- As a SOX Compliance Specialist, you’ll be responsible for ensuring that the company's financial reporting and internal control processes comply with the Sarbanes-Oxley Act (SOX) regulations to ensure compliance and enhance corporate governance and financial transparency, as a publicly traded company.
What you’ll be doing
As part of your role, your responsibilities will include:
Risk Identification and Assessment
- Analyze financial and IT processes to identify and prioritize key SOX risks.
- Translate business and technology insights into actionable risk assessments, focusing on areas with the highest potential impact.
ITGC and Control Design
- Design and maintain SOX controls for ITGC domains: Logical Access, Change Management, and IT Operations.
- Ensure controls meet PCAOB standards for precision, frequency, and evidence, while balancing operational efficiency.
Control Testing and Audit Interaction
- Perform walkthroughs and testing for design and operating effectiveness of ITGCs and IT-dependent controls.
- Act as the primary contact for internal and external auditors, managing audit queries and facilitating compliance reviews.
Automation and Evidence Management
- Champion automation of control evidence collection (e.g., user access reviews, change approvals) to improve accuracy and efficiency.
- Collaborate with IT teams to implement solutions that streamline evidence gathering and maintain audit-ready documentation.
Continuous Improvement and Governance
- Own and oversee the SOX control framework, including ITGCs and IT Automated Controls, continuously seeking ways to refine processes.
- Monitor industry trends and best practices (COSO, COBIT) to maintain compliance standards and proactively address emerging risks.
Internal Control Assessment:
- This role is responsible to evaluate the design and effectiveness of internal controls over financial reporting (ICFR) to ensure compliance with SOX requirements.
Risk Assessment:
- The SOX Compliance Specialist identifies and assesses financial and operational risks that may impact the accuracy of financial statements. This involves understanding business processes and their associated risks.
Documentation:
- The maintenance of detailed documentation of financial processes, controls, and related policies are a function of this role. This includes documenting control procedures, flowcharts, and narratives.
Testing and Auditing:
- The SOX Compliance Specialist is responsible for conducting testing of internal controls to determine their effectiveness in preventing material misstatements in financial statements. This includes both walkthroughs and substantive testing.
Remediation:
- They collaboration with business units and control owners to address control deficiencies or weaknesses identified during testing and the development and implementation of remediation plans are responsibilities of this role.
This job description is not intended to be an exhaustive list of responsibilities. You may be required to complete other reasonable duties in order to achieve business objectives.
Essential skills you’ll bring to the table
The necessary skills that we require for this role include:
- Audit Expertise - Strong background in SOX 404 compliance and risk-based auditing, either:
- Financial Audit Path: Chartered Accountant (CA/CPA) or equivalent qualification, with experience in financial controls and regulatory compliance, OR
- Technology Audit Path: Experience in IT audit, ITGC testing, and technology risk management within SOX environments.
- SOX 404 Knowledge - Familiarity with PCAOB standards, COSO framework, and control design/testing methodologies.
- Analytical Skills - Ability to assess complex processes (financial or IT) and identify key risks.
- Technology Awareness - Understanding of ITGC domains (Logical Access, Change Management, IT Operations) and IT-dependent controls.
- Collaboration Skills - Comfortable working with IT teams on access management, change governance, and evidence automation.
- Project Management - Skilled in managing multiple stakeholders, timelines, and audit deliverables.
- Communication & Documentation - Strong ability to prepare narratives, control matrices, and respond to auditor queries clearly.
- The ability to respond appropriately under pressure
- Excellent problem-solving skills.
- Sound judgment
- The ability to build relationships with clients.
- Positive attitude
- Strong written and verbal communication skills
- Efficient with prioritization of tasks
- High sense of accountability
- Able to multi-task and work under pressure
- A team player with good interpersonal skills
- Must be able to use initiative and be proactive
Desirable skills you’ve got up your sleeve
It would be great if you also have some of the following skills:
- Active Directory – for user access and privileged account reviews.
- Microsoft Entra ID (Azure AD) – for identity and access governance in cloud environments.
- Microsoft SQL Server (MSSQL) – for validating data integrity and completeness of system reports.
- Scytale – for compliance automation and evidence management.
- Jira – for change management traceability and workflow approvals.