Sr. Staff IT SOX & Risk Management Analyst

Illumina

Illumina

IT
San Diego, CA, USA
Posted on Nov 7, 2024
What if the work you did every day could impact the lives of people you know? Or all of humanity?

At Illumina, we are expanding access to genomic technology to realize health equity for billions of people around the world. Our efforts enable life-changing discoveries that are transforming human health through the early detection and diagnosis of diseases and new treatment options for patients.

Working at Illumina means being part of something bigger than yourself. Every person, in every role, has the opportunity to make a difference. Surrounded by extraordinary people, inspiring leaders, and world changing projects, you will do more and become more than you ever thought possible.

Position Summary

The Global Information Services (GIS) Sr. Staff IT SOX & Risk Management Analyst supports Illumina’s GIS Compliance and Risk Management department in executing GIS processes and regulatory compliance practices to cost-effectively meet strategic, operational, and legal/regulatory goals. The role provides assurance as to the effectiveness of internal controls within all enterprise systems (Applications, databases and operating systems) which qualify for SOX inclusion. In addition to applications, knowledge and experience on tools and interfaces supporting business areas tied to SOX are required. General responsibilities include assessing risk, designing and maintaining controls, evaluation of controls, recommendations for improvements, monitoring, collaboration with both internal and external auditors. Additionally, this position will require knowledge in risk management as it pertains to NIST security framework. Position will partner with controls owners to ensure the company is progressing controls from foundational to fully automated. Position requires frequent interaction with management, process and control owners with on time deliverables to ensure SOX program is compliant. The Sr. Staff IT SOX & Risk Management Analyst manages, coordinates, and performs activities that will increase operational maturity and regulatory compliance – all with the spirit of innovation and efficiency. This position interacts with all tiers of staff and management and must possess quality, regulatory and IT knowledge

Responsibilities

  • Responsible for independently representing GIS SOX compliance activities during internal and external Audits.
  • Responsible for managing IT SOX testing, working with stakeholders, including but not limited to business owners, internal and external audit.
  • Responsible for building and maturing IT Security Risk Management process
  • Responsible for maintaining and reporting control effectiveness mapped to security risks
  • Responsible for engaging cross functional leadership team on security risks and drive decisions to improve security risk posture
  • Build and maintain security risk management governance process
  • Address IT control deficiencies, coordinate with business to remediate identified exceptions.
  • Perform reviews, attestations and recertifications of SOX governed applications, including but not limited to provisioning, de-provisioning, user maintenance on a weekly, monthly, and quarterly basis.
  • Coordinate with functional counterparts to gather needed evidence for audits.
  • Responsible for leading overall IT SOX Compliance activities in accordance with the global process and procedures
  • Responsible for guiding IT project teams on SOX requirements analysis, risk assessment, and testing activities.
  • Independently manage SOX compliance related activities with respect to IT changes in accordance with GIS Change Management process.

Requirements

  • Minimum of 8 years of experience performing SOX compliance, risk management and/or operational/IT audits with internal and external auditors.
  • Experience with Sarbanes-Oxley (SOX) compliance and knowledge of legal, regulatory, and life-sciences industry requirements.
  • Knowledge of SAP ERP, Salesforce, and related application access provisioning, de-provisioning, role administration, and licensing controls.
  • Experience with delivery of audit evidence to support logical security access controls.
  • Experience with ServiceNow task and change management workflows.
  • Ability to lead risk-based strategies and provide optimized SOX compliance and risk management approach to mature security posture.
  • Ability to multitask and manage multiple IT projects needs with respect to SOX applicability, demonstrate leadership in fast-paced project implementations with excellent customer service and communication skills
  • Ability to lead process improvement initiatives, navigate ambiguity and demonstrate high collaboration skills
  • Ability to evaluate new technologies to determine SOX impacts and provide executable strategies to meet requirements
  • Ability to work with digital tools and systems such as ValGenesis and SNOW
  • Understanding of medical device regulations applicable to IT systems (FDA, SOX, HIPAA and GAMP).
  • Experience with software development lifecycle activities, methodologies, testing and validation.
  • Strong communication skills to persuade, direct and advise stakeholders on regulatory compliance processes.

Preferred Experience/Education

  • Typically requires a minimum of 8 years of related experience with a Bachelor’s degree in Technology, Science, Business or related field; or 6 years and a Master’s degree; or a PhD with 3 years experience; or equivalent experience.
  • Experience in Medical Devices, Pharmaceutical and/or Biotech Industries desired.

The estimated base salary range for the Sr. Staff IT SOX & Risk Management Analyst role based in the United States of America is: $138,800 - $208,200. Should the level or location of the role change during the hiring process, the applicable base pay range may be updated accordingly. Compensation decisions are dependent on several factors including, but not limited to, an individual’s qualifications, location where the role is to be performed, internal equity, and alignment with market data. Additionally, all employees are eligible for one of our variable cash programs (bonus or commission) and eligible roles may receive equity as part of the compensation package. We offer a wide range of benefits as innovative as our work, including access to genomics sequencing, family planning, health/dental/vision, retirement benefits, and paid time off.


At Illumina, we strive to foster a diverse and inclusive workplace by cultivating an environment in which everyone contributes to our mission. Built on a strong foundation, Illumina has always been rooted in openness, collaboration, and seeking alternative views and perspectives to propel innovation in genomics. We are proud to confirm a zero-net gap in pay, regardless of gender, ethnicity, or race. We also have several Employee Resource Groups (ERG) that deliver career development experiences, increase cultural awareness, and demonstrate our collective commitment to diversity and inclusion in the communities we live and work. We are proud to be an equal opportunity employer committed to providing employment opportunity regardless of sex, race, creed, color, gender, religion, marital status, domestic partner status, age, national origin or ancestry, physical or mental disability, medical condition, sexual orientation, pregnancy, military or veteran status, citizenship status, and genetic information. Illumina conducts background checks on applicants for whom a conditional offer of employment has been made. Qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable local, state, and federal laws. Background check results may potentially result in the withdrawal of a conditional offer of employment. The background check process and any decisions made as a result shall be made in accordance with all applicable local, state, and federal laws. If you require accommodation to complete the application or interview process, please contact accommodations@illumina.com. To learn more, visit: https://www.dol.gov/ofccp/regs/compliance/posters/pdf/eeopost.pdf. The position will be posted until a final candidate is selected or the requisition has a sufficient number of qualified applicants. This role is not eligible for visa sponsorship.