IT SOX Compliance Manager
920 Winter Street Greater Boston Area, Massachusetts 02451
Position: IT SOX Compliance Manager
Location: Greater Boston Area
Duration: 6 months to start
Interview: Phone and In Person
PURPOSE AND SCOPE:
Support management of IT SOX compliance and related IT general and application controls at the corporate level and distributed among the divisions and locations. Manage the development, implementation and testing of controls for new acquisitions and in-scope entities. Manage the performance of annual internal control testing. Facilitate internal and external IT audits including Financial Statement and Sarbanes Oxley audits. Work with senior management to define remediation/mitigation for internally and externally identified audit and compliance deficiencies and track remediation progress. Assist in the management of the SAP GRC Process Control system used to document and manage financial and IT processes, controls, testing and remediation. Support the SAP access provisioning tool used to request, analyze and approve SAP requests. Assist in the management of SAP roles and the identification and assignment of appropriate SAP role approvers. Provide audit and regulatory guidance, support and subject matter expertise to the IT organization.
PRINCIPAL DUTIES AND RESPONSIBILITIES:
- Perform process and control assessments for new acquisitions and divisions, entities and locations new to the audit scope for potential IT general controls, application controls and process improvements. Assist in the definition of remediation plans, activities and retesting for potential issues and process improvement opportunities.
- Perform assessments of in-scope systems, processes and controls to verify that controls are designed appropriately and operating effectively. Assist in the definition of remediation plans, activities and retesting.
- Facilitate IT management’ s documentation updates and management assessments of all in-scope IT processes based on SOX and audit requirements via meetings with the IT Regulatory function and IT management.
- Participate in preparing periodic SOX 404 reporting to the SOX 404 Steering Committee.
- Perform the annual SOX 404 scoping exercise to determine if there are any changes to IT data centers, applications or related processes which should be considered to determine what is in scope for SOX 404 purposes.
- Provide regular updates to the department management (VP and Senior Manager) regarding the status of the SOX testing plans, the issues identified, and solutions to address the identified issues or deficiencies.
- With the IT SOX Compliance Senior Manager, serve as the principal interface with the external IT Audit function and the IT function regarding SOX IT audit related matters.
- In conjunction with the IT Regulatory Compliance function and the IT external auditor, analyze the SOX testing results and work with management to identify, document and test remediation plans for identified deficiencies.
- Responsible for access certifications of financially significant systems, including segregation of duties testing.
- Maintain current knowledge regarding changes to FSA and SOX compliance regulations and ensure that adjusts methodologies in response to the changes by issuing guidance and instructions to the appropriate IT stakeholders and personnel. Determine and recommend changes to current controls to address requirement change or issues.
- Play significant role in the implementation of major projects and initiatives related to auditing automation software and applications to manage governance tasks and SOX financial reporting functions, including the implementation of the SAP GRC platform.
- Monitor the SAP provisioning software to ensure that requests with potential risk/violations are appropriately addressed, mitigated or compensated.
- Other duties as assigned.
Additional responsibilities may include focus on one or more departments or locations. See applicable addendum for department or location specific functions.
PHYSICAL DEMANDS AND WORKING CONDITIONS:
- The physical demands and work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- This position will work out of the corporate headquarters in Waltham, MA with on-site meetings also at our IT facility in Lexington, MA. May require 10-20% travel.
- Reporting to IT SOX Compliance Senior Manager
- Supervise SOX Compliance Staff with Senior Manager
- Bachelor’ s degree in information systems, computer science, business administration.
- Certified Information Systems Auditor or Manager (CISA or CISM) certification preferred.
EXPERIENCE AND REQUIRED SKILLS:
- 8 – 12 years’ related experience in an IT audit firm; or a Master’ s degree with 6 years’ experience; or a PhD with 3 years’ experience; or equivalent directly related work experience.
- Experience working with or for external audit firm, Big Four IT audit experience preferred
- Experience auditing IT processes, applications and infrastructure (servers, databases, data centers, firewalls, etc.)
- Knowledge of COSO and CoBit control models preferred
- Experience with GRC systems, preferably SAP GRC
- Experience with ERP systems, preferably SAP and PeopleSoft
- Experience with healthcare systems preferably Siemens/Soarian
- Strong interpersonal skills and ability to work with senior level management in an independent manner
- Strong analytical and problem solving skills
- Strong organizational/communication skills
IT SOX Compliance Manager (SAP Specialist)
- Manage the SOD analysis component of the SAP provisioning software to ensure that the tool is appropriately configured to prevent SOD violations from being created and apply/approve compensating or mitigating control when possible.
- Monitor SAP role design and advise Basis team to promote IT SOX compliance and maintainability.
- Troubleshoot SAP authorization issues (via PFCG, SU24, SUIM) to protect against and correct inappropriate or excessive access.
- Monitor SAP tables, configurations and roles to evaluate completeness and accuracy of IT general and application controls.
- Trace user activity (via ST03, SUIM, SE16) in order to provide supporting evidence for IT General Controls.
- Leverage expertise in SAP table relations and Authorization Concept to provide mitigation / impact analysis in the event of control deficiencies.
Insert Department/Group Name