Amazon logo

Risk and Control Manager - IT SOX, GFRC

Amazon

Nashville, TNJob$109–155K/yrPosted 2mo ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
$109–155K/yr
Location
Nashville, TN
Work Authorization
Not specified

Requirements

Credentials this posting asks for.

Bachelor's degree

Job overview

Amazon is hiring a Risk and Control Manager - IT SOX, GFRC. The Risk and Control Manager will drive SOX compliance within a fast-paced, dynamic, and tech-forward environment. This role involves leading the IT SOX program, overseeing internal controls over financial reporting, and contributing to process improvements. The manager will build, design, and consult with control owners across the enterprise, requiring deep understanding of internal controls for complex, high-growth organizations.

Key focus areas include Execute IT SOX controls strategies, maintaining and improving program policies and procedures, Contribute to deep dives on IT process areas to define risks and controls, and Drive continuous improvement of the IT SOX program through risk assessment updates.

Successful candidates bring 8+ Years Similar Position In Large Public Companies, 8+ Years Similar Position Within Advisory Practice Of Big 4 Public Accounting Firm Serving Fortune 500 Clients, and 5+ Years Compliance, Audit Or Risk Management Experience. Important skills include SOX Compliance, GFRC, Global Risk-Based Internal Control Environment Design, IT SOX Program Management, IT SOX Controls Strategies, and IT Process Areas Deep Dives. Preferred (not required): COSO 2013 Framework, SEC/PCAOB Regulations, System Implementation, and SDLC Controls.

Skills & qualifications

RequiredNice to have

Skills

SOX ComplianceGFRCCOSO 2013 FrameworkSEC/PCAOB RegulationsGlobal Risk-Based Internal Control Environment DesignIT SOX Program ManagementIT SOX Controls StrategiesIT Process Areas Deep DivesFinancial Reporting Risk AddressingRisk Assessment UpdatesMethodology EnhancementsProcess Optimization302 Sub-Certification ProcessControl Deficiencies EvaluationRemediation Efforts MonitoringITGC Control DesignITGC Control ImplementationSystem ImplementationSystem MigrationSDLC ControlsControl Implications EvaluationTechnology TransformationsPlatform ConsolidationsNew System LaunchesITGC Requirements EmbeddingIAMChange ManagementIT Operations ControlsControl Solutions ConsultingAuditor Inquiries ManagementExternal Audit Teams Relationship ManagementIT General ControlsIT SOX ScopingIT SOX Risk AssessmentIT SOX Control DesignIT SOX TestingIT SOX RemediationERP SystemsDatabasesIT InfrastructureGRC PlatformsAudit Management ToolsCommunication

Qualifications

8+ Years Similar Position in Large Public Companies8+ Years Similar Position Within Advisory Practice of Big 4 Public Accounting Firm Serving Fortune 500 Clients5+ Years Compliance, Audit or Risk Management ExperienceBachelor's Degree or EquivalentMaster's Degree or Equivalent

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
401(k) Match
Paid Time Off
Parental Leave

Full job description

Description

Are you excited about driving SOX compliance in a fast paced, dynamic, tech-forward environment? Come join our Global Financial Risk and Controls (GFRC) controls team to lead the IT SOX program.

GFRC oversees internal controls over financial reporting, subsidiary compliance, internal controls readiness, process improvements, and other enterprise compliance activities. We are a subject matter expertise team that builds, designs, and consults with control owners across the enterprise. This role will require a deep understanding and experience with all aspects of internal controls including financial information technology systems for a complex, high-growth stage, multi-disciplinary organization.

We are currently looking for experienced candidates who have held similar positions in large public companies or who have held a similar position within the advisory practice of a Big 4 public accounting firm serving Fortune 500 clients for +8 years. Requirements for this position also include a deep knowledge the COSO 2013 framework and SEC/PCAOB regulations, as well as the demonstrated ability to design and monitor an effective global risk-based internal control environment. Additionally, demonstrated experience in working collaboratively to accomplish challenges will be expected as this is an ongoing requirement for this position.

Key job responsibilities

IT SOX Program Management

  • Executing on IT SOX controls strategies, including maintaining and improving program policies and procedures

  • Contributing to deep dives on IT process areas to define the set of risks and controls in addressing financial reporting risk

  • Driving continuous improvement of the IT SOX program through risk assessment updates, methodology enhancements, and process optimization

  • Supporting the quarterly 302 sub-certification process and related reporting

  • Assisting in the evaluation of identified control deficiencies and monitoring of remediation efforts

Company-Wide Initiatives

  • Supporting company-wide initiatives that impact ITGC control design and implementation

  • Assisting with system implementation and migration and respective SDLC controls

  • Evaluating control implications for enterprise-wide technology transformations, platform consolidations, and new system launches

  • Partnering with cross-functional teams to ensure ITGC requirements are embedded into large-scale organizational programs

IT SOX Control Consultation (Design & Implementation)

  • Driving control design and implementation with engineering, business, and accounting teams

  • Providing ongoing support to process owners/control owners and cross-functional teams to ensure controls are designed and implemented effectively

  • Advising engineering teams on ITGC requirements for access management, change management, and IT operations controls

  • Consulting on control solutions that balance compliance requirements with operational efficiency and scalability

External Auditor Management

  • Managing auditor inquiries and facilitating timely resolution of identified findings

  • Maintaining ongoing relationships with external audit teams to proactively address emerging IT control concerns

About the team

GFRC team's key purpose is to preserve Amazon's financial reputation by promoting strong controllership that supports internal controls over financial reporting (ICFR) designed to provide reasonable assurance that Amazon's consolidated and statutory financial statements are complete and accurate. We partner closely with our global customers to identify and mitigate key financial reporting risks to achieve the company's control objectives. We do this by maintaining the overall ICFR framework in the GRC platform and supporting the teams responsible for designing, documenting, executing, and assessing their processes, systems, and controls in their respective business environments.

Basic Qualifications

  • 5+ years of compliance, audit or risk management experience

  • Bachelor's degree or equivalent

Preferred Qualifications

  • Master's degree or equivalent

  • Deep knowledge of IT general controls (ITGCs), including access management, change management, and IT operations

  • Experience with IT SOX scoping, risk assessment, control design, testing, and remediation

  • Understanding of the COSO 2013 framework and SEC/PCAOB regulations as they relate to IT controls

  • Familiarity with ERP systems, databases, and IT infrastructure relevant to financial reporting

  • Experience working with GRC platforms and audit management tools

  • Strong understanding of SDLC controls and system implementation lifecycle

  • Excellent written and verbal communication skills

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits .

USA, CA, Culver City - 121,200.00 - 163,900.00 USD annually

USA, MA, Boston - 121,200.00 - 163,900.00 USD annually

USA, OR, Portland - 121,200.00 - 163,900.00 USD annually

USA, TN, Nashville - 109,000.00 - 155,400.00 USD annually

USA, TX, Austin - 121,200.00 - 163,900.00 USD annually

USA, VA, Arlington - 121,200.00 - 163,900.00 USD annually

USA, WA, Seattle - 121,200.00 - 163,900.00 USD annually

You've read the whole posting — now see how you match it.

Risk and Control Manager - IT SOX, GFRC at Amazon | Olive Jobs