Job Description
The IT Compliance Analyst for our client is responsible for ensuring our compliance with Sarbanes-Oxley 404 (SOX) reporting requirements, and assisting in our other Information Technology initiatives, such as implementation of SOX framework, reviewing / validating SOC reports and assure that our systems are following PCI DSS mandates.
This position is part of the Global IT organization in Sunnyvale, California. United States
and will be a fully remote position. You will be a part of the IT Compliance and report to the Senior IT Compliance Manager responsible for SOX and other compliance activities.
If you thrive in a fast-paced and evolving role and want to work to build a world-class IT compliance organization read on.
Job Experience Requirements :
- Minimum bachelor's degree, ideally in a relevant field
- Minimum of 5 years' experience working in a related field but ideally 10+ years.
- Applicant must be initiative-taking and be able to work without constant supervision.
- Must possess a compliance / audit mindset and has proven experience putting it to use.
- It would be a plus if you also possess previous experience in :
- Previous experience working with Sarbanes-Oxley 404 compliance is a huge advantage.
- Familiarity and experience with other compliance topics such as GDPR, ISO 27k, NIST2, etc.
- Proficient knowledge of SAP, OneStream, Salesforce a big plus
- CISA / CIA certification preferred, but not required.
Job Responsibilities :
- Assess and document all IT General Controls related to the SOX program as part of on-going compliance efforts.
- Be responsible for monthly data handling in relation to SOX controls.
- Be responsible for quarterly user access review, initiating the reviews and follow up on completion.
- Perform semi-monthly associate job transfer analytics.
- Perform monthly termination investigations.
- Participation in EY and Danaher Corporate ITGC and SOX audits three times a year, identifying and gathering of documentation and evidence for the auditors.
- You will take daily control of our audit process for AD shared and service accounts, CyberArk privileged accounts (monitoring access and activity), job batch monitoring, including the ongoing maintenance of our list of assets and systems.