Senior Sox Manager – It

Instacart Instacart · Consumer · United States · Remote · Accounting & Finance

Instacart is seeking a Senior SOX Manager – IT to lead IT General Controls (ITGC) and IT Automated Controls (ITAC) compliance activities for their SOX program. This role ensures the IT control environment supports compliance with Section 404 of the Sarbanes-Oxley Act (SOX). The position requires a deep understanding of SOX 404, COSO framework, COBIT principles, IT security, and risk management, with a focus on access management, change management, and disaster recovery. A key aspect is partnering closely with engineering teams to design effective and sustainable controls, bridging the gap between compliance requirements and engineering practices. Experience in a fast-paced technology environment and strong communication skills are essential.

What you'd actually do

  1. Lead and manage the execution of our IT General Controls (ITGC) and IT Automated Controls (ITAC) compliance activities as part of the company's SOX program.
  2. Ensure the company's IT control environment supports an efficient and effective internal control framework to comply with Section 404 of the Sarbanes-Oxley Act (SOX).
  3. Own all IT related controls processes, including defining and optimizing IT controls over financial reporting (ICFR).
  4. Take charge of maintaining compliance while proactively identifying risks and partnering with IT stakeholders to strengthen the control environment.
  5. Work alongside this embedded team — leveraging their systems knowledge and Engineering relationships to design controls that are rigorous, right-sized, and operationally sustainable.

Skills

Required

  • Bachelor's degree in Information Technology, Accounting, or a related field
  • 10+ years of experience in IT audit, SOX compliance, or risk management with a focus on IT controls
  • Demonstrated expertise in identifying, designing, and testing IT controls to support compliance standards
  • Deep knowledge of SOX 404, COSO framework, COBIT principles, IT security, and risk management practices
  • Hands-on experience with IT controls domains including access management, change management, and disaster recovery
  • Proven ability to earn the trust of engineering teams and communicate technical risks and control concepts in plain language
  • Experience working in or alongside high-velocity engineering organizations at a technology company

Nice to have

  • CISA, CISSP, or CPA preferred
  • Advanced degree (MBA, MIS, or equivalent)
  • Experience managing IT SOX efforts for ERP systems such as Oracle, SAP, or Workday
  • Familiarity with cloud-based environments (AWS, Azure, GCP) and related control implications
  • Prior experience in an embedded or liaison role between compliance and engineering functions
  • Strong project management and organizational skills with a results-oriented approach

What the JD emphasized

  • IT General Controls (ITGC)
  • IT Automated Controls (ITAC)
  • SOX
  • Sarbanes-Oxley Act (SOX)
  • ITGC
  • ITAC
  • SOX 404
  • COSO framework
  • COBIT principles
  • IT security
  • risk management practices
  • access management
  • change management
  • disaster recovery
  • earn the trust of engineering teams
  • communicate technical risks and control concepts in plain language
  • high-velocity engineering organizations
  • embedded or liaison role between compliance and engineering functions