strong, demonstrable experience operating SOX ITGCs and supporting SOX audits (walkthroughs/testing/remediation). Practical experience embedding controls into IT processes. Experience working in environments with evolving tooling and maturity; able to set up effective interim approaches. Proven ability to coach and upskill IT teams and build sustainable control ownership. Experience with GRC tools (Riskonnect desirable) and experience of standard IT tooling that support SOX controls for extraction of relevant data.
Strong SOX/ICFR understanding and audit expectations (PCAOB-aligned). Knowledge of COSO, COBIT, ITIL; awareness of ISO 27001 / NIST helpful for alignment. 5+ years experience in IT, Information Security, Risk, Audit, or related discipline.
- Excellent documentation and control design skills.
- Confident facilitator/trainer; can communicate effectively with engineers, managers, auditors, and finance stakeholders.
- P…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).