Jobs and Careers
NA

Senior Manager, IT Compliance

Natera
UKRemotefull_timeVerifiedPosted 26 Apr 2023
💰 $175,000/yr($143,800/yr$175,000/yr)

About the role

POSITION SUMMARY:

Natera is looking for a Sr Manager, IT Compliance whose main responsibility is ensuring Information Technology is in compliance as a public healthcare company, mainly SOX, SOC 2 and GxP.  The IT Compliance Manager is primarily responsible for managing the design and execution of IT Controls and providing guidance to management and staff on ITGC best practices across all IT infrastructure and application solutions on-prem and cloud. 

This individual will work to ensure IT risk is properly managed, compliance requirements are met and that special projects run smoothly. This individual will quickly gain broad exposure to the operations of the company  and collaborate with the IT, Internal Audit team and other business partners to deliver compliance-focused infrastructure in addition to internal and external audit to support the establishment of a consistent, repeatable, and scalable compliance approach.

 

RESPONSIBILITIES: 

  • Develop/write IT General Control procedures and policies. Provide guidance in implementing ITGC controls. Manage and direct IT around SOX compliance and application controls activities, risk assessment, controls rationalization, and controls optimization processes.

  • Coordinate and provide expert control guidance to management, control owners and others to ensure compliance with Sarbanes-Oxley (SOX) regulations and IT Control standards.

  • Provide technical support in the assessment, design and implementation of ITGC requirements. Review new systems architecture and determine SOX scoping for ITGC and IT application controls.

  • Work cross-functionally on technology implementation projects to provide IT controls expertise and test controls to meet financials and information security requirements.

  • Understand applicable laws and regulations to provide a point of view on audit requirements related to information security and privacy controls.

  • Review control evidence for adherence to accuracy, completeness and precision of control execution for all ITGC. Review test findings, facilitate the remediation of ITGC control gaps, and escalate possible critical issues to senior management

  • Guide the planning, scoping and execution of internal audits primarily in areas associated with technology and technology-related risks including reviews of new and enhanced products and supporting systems, process changes and system implementations.

  • Partner with Internal Audit, Security, Privacy, Engineering, Quality teams to lead and manage and contribute to the technology audits, including supporting the design and development of audit programs.

  • Work with management and users to interpret the significance of audit findings, conclude on findings, make practical recommendations, and verify that remediation plans are implemented.

  • Identifies, quantifies, tracks, and leads mitigation of risks and control exceptions in collaboration with internal and 3rd party Risk program requirements and communicates results to department leadership. Supports and interprets information provided by Internal/External Audit for relevant compliance concerns.

  • Assist in the development of Disaster Recovery and Business Continuity plans. Assist in the testing (planning and execution) of the DR/BCP.

  • Lead training for staff, IT, and business personnel on topics such as SOX documentation, access controls, change management, segregation of duties, and SOC reporting

 

QUALIFICATIONS AND EXPERIENCE: 

 

  • Bachelor’s degree in computer science or related technical field, or equivalent practical experiences in similar industries over 7+ years.

  • Big 4 Public accounting IT audit experience and/or public company experience working with controls required.  CPA, CIA, or CISA designation preferred

  • Big 4 assurance or advisory services experience and/or public company experience working with controls preferred.  CPA, CIA, or CISA designation preferred

  • In-depth knowledge of Sarbanes-Oxley requirements, COSO Framework, PCAOB Auditing Standards and internal controls, and COBIT

  • Experience with Oracle Fusion ERP expertise is essential, Fastpath SOX management software or similar tool desired

  • Strong working knowledge of  NIST, ISO 27001 or ISO 27018, SOC security and privacy principles and provide practical examples of their application across the technical domain.

  • Experience in mapping and applying IT control & security frameworks such as SOC 1, SOC 2, NIST, ISO27001 or related IT compliant posture

  • Strong knowledge and experien

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Natera

View company profile →