It Sox Risk Principal Associate, Sox Advisory Team

Capital One Capital One · Banking · Richmond, VA +1

This role focuses on IT SOX risk and advisory within a financial institution, ensuring data integrity and managing technology risks in the general control environment. Responsibilities include guiding stakeholders through risk management frameworks, advising on data and technology risks, supporting technology transformations, and reporting on control performance. It requires experience in internal controls, data risk management, and IT general controls.

What you'd actually do

  1. Assist in guiding multiple customer stakeholders through our robust risk management framework including scoping, risk assessment, control design, testing, deficiency analysis, reporting and certification.
  2. Assist in advising business process performers, risk offices, internal auditors and accountable executives on emerging data and technology risks and communicate identified risks or issues and recommended remediation actions to these stakeholders.
  3. Support technology and business transformation, including assessing potential control changes that may be required as we embrace cloud capabilities to enhance our financial reporting and risk management practices.
  4. Perform analysis, capture and report control performance metrics and assist in preparing quarterly stakeholder reporting.
  5. Interpret and communicate program and control information to various stakeholders including identified risks or issues and recommended remediation.

Skills

Required

  • Bachelor's Degree or military experience
  • 3 years of experience in Internal Controls, Data Risk Management, Risk Management, Audit or a combination
  • 3 years of experience in identifying and assessing IT general, IT application, data movement and systems implementation controls

Nice to have

  • 4 years of experience in Auditing and Control Evaluation
  • Certified Internal Auditor (CIA) certification or Certified Information Systems Auditor (CISA) certification
  • AWS Certified Cloud Practitioner or AWS Certified Solutions Architect

What the JD emphasized

  • IT general, IT application, data movement and systems implementation controls