Senior Analyst, Security Compliance
Summary
Lead SOC 1/2 and SOX compliance efforts, assess IT/security controls, drive remediation, and automate evidence collection for a fintech company.
You will lead SOC 1 and SOC 2 examinations, support SOX planning and execution, assess IT and security control design and effectiveness, drive remediation, mature ITGCs and ITACs, develop auditor-ready documentation, coordinate with auditors and control owners, and improve evidence collection through automation.
Responsibilities
- Lead and manage SOC 1 and SOC 2 examinations under AICPA standards
- Support end-to-end SOX planning and execution
- Scope IT systems and prepare for audits
- Develop and deliver training for control owners
- Translate SOX and audit requirements into scalable controls
- Lead security and IT control gap assessments
- Evaluate control design and operating effectiveness
- Drive remediation through completion
- Mature ITGCs and ITACs
- Oversee audit initiative quality and execution
- Assess risk and guide teams through audit and compliance matters
- Perform impact assessments for SOX control deficiencies
- Design risk-based remediation plans
- Implement and enhance controls monitoring
- Identify systemic program challenges and recommend process improvements
- Develop and maintain data flow diagrams and process flowcharts
- Work with internal and external auditors
- Support audit evidence collection and automation initiatives
Requirements
- 5+ years of experience in external IT audit, technology risk assurance, or advisory
- Experience with ICFR and SOX 404 frameworks
- Experience with control design and operating effectiveness testing
- Experience at a Big 4 or large public accounting firm, or with external auditors
- Experience leading compliance and audit initiatives from planning through close
- Experience assessing hybrid and cloud environments including IaaS, PaaS, and SaaS
- Experience with access management, change management, and logging or monitoring controls
- Experience with risk and control frameworks such as NIST, ISO 27001, or COBIT is a plus
- CPA, CISA, CRISC, or similar certification is a plus
Benefits
- Equity
- Bonus program
- Wellness allowance
- Medical insurance
- Dental insurance
- Vision insurance
- 401(k)