Sr. Staff IT SOX & Risk Management Analyst
Illumina
Position Summary
The Global Information Services (GIS) Sr. Staff IT SOX & Risk Management Analyst supports Illumina’s GIS Compliance and Risk Management department in executing GIS processes and regulatory compliance practices to cost-effectively meet strategic, operational, and legal/regulatory goals. The role provides assurance as to the effectiveness of internal controls within all enterprise systems (Applications, databases and operating systems) which qualify for SOX inclusion. In addition to applications, knowledge and experience on tools and interfaces supporting business areas tied to SOX are required. General responsibilities include assessing risk, designing and maintaining controls, evaluation of controls, recommendations for improvements, monitoring, collaboration with both internal and external auditors. Additionally, this position will require knowledge in risk management as it pertains to NIST security framework. Position will partner with controls owners to ensure the company is progressing controls from foundational to fully automated. Position requires frequent interaction with management, process and control owners with on time deliverables to ensure SOX program is compliant. The Sr. Staff IT SOX & Risk Management Analyst manages, coordinates, and performs activities that will increase operational maturity and regulatory compliance – all with the spirit of innovation and efficiency. This position interacts with all tiers of staff and management and must possess quality, regulatory and IT knowledge
Responsibilities
- Responsible for independently representing GIS SOX compliance activities during internal and external Audits.
- Responsible for managing IT SOX testing, working with stakeholders, including but not limited to business owners, internal and external audit.
- Responsible for building and maturing IT Security Risk Management process
- Responsible for maintaining and reporting control effectiveness mapped to security risks
- Responsible for engaging cross functional leadership team on security risks and drive decisions to improve security risk posture
- Build and maintain security risk management governance process
- Address IT control deficiencies, coordinate with business to remediate identified exceptions.
- Perform reviews, attestations and recertifications of SOX governed applications, including but not limited to provisioning, de-provisioning, user maintenance on a weekly, monthly, and quarterly basis.
- Coordinate with functional counterparts to gather needed evidence for audits.
- Responsible for leading overall IT SOX Compliance activities in accordance with the global process and procedures
- Responsible for guiding IT project teams on SOX requirements analysis, risk assessment, and testing activities.
- Independently manage SOX compliance related activities with respect to IT changes in accordance with GIS Change Management process.
Requirements
- Minimum of 8 years of experience performing SOX compliance, risk management and/or operational/IT audits with internal and external auditors.
- Experience with Sarbanes-Oxley (SOX) compliance and knowledge of legal, regulatory, and life-sciences industry requirements.
- Knowledge of SAP ERP, Salesforce, and related application access provisioning, de-provisioning, role administration, and licensing controls.
- Experience with delivery of audit evidence to support logical security access controls.
- Experience with ServiceNow task and change management workflows.
- Ability to lead risk-based strategies and provide optimized SOX compliance and risk management approach to mature security posture.
- Ability to multitask and manage multiple IT projects needs with respect to SOX applicability, demonstrate leadership in fast-paced project implementations with excellent customer service and communication skills
- Ability to lead process improvement initiatives, navigate ambiguity and demonstrate high collaboration skills
- Ability to evaluate new technologies to determine SOX impacts and provide executable strategies to meet requirements
- Ability to work with digital tools and systems such as ValGenesis and SNOW
- Understanding of medical device regulations applicable to IT systems (FDA, SOX, HIPAA and GAMP).
- Experience with software development lifecycle activities, methodologies, testing and validation.
- Strong communication skills to persuade, direct and advise stakeholders on regulatory compliance processes.
Preferred Experience/Education
- Typically requires a minimum of 8 years of related experience with a Bachelor’s degree in Technology, Science, Business or related field; or 6 years and a Master’s degree; or a PhD with 3 years experience; or equivalent experience.
- Experience in Medical Devices, Pharmaceutical and/or Biotech Industries desired.
At Illumina, we strive to foster a diverse and inclusive workplace by cultivating an environment in which everyone contributes to our mission. Built on a strong foundation, Illumina has always been rooted in openness, collaboration, and seeking alternative views and perspectives to propel innovation in genomics. We are proud to confirm a zero-net gap in pay, regardless of gender, ethnicity, or race. We also have several Employee Resource Groups (ERG) that deliver career development experiences, increase cultural awareness, and demonstrate our collective commitment to diversity and inclusion in the communities we live and work. We are proud to be an equal opportunity employer committed to providing employment opportunity regardless of sex, race, creed, color, gender, religion, marital status, domestic partner status, age, national origin or ancestry, physical or mental disability, medical condition, sexual orientation, pregnancy, military or veteran status, citizenship status, and genetic information. Illumina conducts background checks on applicants for whom a conditional offer of employment has been made. Qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable local, state, and federal laws. Background check results may potentially result in the withdrawal of a conditional offer of employment. The background check process and any decisions made as a result shall be made in accordance with all applicable local, state, and federal laws. If you require accommodation to complete the application or interview process, please contact accommodations@illumina.com. To learn more, visit: https://www.dol.gov/ofccp/regs/compliance/posters/pdf/eeopost.pdf. The position will be posted until a final candidate is selected or the requisition has a sufficient number of qualified applicants. This role is not eligible for visa sponsorship.