Full Job Description
In this role, you will serve as a member of the Technology, Data, and Operations (TD&O) Sarbanes-Oxley (SOX) Governance team, supporting Truist's TD&O business unit in meeting requirements under Sections 404 and 302 of the Sarbanes-Oxley Act of 2002 and the Federal Deposit Insurance Corporation Improvement Act of 1991.
TD&O SOX Governance teammates serve as subject matter experts for SOX IT general controls and act as primary liaisons across TD&O leadership, process and control owners, SOX Program Management (SPM), the Business Execution and Risk Organization (BERO), and internal and external auditors. This role is responsible for coordinating SOX audit-related activities, managing and tracking audit requests, supporting audit readiness, and partnering with TD&O stakeholders to help ensure timely, accurate, and well-supported audit execution. The role also requires openness to learning and responsibly embedding AI-enabled capabilities and identifying automation opportunities to improve the efficiency, consistency, and sustainability of SOX governance processes.
Role expectations and accountabilities (other duties may be assigned as business needs evolve):
• Demonstrate knowledge of SOX IT general controls and coordinate with internal and external auditors to manage audit requests, track deliverables, and support timely, accurate audit execution.
• Partner with TD&O process and control owners, SOX Program Management, BERO, auditors, and other risk partners to support audit readiness, resolve request-related issues, and promote consistent SOX governance routines.
• Apply technology risk, IT control, and TD&O operational knowledge to evaluate SOX-related matters, advise business and technology partners, and identify practical, risk-informed solutions.
• Support documentation of SOX issues, development of remediation plans, and monitoring of remediation activities through timely resolution.
• Identify responsible opportunities to streamline, automate, and enhance SOX governance activities, reporting, audit request management, and related control support processes, including through appropriate use of AI-enabled capabilities.
ESSENTIAL DUTIES AND RESPONSIBILITIES
Following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time.
1. Identifies, assesses, and mitigates technology-related risks to maintain compliance with regulatory requirements and internal policies.
2. Implements and monitors governance processes, controls, and procedures to manage technology risks effectively.
3. Conducts governance analysis, vulnerability assessments, and/or control testing to protect critical technology infrastructure and data.
4. Provides detailed reporting on technology risk posture and compliance status to internal stakeholders.
5. Manages and supports technology governance projects and assignments while collaborating with cross-functional teams to ensure controls are integrated into technology projects and operations.
6. May support audits or remediation activities by preparing documentation and responding to inquiries related to technology governance.
7. Maintains awareness of industry best practices, regulatory changes, and evolving risk landscapes to update governance strategies.
Qualifications
Required Qualifications
The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
1. Bachelor's degree in Information Technology, Information Security, Engineering, or related field.
2. Minimum of 5 years of professional experience in technology governance.
3. Knowledge of regulatory requirements and compliance frameworks.
4. Experience applying governance assessment methodologies and control frameworks.
Preferred Qualifications
1. Master's degree in Accounting, Finance, Information Technology, Information Systems, Cybersecurity, or a related field, or equivalent education and related training.
2. Five or more years of experience performing, overseeing, or managing IT components of SOX audits, including IT general controls, automated controls, key reports, and audit evidence management.
3. Experience working with internal audit, external audit, SOX program management, technology control owners, and risk partners to support audit execution, issue remediation, and control readiness.
4. Strong understanding of technology risk, IT governance, change management, access management, SDLC, cybersecurity, infrastructure, cloud, and data-related control environments.
5. Experience managing audit requests, tracking deliverables, monitoring remediation activities, and communicating status, risks, and escalations to stakeholders and leadership.
6. Proficiency with Microsoft Office and Microsoft 365 collaboration and workflow tools, including Excel, PowerPoint, Word, Teams, SharePoint, and related reporting or automation capabilities.
7. Relevant professional certification, such as CISA, CRISC, CISSP, CISM, CPA, CIA, or similar credential.