×
Register Here to Apply for Jobs or Post Jobs. X

Sr. Manager, IT Control, Assurance & SOX

Job in Raynham, Bristol County, Massachusetts, 02767, USA
Listing for: J&J Family of Companies
Full Time position
Listed on 2026-08-14
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant, IT Project Manager
Job Description & How to Apply Below

Sr. Manager, IT Controls, Assurance & SOX

DePuy Synthes is recruiting for a Sr. Manager, IT Controls, Assurance & SOX located in New Brunswick, NJ or Palm Beach Gardens, FL or Warsaw, IN or West Chester, PA or Raynham, MA.

This role leads the design, execution, and continuous improvement of DePuy Synthes' IT controls, assurance, and (SOX) program within the Governance & Risk function of Cybersecurity. The Sr. Manager will own the enterprise IT SOX control framework, IT general controls (ITGCs), automated application controls, and IT-related assurance activities across financially relevant systems, cloud platforms, and third-party services. This position partners closely with Finance, Internal Audit, External Auditors, Application Owners, and Infrastructure teams to ensure a strong control environment, timely remediation of deficiencies, and audit-ready operations as the company stands up as an independent, publicly traded entity.

Key Responsibilities
  • Own the enterprise IT control framework — including ITGCs (access, change, operations), automated application controls, and IT-dependent business controls — aligned to COBIT, COSO, NIST CSF, and internal policies
  • Lead design and operating effectiveness assessments of IT controls across ERP, cloud, SaaS, and infrastructure platforms, and drive remediation of identified gaps
  • Partner with application, cloud, and infrastructure teams to embed preventive and detective controls by design in the SDLC, Dev Ops pipelines, and cloud landing zones
  • Extend the assurance program to third parties and managed service providers, including review of SOC 1/SOC 2 reports, complementary user entity controls (CUECs), and bridge letters
  • Serve as the primary IT liaison for Internal Audit, External Auditors, and regulatory examiners — coordinating walkthroughs, evidence, testing, and management responses
  • Advance continuous controls monitoring (CCM), analytics, and automation to expand control coverage and reduce manual testing effort
  • Own the end-to-end IT SOX program — scoping, risk assessment, control design, management testing, deficiency evaluation, and reporting across in-scope financial systems and supporting IT infrastructure
  • Define the annual IT SOX plan in partnership with Finance, Internal Audit, and External Auditors, including in-scope applications, ITGCs, key reports, and automated controls
  • Lead management testing of ITGCs and IT-dependent business controls, ensuring timely completion, quality of evidence, and consistent workpaper standards
  • Drive deficiency evaluation, root cause analysis, remediation planning, and status reporting to leadership and the Audit Committee
  • Stand up and operate the first-year SOX program for the standalone DePuy Synthes entity, including RCMs, narratives, and control ownership across the new operating model
  • Modernize the SOX program through GRC tooling (e.g., Service Now IRM, Audit Board, Archer), risk-based sampling, and automated evidence collection
  • Lead IT compliance activities across applicable regulatory, contractual, and internal policy requirements — including SOX, SEC, GxP, HIPAA, GDPR, and other data protection and industry regulations
  • Maintain an integrated IT policy, standard, and control library, and drive alignment across Cybersecurity, IT, Legal, Privacy, and Compliance functions
  • Track regulatory change, assess IT impact, and update controls, policies, and evidence to keep the environment continuously compliant
  • Coordinate IT responses to customer, partner, and regulator due diligence requests, security questionnaires, and certification programs (e.g., ISO 27001, HITRUST where applicable)
  • Assess compliance implications of emerging technologies (cloud, AI/ML, GenAI, automation) and update the control and compliance framework accordingly
  • Provide training, guidance, and clear escalation paths to IT and business control owners to reinforce a strong compliance culture
  • Provide regular reporting to the CISO, Director of Governance & Risk, Finance leadership, and the Audit Committee on IT controls, SOX status, and compliance posture
  • Support Day-1 readiness and post-separation BAU operations for controls, assurance, SOX, and compliance across…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary