Geico

Principal, SOX and MAR

Geico • $146K — $229K *
Finance & Insurance
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in SOX program management or Internal Audit in public companies
  • Bachelor's degree in Accounting, Finance, or related field
  • Expertise in SOX Sections 302 & 404 and COSO Framework
  • Experience with ITGCs and automated controls
  • Ability to influence senior stakeholders and drive initiatives
  • Strong analytical and project management skills
  • Excellent communication and documentation abilities

Responsibilities

  • Coordinate execution alignment with the overall SOX program
  • Maintain the annual SOX program calendar and manage key milestones
  • Develop governance documents and prepare status materials
  • Identify opportunities for process improvements and efficiency
  • Lead annual SOX risk assessment and analyze financial reporting risks
  • Guide control owners on maintaining accurate, audit-ready documentation
  • Coordinate interactions with Internal and External Audit for compliance

Benefits

  • Comprehensive health, dental, and vision care
  • 401(k) plan with company match
  • Paid time off and holidays
  • Career development and advancement opportunities
  • Flexible working arrangements including remote work options
Full Job Description

Principal, SOX and MAR

The Principal, SOX serves as the senior execution lead and technical subject matter expert within the SOX Program Management Office (PMO), accountable for driving day-to-day execution, governance, documentation quality, stakeholder coordination, and continuous improvement of GEICO’s Sarbanes-Oxley and NAIC Model Audit Rule compliance programs under the direction of the Director, SOX PMO.

The Principal partners closely with process owners and key stakeholders, including IT leadership, Internal Audit, and External Audit, to help ensure that Internal Control over Financial Reporting (ICFR) remains effective, scalable, and risk-aligned in support of management’s assertions under Sections 302 and 404 of Sarbanes-Oxley and Section 16 of the NAIC Annual Financial Reporting Model Regulation (Model #205). This role serves as a catalyst for strategic transformation and continuous improvement across the SOX program.

Role in Context

The Principal operates within the SOX PMO as a management governance and execution role. Process and control owners remain accountable for control design, execution, evidence, certification, and remediation. The SOX PMO establishes and administers the program framework and standards. Internal Audit independently tests controls and provides independent assurance.

The Principal is authorized to manage routine program execution and enforce approved SOX PMO standards, while escalating material scoping decisions, methodology changes, deficiency classifications, unresolved stakeholder matters, and other risk-significant judgments to the Director, SOX PMO.

Key Responsibilities

1. SOX Program Execution and Governance

  • Coordinate execution alignment with the parent company’s consolidated SOX program, including applicable methodology, scoping, documentation, certification, and reporting requirements, and escalate potential alignment issues to the Director.
  • Maintain the annual SOX program calendar, including key planning, walkthrough, testing readiness, deficiency evaluation, remediation, certification, and reporting milestones.
  • Serve as the day-to-day program execution lead, developing governance documents, maintaining program trackers, coordinating deliverables, preparing status materials, and escalating risks, delays, and decision points to the Director, SOX PMO.
  • Drive governance over both business process and IT-dependent controls by promoting adherence to program standards, methodologies, and documentation requirements.
  • Identify opportunities to enhance program effectiveness, efficiency, and scalability through process improvements and automation initiatives.
  • Apply SOX, ICFR, and COSO expertise to guide day-to-day program execution, documentation, and stakeholder decisions.

2. Risk Assessment and Scoping

  • Lead execution of the annual SOX risk assessment process, including analysis of significant accounts, applications, disclosures, financial reporting risks, fraud risks, and changes impacting in-scope processes, systems, reports and third-party service providers, with recommendations prepared for Director review and approval.
  • Evaluate business, operational, and technology changes for potential SOX impacts, including MAR considerations and governance of entity-level controls (ELC).
  • Govern SOX content and change control within the GRC platform by developing and maintaining program standards, reviewing risk-significant changes and facilitating approval through the SOX PMO governance process.
  • Partner with control owners to help confirm risks, controls, applications, evidence, deficiencies, and remediation plans remain current, accurate, and audit ready.

3. Business Process Controls Execution

  • Lead reviews of process narratives, flowcharts, and risk-and-control matrices (RCMs) for quality, consistency, and compliance with SOX methodology.
  • Partner and drive follow-through with Finance, Actuarial, Claims, Underwriting, Premium, Reinsurance, Treasury, Tax, Technology, and other functional leaders to strengthen control design and execution.
  • Lead documentation-quality and readiness reviews for financial-close controls, including journal entries, account reconciliations, financial reporting, and disclosure-related controls.
  • Provide guidance and challenge around Management Review Controls (MRCs), evidence standards, precision of review, and documentation quality consistent with PCAOB expectations and industry best practices.
  • Perform quality reviews of SOX documentation, including RCMs, narratives, walkthroughs, control evidence, and issue documentation to promote accuracy, consistency, completeness, and audit readiness.

4. IT Controls and Automated Controls Governance and Execution

  • Coordinate governance over IT General Controls (ITGCs) with technology stakeholders, including logical access, change management, computer operations, and system development lifecycle controls for in-scope systems.
  • Develop and maintain standards for automated application controls, system-generated reports, and Information Produced by the Entity (IPE), including design and documentation adequacy.
  • Govern third-party service provider control considerations, including SOC report reviews, bridge letter monitoring, complementary user entity control evaluation, gap assessment, and remediation tracking.
  • Coordinate with AI Governance and Third-Party Risk Management functions to evaluate control implications arising from cloud technologies, robotic process automation, artificial intelligence, and other emerging technologies.

