Jobs and Careers
NA

Principal ICFR Analyst

Navy Federal Credit Union
United Statesfull_timeVerifiedPosted 1 Jul 2025

About the role

To provide internal control guidance, evaluate control effectiveness, and recommend improvements to control-related t practices. Research and establish new practices to ensure credit union control alignment with Section 404 of the Sarbanes Oxley Act (SOX). Work closely with key business partners to understand processes, financial statement risks, and key financial controls to reduce the risk of financial misstatement. Collaborate with business units to mitigate risk by virtue of new control-centric processes and automation. Responsible for gathering data, creating reports, documenting and assessing Internal Control over Financial Reporting (ICFR), and producing evidence of control operational and design effectiveness for facilitate the delivery of auditable evidence to internal and external auditors. Lead complex/unusual tasks of considerable impact that require advances analysis.

  • Lead multi-disciplinary control initiatives to evaluate controls and ultimately transform any control gaps into mature control environments
  • Evaluate the operational performance of existing controls and devise remediation strategies that align control performance with the appropriate risk mitigation methodology
  • Gather and review existing policies, process narratives, and process models to develop insight into the current state of business processes
  • Partner with external and internal auditors establish audit scope, evidence, priorities and testing procedures that will serve as the foundation for the subsequent audit execution strategy
  • Design, develop, and implement Key Control Matrices (KCMs) that summarizes a broad range of business processes into a control-centric and executive-ready audit deliverable
  • Creates and recommends remediation plans for existing ICFR related Information Technology General Computer (ITGC) controls to address control gaps in design effectiveness
  • Validate and update SOX documentation (e.g., Business Process Modeling Notation [BPMN] modes, process narratives, and KCMs) as needed to ensure accuracy and completeness
  • Identify industry best practices associated with risk management and develop subordinate qualitative and quantitative methodologies needed to address those risks using effective controls
  • Produce detailed timelines and milestones for control-related project the enables external tracking and performance appraisal
  • Review results from control and substantive testing to facilitate the remediation of control gaps and escalate possible critical issues to senior management
  • Develop and maintain strategic plans that enable IRC to evaluate new risk and/or control-based technologies likely to have a significant future impact on team activity
  • Lead project teams that resolve highly technical and complex preventative, detective, or corrective control problems
  • Serve as resource for the resolution of complex and/or unique problems Lead
  • Lead, guide and mentor junior staff
  • Ensure preventative, detective, and corrective controls are properly identified and aligned with business priorities such that new controls have an insignificant negative impact on the successful realization of business objectives
  • Solve control-related business problems by defining the problem, interviewing stakeholders, identifying and evaluating alternatives, and presenting findings
  • Identify business areas that may benefit from SOX 404 or industry best practices as applicable
  • Perform other related duties as assigned
  • Significant experience that commensurate with what SOX 407 describes as "expert": Advanced knowledge of SOX including GAAP principles, financial statement preparation, and internal accounting controls
  • Significant experience with General Ledger (GL) technology including but not limited to data integration, accounting rules engines, and financial data hubs/warehouses/marts
  • Significant experience re-designing processes to be consistent with SOX 404 guidance and partnering with business unit personnel to complete the transformation
  • Significant experience with extracting and documenting information technology application control/process information (e.g., access controls lists, change controls, segregation of duties, etc.)
  • Significant experience assessing the design an operational effectiveness of user control considerations: such as SSAE 16/18 SOC 1 Type II reports (experience creating attestations for service organization is preferred) and SSAE 16/18 SOC 2 Type II reports
  • Extensive experience in problem resolution including determining root cause, scope and scale of issues
  • Significant in leading large projects/initiatives which have business risk and impact
  • Extensive experience in managing multiple priorities independently and/or in a team environment to achieve goals
  • Experience in

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Navy Federal Credit Union

View company profile →