Lead, Security Controls Assurance - SOX
Core
Lead Security Controls Assurance for SOX compliance, defining IT general controls (ITGC) requirements and acceptance criteria for engineering systems to support financial reporting.
Role type
Senior IC Security Controls Assurance Lead (SOX)
Builds
Control design methodology, continuous control monitoring, and automated evidence collection for ITGCs.
Domain
Financial services compliance (SOX) + Cloud Infrastructure & Engineering
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SOX 404 compliance expertise, PCAOB AS 2201 knowledge, COSO 2013 framework, ITGC design (logical access, change management, computer operations, program development), engineering fluency (code reading, Terraform, CI/CD), Python or systems language (Go, Rust, C/C++), second-line control monitoring, cross-functional collaboration
Preferred skills
Big 4 audit experience, first-year SOX 404(a)/(b) assessment leadership, home-built financially significant systems control definition, AI/ML system controls, continuous controls monitoring setup, SOC 1 reliance, CISSP/CISA/CPA certification
Technologies
Python, Go, Rust, C/C++, Terraform, CI/CD pipelines, LLMs (Claude)
Responsibilities
Define control requirements and acceptance criteria for SOX in-scope systems; pressure-test infrastructure changes for SOX impact; own second-line control monitoring and evidence readiness; drive control deficiency remediation; assess scope changes through a SOX lens; maintain alignment with broader compliance portfolio (SOC 2, ISO 27001/42001).
Seniority
Senior, hands-on IC with strategic oversight