5. MAR and Statutory Reporting Execution

  • Execute key components of the company’s MAR program and maintain statutory ICFR documentation.
  • Operate MAR as an integrated extension of SOX by leveraging the same control inventory, walkthroughs, and evidence within the GRC platform, while coordinating statutory-specific risk and control assessments where requirements differ from SOX.
  • Maintain complete and accurate lineage within the GRC platform from financial statement account and assertion to risk, control, owner, system or report, evidence, deficiency, and remediation activity.
  • Coordinate quarterly and annual management certification activities, including control owner readiness, evidence completeness, deficiency status, disclosure considerations, and preparation of supporting materials for Director review.
  • Prepare and maintain documentation supporting Management’s Report of Internal Control over Financial Reporting.
  • Conduct SOX impact assessments for changes arising from NAIC and DOI guidance and recommend program enhancements or control framework adjustments, as appropriate.

6. Deficiency Management and Remediation

  • Lead and coordinate deficiency intake, documentation, root-cause analysis, remediation tracking, and retest-readiness activities. Prepare severity, aggregation, disposition, reporting, and stakeholder-communication considerations for Director review and approval, in coordination with Internal Audit and relevant control owners.
  • Partner and constructively challenge control owners to develop outcome-based remediation plans, monitor milestones, and confirm management readiness for retest by Internal Audit.

7. Audit Coordination and Stakeholder Management

  • Coordinate day-to-day interactions with Internal Audit and External Audit, including walkthrough scheduling, evidence requests, status follow-ups, and resolution of execution-level questions; escalate judgmental, strategic, or risk-significant matters to the Director, SOX PMO.
  • Manage day-to-day stakeholder engagement across Finance, Technology, Compliance, Risk, and business operations to drive timely execution of SOX deliverables.
  • Present observations, recommendations, and program updates to management and leadership forums.

8. Continuous Improvement and Innovation

  • Serve as a thought leader and trusted advisor on SOX technical matters, including PCAOB and SEC expectations.
  • Leverage Artificial Intelligence and emerging technologies to lead execution of approved control optimization, automation, analytics, and continuous monitoring initiatives, including identifying candidate controls, coordinating with stakeholders, documenting changes, and implementation readiness.
  • Monitor business, process, technology, organizational, and system changes to identify potential SOX impacts and prepare impact assessments for Director review.
  • Further the culture of candor, ownership, and continuous improvement aligned with the Controller’s values.

Qualifications

Required

  • 8+ years of progressive experience in SOX program management, Internal Audit, or a related compliance function in a public company or large complex organization.
  • Bachelor’s degree in Accounting, Finance, Information Systems, Business Analytics, or related field.
  • Strong knowledge of SOX Sections 302 and 404, COSO Internal Control Framework, PCAOB AS 2201, and SEC interpretive guidance on ICFR.
  • Demonstrated expertise with scoping, walkthroughs, risk assessments, issue remediation, maintaining controls, ITGCs, and automated controls.
  • Experience with artificial intelligence, SDLC, Agile, Lean Six Sigma, continuous improvement, data analytics, automation, or technology-enabled control transformation.
  • Proven ability to collaborate with and influence senior stakeholders, drive cross-functional initiatives independently, and escalate risks or decision points effectively.
  • Ability to operate independently with limited supervision, manage competing priorities, and consistently deliver high-quality work within established timelines.
  • Excellent written and verbal communication, analytical, advanced Excel, project management, and documentation skills.

Strongly Preferred

  • Professional certification such as CPA, CIA, CISA, CFE, CERP, or CISM.
  • Experience with Agile, Lean Six Sigma, data analytics, visualization tools (e.g., Power BI, Tableau), and SQL.
  • Property & Casualty insurance industry experience.
  • Experience supporting statutory financial reporting and MAR compliance controls.
  • Prior experience in consulting, Big Four or large public accounting firm.
  • Experience with AuditBoard/SOXHUB or comparable GRC platforms such as Workiva, Archer, or ServiceNow GRC.
  • Experience leading control automation, controls analytics, and emerging technology risk initiatives.
  • Familiarity with NAIC, NYDFS, and state DOI expectations as they relate to internal controls and corporate governance disclosures (e.g., CGAD).


 

Annual Salary

$146,575.00 - $229,600.00

The above annual salary range is a general guideline. Multiple factors are taken into consideration to arrive at the final hourly rate/ annual salary to be offered to the selected candidate. Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate’s work experience, education and training, the work location as well as market and business considerations.


 

At this time, GEICO will not sponsor a new applicant for employment authorization for this position.

About Geico

GEICO (Government Employees Insurance Company) is an American auto insurance company with headquarters in Chevy Chase, Maryland. It is the second largest auto insurer in the United States, after State Farm. GEICO is a wholly owned subsidiary of Berkshire Hathaway that provides coverage for more than 24 million motor vehicles owned by more than 15 million policy holders as of 2017. GEICO writes private passenger automobile insurance in all 50 U.S. states and the District of Columbia. The insurance agency sells policies through local agents, called GEICO Field Representatives, and over the phone directly to the consumer, and through their website.
Learn more about Geico
Size
40,000 employees
Industry
Founded
1936

Similar Jobs

More Jobs at Geico

More Finance & Insurance Jobs

Find similar Principal, SOX and MAR jobs: