Lead, Security Controls Assurance - SOX
Leads technical SOX controls assurance for financially significant systems, translating audit requirements into engineering acceptance criteria and continuous monitoring. Requires ITGC and SOX 404 expertise, strong engineering fluency, programming ability, and cross-functional collaboration with Finance, Engineering, and auditors.
About the job
Responsibilities
- Define control requirements and acceptance criteria across IT general control domains: logical access, change management, computer operations, and program development for SOX in-scope systems.
- Establish auditability, segregation of duties, change control, immutable logging, and evidence-retention requirements for financially significant systems before go-live.
- Review infrastructure, system, and agent-framework changes for SOX impact, including changes to scope, key control populations, and evidence requirements.
- Own second-line control monitoring and evidence readiness, including continuous controls monitoring, automated evidence collection, control testing, walkthrough preparation, population and completeness validation, and controls-framework mapping.
- Drive root-cause analysis and remediation of ITGC deficiencies with engineering, Internal Audit, and external-audit partners; assess remediation effectiveness before retesting.
- Assess the control-design, evidence, and engineering impact of new products, entities, systems, and integrations entering SOX scope.
- Align SOX ITGCs with SOC 2, ISO 27001/42001, and other compliance frameworks so controls and evidence are designed and maintained efficiently.
Requirements
- Experience leading or making senior contributions to an ITGC program through SOX 404 readiness and/or at a public company.
- Working knowledge of PCAOB AS 2201, COSO 2013, and external-auditor technology-control scoping, testing, and deficiency evaluation.
- Engineering fluency, including the ability to read code and Terraform, follow CI/CD pipelines, and assess technical designs.
- Programming experience in Python or a systems language such as Go, Rust, C, or C++.
- Familiarity with developer platforms, release engineering, cloud infrastructure, or ERP and financial-systems controls.
- Understanding of second-line assurance responsibilities and the distinction between monitoring and Internal Audit’s independent testing.
- Strong collaboration and communication across Finance, Engineering, Internal Audit, and external auditors.
- Experience using Claude or other LLMs as working tools and evaluating appropriate AI applications for SOX assurance.
- Bachelor’s degree or equivalent combination of education, training, and experience.
Nice-to-haves
- Big Four or equivalent audit/advisory experience, ideally in IT audit, combined with in-house experience at an AI-focused technology company.
- Experience with first-year SOX 404(a) and 404(b) assessments, including a first external ITGC audit.
- Experience defining or assessing controls for home-built financially significant systems, usage-based billing, or revenue-metering pipelines.
- Experience defining or assessing controls for AI/ML systems or production agents.
- Experience establishing continuous controls monitoring or automated evidence programs.
- Experience with SOC 1 reliance, service-organization control mapping, and complementary user-entity controls.
- CISSP, CISA, CPA, or equivalent certification.
Compensation
- Annual salary: $410,000–$510,000 USD.
Skills
Sox 404, Itgc, Pcaob As 2201, Coso 2013, Terraform, CI/CD, Python, Go, Rust, C++, Cloud Infrastructure, SOC 2, ISO 27001, Continuous Monitoring, LLMs
Similar jobs
Security Engineering jobsLeads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.
Owns DRTM adoption, attestation, and platform hardening across x86 and ARM infrastructure, working across firmware, bootloaders, kernels, hardware, and silicon security. The role requires deep systems-security experience, upstream Linux or firmware contributions, and strong vendor and OEM leadership.
Leads cyber-focused AI misuse enforcement, managing analysts and contractors while developing detection and mitigation strategies for attacks, malware, and exploitation. Requires people management, cybersecurity expertise, high-volume abuse enforcement, data analysis with SQL or Python, and cross-functional risk communication.
Defines the security architecture for a next-generation operating system, spanning trust boundaries, hardware-backed protections, isolation, secure updates, and AI-agent guardrails. The role requires deep privileged-systems expertise, systems programming ability, and experience securing platforms across hardware, firmware, and software.
Leads cybersecurity and cyber intelligence operations for high-risk user-safety decisions, combining strategic planning, operational systems, automation, and direct people management. Requires 8+ years in cybersecurity-related work and 4+ years leading teams.