SOX & Compliance Manager

Prophecy Technologies

$100K — $130K *
Finance & Insurance
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in Governance, Risk, Compliance (GRC) management.
  • Strong proficiency in internal controls and audit management practices.
  • Demonstrated expertise in cybersecurity compliance and related standards.
  • In-depth knowledge of Sarbanes-Oxley (SOX) and Non-SOX regulatory frameworks.
  • Familiarity with Key compliance frameworks such as ISO 27001, NIST, PCI DSS, SOC, GDPR, and CCPA.

Responsibilities

  • Lead and manage the SOX compliance program, covering all phases from planning to reporting.
  • Conduct annual SOX risk assessments and scoping for internal controls.
  • Coordinate reviews to assess control designs and effectiveness testing.
  • Collaborate with process owners to identify and mend control deficiencies.
  • Ensure timely completion of SOX certifications and regulatory compliance requirements.
  • Monitor and adapt to regulatory changes impacting SOX compliance, suggesting proactive improvements.
  • Lead compliance program development for company policies and various regulatory mandates.

Benefits

  • Opportunity to specialize in Sarbanes-Oxley and NERC CIP compliance.
  • Collaboration with cross-functional teams including IT, cybersecurity, and operations.
  • Leadership role with significant influence over compliance strategies and practices.
  • Engagement in continuous improvement initiatives across organizational processes.
Full Job Description
Role Overview:

The SOX & Compliance Manager will lead and manage the organization's compliance programs, encompassing Sarbanes-Oxley (SOX), Non-SOX regulatory compliance, NERC CIP (North American Electric Reliability Corporation Critical Infrastructure Protection), and other Non-NERC CIP initiatives. This role involves overseeing internal and external audit activities, partnering with various teams including business, IT, cybersecurity, risk management, legal, and operations to ensure regulatory adherence, strengthen internal controls, mitigate risks, and achieve successful audit outcomes. The ideal candidate will possess strong expertise in governance, risk, compliance (GRC), internal controls, audit management, cybersecurity compliance, and various regulatory frameworks.

Key Responsibilities:
  • Lead the organization's SOX compliance program, including planning, execution, monitoring, testing, and reporting.
  • Manage annual SOX risk assessments and control scoping activities.
  • Coordinate control design reviews and operating effectiveness testing.
  • Partner with process owners to identify, document, and remediate control deficiencies.
  • Ensure timely completion of SOX certifications and compliance requirements.
  • Maintain SOX narratives, process flows, risk control matrices (RCMs), and supporting documentation.
  • Monitor regulatory changes affecting SOX compliance and recommend improvements.
  • Develop and maintain compliance programs for company policies, regulatory requirements, industry standards, and operational controls.
  • Conduct compliance assessments and gap analyses across business and technology functions.
  • Support implementation and monitoring of compliance frameworks such as ISO 27001, NIST, PCI DSS, SOC, GDPR, and CCPA.
  • Track remediation activities and ensure closure of compliance findings.
  • Manage NERC CIP compliance activities across applicable business units and critical infrastructure environments.
  • Coordinate CIP evidence collection, documentation management, and compliance reporting.
  • Oversee periodic reviews of CIP standards, policies, procedures, and technical controls.
  • Partner with cybersecurity, IT, and operations teams to ensure compliance with NERC CIP requirements.
  • Support self-certifications, spot checks, compliance monitoring, and regulatory audits.
  • Track and manage mitigation plans and corrective action activities.
  • Oversee compliance initiatives associated with operational technology (OT), cybersecurity, and industry-specific regulatory requirements.
  • Conduct assessments to ensure adherence to corporate and regulatory standards.
  • Manage compliance documentation, evidence repositories, and reporting mechanisms.
  • Facilitate continuous improvement initiatives.

Required Skills:
  • Strong expertise in Governance, Risk, Compliance (GRC).
  • Proficiency in internal controls and audit management.
  • Experience with cybersecurity compliance.
  • Familiarity with regulatory frameworks including Sarbanes-Oxley (SOX), Non-SOX regulations, and NERC CIP.
  • Knowledge of compliance frameworks such as ISO 27001, NIST, PCI DSS, SOC, GDPR, and CCPA.

Similar Jobs

More Jobs at Prophecy Technologies

More Finance & Insurance Jobs

Find similar SOX & Compliance Manager jobs: