Head of It Sox

Anthropic Anthropic · AI Frontier · San Francisco, CA · Finance

This role leads the IT SOX compliance program, focusing on IT General Controls (ITGCs), application controls, and risk assessments. It involves cross-functional collaboration with Engineering, Security, IT, DevOps, and Finance to ensure SOX 404 compliance in a rapidly scaling, technology-driven environment. The role aims to build and scale IT SOX controls, leveraging AI and automation to enhance efficiency and compliance, and will manage external auditors. The position is critical for strengthening internal control maturity for pre-IPO and public company readiness.

What you'd actually do

  1. Lead and manage the organization's end-to-end IT SOX compliance program
  2. Own SOX IT planning, scoping, testing, remediation, and reporting activities
  3. Build scalable, automated, and sustainable controls to support growth through pre-IPO and post-IPO readiness
  4. Pioneer the use of AI and automation technologies to enhance control effectiveness, continuous monitoring, and risk detection
  5. Design, implement, and monitor IT General Controls (ITGCs) across critical systems

Skills

Required

  • Hands-on IT audit and SOX compliance experience
  • Establish or scale SOX IT compliance programs
  • Deep understanding of ITGCs, application controls, and risk assessments
  • Strong project management, analytical, and communication skills

Nice to have

  • 10+ years of hands-on IT audit and SOX compliance experience
  • Experience with Workday, Salesforce, NetSuite, GitHub, or other enterprise business systems
  • CISA, CIA, CPA, or similar certification
  • Experience supporting rapid company growth and scaling compliance programs
  • Interest in or experience applying AI/ML technologies to audit, compliance, or risk management processes
  • Understanding of financial data security and compliance requirements
  • Experience working at a high-growth AI or technology company
  • Familiarity with auditing modern software development environments

What the JD emphasized

  • SOX 404 compliance
  • ITGCs
  • application controls
  • risk assessments
  • scalable controls
  • AI and automation technologies
  • continuous monitoring
  • risk detection
  • IT automated controls (ITACs)
  • Systems Development Life Cycle (SDLC) controls
  • SEC cybersecurity disclosure requirements
  • cyber risks
  • external auditors
  • IT SOX matters
  • public company compliance
  • pre-IPO readiness