IT SOX Manager
On-siteAustin, Texas, United States
Job Summary
Lead the execution of the IT SOX program, including scoping, planning, walkthroughs, testing, and reporting. Assess the design and operating effectiveness of IT General Controls and relevant application controls while performing end-to-end IT audit activities such as risk assessment, control testing, issue identification, and follow-up. Maintain accurate SOX documentation, partner with IT control owners to understand processes and resolve control issues, and track remediation activities to strengthen the overall IT control environment. Support Internal Audit and external auditors by coordinating requests and facilitating walkthroughs, while preparing SOX status reports and dashboards for leadership. Develop training and guidance to help IT control owners understand their responsibilities and contribute to continuous improvement initiatives that increase the efficiency and maturity of the IT SOX program.
Required Qualifications
- Strong knowledge of SOX, IT General Controls (ITGCs), and the COSO framework
- Understanding of how IT controls support internal controls over financial reporting (ICFR)
- Working knowledge of IT environments, including applications, databases, operating systems, infrastructure, and access/security controls
- Strong understanding of Software Development Life Cycle (SDLC) processes and related controls
- Strong analytical and problem-solving skills with the ability to identify risks and develop effective solutions
- Excellent communication and interpersonal skills with the ability to work effectively across IT, Accounting, Audit, and business teams
- Strong organizational skills with the ability to manage multiple priorities and deadlines
- Ability to work independently, exercise sound judgment, and take ownership of assigned responsibilities
- 4–7 years of experience in IT audit, IT compliance, IT risk management, or a related field
- Experience working in public accounting, internal audit, or a corporate SOX environment
- Hands-on experience supporting SOX ITGC testing and IT audits
- 3–5 years of end-to-end audit experience, including planning, fieldwork, testing, reporting, and follow-up
- Experience with SDLC controls, including application development, testing, change management, and implementation
- Experience identifying control gaps and supporting remediation efforts
- Experience working with both technical and non-technical stakeholders
Desired Qualifications
- CISA, CIA, CPA, CISSP, Security+, or progress toward a relevant certification is preferred
- Hands-on experience applying leading IT governance and security frameworks, including COBIT, NIST, ISO 27001, or SOC 1/SOC 2
- Proven experience leveraging GRC platforms such as AuditBoard or Archer to manage controls, evidence, testing, and remediation activities
- Experience working with identity and access management tools such as Okta or Microsoft Azure AD/Entra ID to support access controls and user provisioning processes
- Familiarity with change management and development tools such as Jira, with an understanding of how these tools support SDLC and change control processes
- Exposure to complex technology environments, including ERP, CRM, custom applications, and cloud platforms such as Microsoft Azure
- Knowledge of ITIL principles and IT service management processes
- Experience supporting SOX compliance within a public company environment
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.