Jobs and Careers
FE

Principal Information Security Engineer - IT SOX Compliance (Remote)

Ferguson
UKRemotefull_timeVerifiedPosted 31 May 2024

About the role

Job Posting:

Ferguson is North America’s leading value-added distributor across residential, non-residential, new construction and repair, maintenance, and improvement (RMI) end markets. Spanning 34,000 suppliers and more than one million customers, we deliver local expertise, value-added solutions, and the industry’s most extensive portfolio of products. From infrastructure, plumbing, and appliances, to HVAC, fire protection, fabrication, and more, we make our customers’ complex projects simple, successful, and sustainable.

We have an exciting opportunity for a remote Principal level, IT SOX Compliance Engineer to join the Information Security organization, within the Ferguson IT organization. The Principal of SOX Compliance leads and supports the program, policies, and practices to ensure the organization is aligned with the Sarbanes-Oxley Act. The incumbent performs comprehensive reviews of IT processes to ensure appropriate controls and procedures are designed and operating effectively. The role is key to ensuring the execution of the IT SOX Program and providing recommendations to Management (control owners and performers) for enhancing processes and controls and improving documentation to meet SOX requirements and to drive consistent execution of the IT SOX controls. As part of this role, this position is responsible for coordinating with internal and external audit, coordinating responses and supporting remediation of identified SOX issues, and IT General Controls design and execution coordination.

**This role is approved to be 100% remote within the United States.**

    Duties and Responsibilities:

    • Development, implementation, and execution of the Company’s IT SOX compliance program while ensuring compliance with the Sarbanes-Oxley Act and deadlines. This may include identifying, designing, and validating key controls, developing operational procedures, documenting testing, and reporting results to management, internal and external audit.
    • Lead and support the rationalization of internal control design, activities, maintain key controls inventory, and ensure SOX documentation reflects a high level of quality.
    • In partnership with Internal Audit, coordinate enterprise execution of SOX activities, including support for planning and coordinating walkthroughs, testing of IT general controls, application controls, and key system generated reports.
    • Performs proper risk and impact analysis, evaluate, and drive remediation (including working with management on remediation solutions) of identified control deficiencies and findings from SOX, Internal and External audit in a timely manner.
    • Support, guide and train the guidance of IT SOX compliance policies and procedures to advise a matrixed team of compliance coordination resources, control performers, and control owners.
    • Review merger and acquisitions and system implementations to assess risks and potential impact on key SOX internal controls and compliance requirements.
    • Maintains awareness of all applicable laws and regulations and the corresponding levels of IT SOX compliance, communicates to relevant collaborators and use as basis for input to IT policies.
    • Aide in aligning IT policies, standards, and procedures in response to SOX compliance requirements.
    • Lead and support services and relationships with external testers and compliance consultants, as appropriate.
    • Support senior Finance leadership, Internal Audit, external auditor and external testing consultants (as appropriate) to help coordinate planning and scoping of SOX audit processes.
    • Oversee process owners, SOX control owners, SOX control performers, and compliance coordinators to ensure controls are well defined and in compliance with applicable laws and regulations.
    • Collaborates with IT leaders and managers at all levels to identify areas where SOX control enhancements and/or documentation improvements are needed.
    • Participate and provide input to SOX audit engagements and coordinates all Technology SOX responses to internal and external audits.
    • Researches and assesses SOX deficiencies identified and works with Management to identify appropriate solutions. Follows-up on remediation activities to verify appropriate resolution.
    • Participates and provides input to Internal Audit’s annual technology audit plan. Participates and assists with coordination of Internal Audit’s activities within the IT domain.
    • Coordinates preparation of metrics and dashboards providing information on SOX compliance program progress, including improvements to resource knowledge maturity.
    • Assists in preparation of executive presentations and supports Sr. Director, participating in Steering Committee, Internal / External Audit, and IT Risk Coordination sessions, as appropriate.

    Knowledge, Skills & Abilities

    • R

    Apply for this role

    Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

    Apply Now →Generate Application Kit

    Free account required — sign up in 30s

    Company

    Ferguson

    View company profile →