What you will be doing- Desgn and implement the company's ICFR framework end to end - scoping and materiality analysis, risk assessment, process walkthroughs, narratives and flowcharts, and risk and control matrices across all significant processes
- Build the SOX program from the ground up: control design, testing calendar, evidence standards, documentation repository, and the operating cadence that keeps it running once we're public
- Design and execute control testing - test plans, sampling methodology, and design and operating effectiveness testing - and evaluate deficiencies for severity, aggregation, and disclosure implications
- Partner with process owners to remediate gaps: co-design practical controls, drive owner accountability through remediation plans and deadlines, and validate that fixes hold through subsequent testing cycles
- Coordinate ITGC scoping and testing with IT and third-party providers across ERP, access management, change management, and key system interfaces
- Serve as the primary liaison to external auditors and any co-sourced internal audit partner on controls matters, and report status, risks, and deficiencies to the CFO, Audit Committee, and executive leadership
You should have the following- 7-10 years of progressive experience in internal controls, internal audit, or risk advisory, including a foundation at a Big 4 firm
- Direct experience implementing a SOX program at a company going through IPO readiness or its first year as a public company - you've done a first-time implementation, not just maintained a mature program
- CPA, CIA, or equivalent certification
- Bachelor's degree in Accounting, Finance, Information Systems, or a related field
- Deep working knowledge of the COSO 2013 framework, PCAOB standards, and SEC reporting requirements as they apply to ICFR
- Demonstrated ability to design controls in an unstructured environment - scoping from a standing start, building control matrix and narratives where no documentation exists, and making pragmatic materiality and coverage judgments
- Strong working knowledge of ITGCs and how they interact with business process controls in an ERP environment (NetSuite preferred)
- Proven ability to influence process owners who don't report to you - securing buy-in on control design, driving remediation to completion, and escalating appropriately when timelines slip
- Excellent written and verbal communication, including the ability to present deficiency assessments and program status credibly to executives, external auditors, and an Audit Committee
Nice to have- Experience at a high-growth company that scaled revenue several-fold, where controls had to be redesigned as volume and headcount outgrew them
- Inventory, cost accounting, or manufacturing process controls experience in a hardware or physical-product business
- Familiarity with government contracting compliance environments (FAR, DFARS, CAS, DCAA audits) and how they overlay with SOX
- Hands-on experience implementing a SOX management tool (AuditBoard, Workiva, or similar)
- Experience with automation, continuous controls monitoring, or analytics-driven testing approaches
US Salary Range$133,000 - $186,000 USD
The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are considered part of Neros' total compensation package.