freehire launches on Product Hunt on 26 August.

Follow →

Senior Analyst, Security Compliance

Summary

Lead SOC 1/2 and SOX compliance audits, assess IT/security controls, drive remediation, and automate evidence collection for a fintech company.

You will lead SOC 1 and SOC 2 examinations, support SOX planning and execution, assess IT and security control design and effectiveness, drive remediation, mature ITGCs and ITACs, develop auditor-ready documentation, coordinate with auditors and control owners, and improve evidence collection through automation.

Responsibilities

  • Lead and manage SOC 1 and SOC 2 examinations under AICPA standards
  • Support end-to-end SOX planning and execution
  • Scope IT systems and prepare for audits
  • Develop and deliver training for control owners
  • Translate SOX and audit requirements into scalable controls
  • Lead security and IT control gap assessments
  • Evaluate control design and operating effectiveness
  • Drive remediation through completion
  • Mature ITGCs and ITACs
  • Oversee audit initiative quality and execution
  • Assess risk and guide teams through audit and compliance matters
  • Perform impact assessments for SOX control deficiencies
  • Design risk-based remediation plans
  • Implement and enhance controls monitoring
  • Identify systemic program challenges and recommend process improvements
  • Develop and maintain data flow diagrams and process flowcharts
  • Work with internal and external auditors
  • Support audit evidence collection and automation initiatives

Requirements

  • 5+ years of experience in external IT audit, technology risk assurance, or advisory
  • Experience with ICFR and SOX 404 frameworks
  • Experience with control design and operating effectiveness testing
  • Experience at a Big 4 or large public accounting firm, or with external auditors
  • Experience leading compliance and audit initiatives from planning through close
  • Experience assessing hybrid and cloud environments including IaaS, PaaS, and SaaS
  • Experience with access management, change management, and logging or monitoring controls
  • Experience with risk and control frameworks such as NIST, ISO 27001, or COBIT is a plus
  • CPA, CISA, CRISC, or similar certification is a plus

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available