Manager, SOX Compliance
Listed on 2026-02-14
-
IT/Tech
Cybersecurity, IT Business Analyst
Job Summary
We’re building a world of health around every individual—shaping a more connected, convenient, and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable, and prioritize safety and quality in everything we do. Join us and be part of something bigger—helping to simplify health care one person, one family, and one community at a time.
A leading enterprise technology organization is seeking a highly skilled Manager, SOX Compliance to advance and mature its Technology Compliance function. This role requires strong technical acumen, including experience with AI‑driven controls monitoring, Identity and Access Management (IAM), automation tools, and new system implementations. The Manager will drive both strategic oversight and hands‑on execution of SOX ITGC compliance activities across the enterprise’s digital platforms and evolving technology ecosystem.
The Manager, SOX Compliance will act as a key liaison between internal technology teams, business partners, system owners, and external auditors. They will oversee the integrity and efficiency of SOX testing processes, evaluate evidence for completeness and accuracy, and leverage automation and intelligent tooling to streamline control testing and reporting. The role includes assessing IAM practices, monitoring access provisioning controls, and ensuring appropriate governance across both legacy and modern cloud environments.
This leader will also provide guidance on technology‑driven remediation efforts, influence the design of controls for new applications and system implementations, and partner with engineering teams to embed compliance requirements early in the development lifecycle. This is a critical role in ensuring a stable, well‑controlled environment that supports financial, operational, and regulatory objectives while enabling innovation and digital transformation.
Key Responsibilities- Lead and execute ITGC testing activities, with emphasis on access management, user provisioning and termination processes, and change management controls.
- Validate and assess audit evidence to ensure completeness, accuracy, and proper traceability to system‑of‑record sources (IPE validation).
- Collaborate with subject matter experts to resolve audit discrepancies, including missing documentation, unclear access histories, and process gaps.
- Participate in system scoping assessments to understand data flows across claims, operational, and financial control systems.
- Serve as a first‑level reviewer of audit evidence, control narratives, and remediation summaries prior to escalation to leadership or external auditors.
- Provide guidance and education to control owners on SOX expectations, documentation requirements, and audit readiness.
- Partner closely with internal audit, legal, risk management, and IT teams to ensure alignment and consistency in audit execution.
- Manage requests within Audit Board and ensure timely, accurate responses from business units and technical teams.
- Monitor, track, and report status of findings, remediation efforts, and stakeholder deliverables.
- Build and maintain strong relationships across business units to strengthen control awareness and foster a positive compliance culture.
- Use JIRA to track and manage daily compliance activities, workflow, and issue resolution.
- 5+ years of experience in SOX compliance, ITGC testing, or technology audit.
- 3+ years of direct experience working with the SOX Compliance Framework.
- 3+ years collaborating with cross‑functional teams in complex corporate or regulated environments.
- 1+ year of experience performing system traceability assessments and IPE testing.
- Deep understanding of SOX 404 requirements, ITGC domains, and audit methodologies.
- Familiarity with relevant industry frameworks, including NIST, ISO, HITRUST, HIPAA, and PCI.
- Strong analytical, troubleshooting, communication, and documentation skills.
- Experience with claims systems or healthcare‑related control environments.
- Professional certifications such as CISA, CRISC, CISM, or CGEIT.
- Industry…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).