Technology Compliance Analyst

Unity Unity · Enterprise · Bangalore, India · Legal

This role is for a Technology Compliance Analyst at Unity, focusing on IT General Controls (ITGC) and global standards like SOX, SOC, and ISO 27001. The analyst will manage the end-to-end lifecycle of ITGC, including evidence collection, quality assurance, external audit walkthroughs, and control testing automation, utilizing tools like AuditBoard within a cloud environment (GCP, AWS).

What you'd actually do

  1. Own the day-to-day execution and documentation of ITGC, ITAC, and IPE controls, ensuring Unity maintains a robust and audit-ready control environment.
  2. Act as a key liaison for external auditors by managing PBC evidence collection, validating scope, and coordinating technical walkthroughs with control owners.
  3. Perform rigorous Quality Assurance (QA) reviews on control performance and conduct Segregation of Duties (SOD) analyses to identify and mitigate critical access conflicts.
  4. Identify and implement automation opportunities within the control testing lifecycle and manage compliance health through AuditBoard.
  5. Partner with cross-functional teams across the US and Europe to remediate deficiencies and ensure compliance across cloud-native environments (AWS/GCP).

Skills

Required

  • Testing and executing IT General Controls (ITGC) under frameworks such as SOX, SOC, PCI, or ISO 27001.
  • Foundational knowledge of cloud and development environments, specifically evidence preparation for AWS, GCP, Terraform, and GitHub.
  • Hands-on experience managing audit workflows, evidence repositories, and control performance tracking within AuditBoard.
  • Proficiency in conducting Segregation of Duties (SOD) analysis and identifying access conflicts across diverse systems.
  • Ability to facilitate technical walkthroughs with external auditors and manage the full Provided by Client (PBC) evidence lifecycle.

Nice to have

  • Bachelor's or Master's degree in Computer Science or a related field (e.g., BE, MCA, MSC).
  • Relevant experience in SOX testing, SOC, PCI, ISO 27001 or IT audit/compliance.
  • CISA or any relevant certification

What the JD emphasized

  • SOX
  • SOC
  • ISO 27001
  • ITGC
  • AuditBoard
  • SOD