SOX and Compliance Analyst

McKesson’s Corporate

Cork

On-site

EUR 56,000 - 94,000

Full time

8 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

McKesson is seeking an experienced IT Governance, Risk & Compliance professional to administer SAP GRC solutions, support SOX ITGC testing, and drive IAM processes with SailPoint. You will collaborate with Information Security to maintain robust controls and deliver executive risk reporting.

You will coordinate audits, manage remediation plans, and identify opportunities to improve governance and automation across the GRC program, ensuring regulatory compliance and strong risk management across

Qualifications

  • 4+ years of experience in IT Governance, Risk & Compliance (GRC), IT Audit, SOX Compliance, Cybersecurity Compliance, Identity & Access Management, or related fields.
  • Bachelor's degree in Information Systems, Information Security, Computer Science, Accounting, Risk Management, Business Administration, or a related field; or equivalent combination of education and experience.
  • Hands‑on experience administering SAP GRC Access Control and/or SAP Process Control.
  • Experience performing SOX controls testing, audit support, evidence collection, and compliance documentation.
  • Experience supporting SailPoint Identity Governance & Administration (IGA) or similar IAM platforms.
  • Knowledge of IT General Controls (ITGC), access governance, Segregation of Duties (SoD), and regulatory compliance frameworks.
  • Experience working with cybersecurity compliance reporting, risk metrics, vulnerability management, or security control monitoring.
  • Strong analytical, communication, documentation, and stakeholder management skills.

Responsibilities

  • Administer and support SAP GRC Access Control and Process Control solutions, including user provisioning, access requests, emergency access management, and Segregation of Duties (SoD) monitoring.
  • Execute SOX ITGC and automated control testing activities, including evidence collection, documentation, validation, and issue tracking.
  • Support SailPoint Identity Governance & Administration (IGA) processes, user access reviews, certification campaigns, role management, and provisioning workflows.
  • Develop and maintain cybersecurity compliance dashboards, risk reports, vulnerability tracking metrics, and executive reporting.
  • Partner with Information Security teams to monitor remediation efforts for identified vulnerabilities and control deficiencies.
  • Coordinate internal and external audit activities, provide audit evidence, and support walkthroughs and testing requests.
  • Track control exceptions and drive remediation plans through closure while ensuring compliance with internal policies and regulatory requirements.
  • Identify opportunities to improve governance, compliance, automation, and operational effectiveness across GRC processes.

Skills

GRC experience
SOX / ITGC
IAM / Access Management
Audit support

Education

Bachelor's degree in Information Systems or related field

Tools

SAP GRC
SailPoint

Job description

McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve – we care. What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow’s health today, we want to hear from you.

What You’ll Do
  • Administer and support SAP GRC Access Control and Process Control solutions, including user provisioning, access requests, emergency access management, and Segregation of Duties (SoD) monitoring.
  • Execute SOX ITGC and automated control testing activities, including evidence collection, documentation, validation, and issue tracking.
  • Support SailPoint Identity Governance & Administration (IGA) processes, user access reviews, certification campaigns, role management, and provisioning workflows.
  • Develop and maintain cybersecurity compliance dashboards, risk reports, vulnerability tracking metrics, and executive reporting.
  • Partner with Information Security teams to monitor remediation efforts for identified vulnerabilities and control deficiencies.
  • Coordinate internal and external audit activities, provide audit evidence, and support walkthroughs and testing requests.
  • Track control exceptions and drive remediation plans through closure while ensuring compliance with internal policies and regulatory requirements.
  • Identify opportunities to improve governance, compliance, automation, and operational effectiveness across GRC processes.
Basic Requirements
  • 4+ years of experience in IT Governance, Risk & Compliance (GRC), IT Audit, SOX Compliance, Cybersecurity Compliance, Identity & Access Management, or related fields.
  • Bachelor's degree in Information Systems, Information Security, Computer Science, Accounting, Risk Management, Business Administration, or a related field; or equivalent combination of education and experience.
  • Hands‑on experience administering SAP GRC Access Control and/or SAP Process Control.
  • Experience performing SOX controls testing, audit support, evidence collection, and compliance documentation.
  • Experience supporting SailPoint Identity Governance & Administration (IGA) or similar IAM platforms.
  • Knowledge of IT General Controls (ITGC), access governance, Segregation of Duties (SoD), and regulatory compliance frameworks.
  • Experience working with cybersecurity compliance reporting, risk metrics, vulnerability management, or security control monitoring.
  • Strong analytical, communication, documentation, and stakeholder management skills.
Preferred Skills/Experience
  • Experience with SAP S/4HANA environments and SAP security concepts.
  • Knowledge of NIST, ISO 27001, COBIT, PCI-DSS, HIPAA, or other cybersecurity and compliance frameworks.
  • Experience using Integrated Risk Management (IRM), GRC Automation, or Regulatory Technology (RegTech) platforms.
  • Professional certifications such as CISA, CRISC, CISSP, CGEIT, SAP GRC, Security+, or SailPoint certifications.
  • Experience developing compliance dashboards and executive-level reporting.
  • Knowledge of vulnerability management tools and remediation tracking processes.
  • Experience supporting large-scale audit programs across complex enterprise environments.
  • Proven track record of driving process improvements and compliance automation initiatives.
  • Technical experience across SAP Basis, HANA/Oracle/MSSQL database administration, SAP BusinessObjects, Linux administration, and Windows administration.
  • Platform experience across SAP RISE, SAP Business Technology Platform (BTP), and other SAP SaaS deployments.
  • Experience with hyperscaler platforms, including Microsoft Azure and Google Cloud Platform (GCP).
  • Advanced Identity and Access Management experience, including SSO/MFA and authentication protocols or technologies such as OpenID, SAML, Kerberos, SPNego, LDAP, Active Directory, Okta, and SAP Identity Provider.
  • Privileged Access Management experience across OS, database, and application layers in SAP and non‑SAP environments, including CyberArk.
  • Expertise in Identity Governance and Administration (IGA), SAP GRC, and SailPoint.
  • Experience with SOX/SOC controls across OS, database, and application layers in SAP and non‑SAP environments.
Benefits & Total Rewards
  • We care about the well‑being of the patients and communities we serve, and that starts with caring for our people.
  • Our Total Rewards package includes comprehensive benefits to support physical, mental, and financial well‑being. Our Total Rewards offerings serve the different needs of our diverse employee population and ensure they are the healthiest versions of themselves.
  • Competitive compensation package at McKesson. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets.
  • Base Pay Range for this position €56,300 - €93,800.
  • Includes: in addition to base pay, other compensation such as an annual bonus or long‑term incentive opportunities may be offered.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOX and Compliance Analyst
SOX and Compliance Analyst

McKesson • Cork

Hybrid
EUR 56,000 - 94,000
Cybersecurity GRC Analyst, SAP Platform
Cybersecurity GRC Analyst, SAP Platform

McKesson’s Corporate • Cork

On-site
EUR 56,000 - 94,000
Cybersecurity GRC Analyst, SAP Platform
Cybersecurity GRC Analyst, SAP Platform

McKesson • Cork

Hybrid
EUR 56,000 - 94,000
Sr IAM Engineer – SAP Security (Integration)
Sr IAM Engineer – SAP Security (Integration)

McKesson • Cork

On-site
EUR 66,000 - 110,000
SOX & GRC Compliance Analyst (SAP & IAM)
SOX & GRC Compliance Analyst (SAP & IAM)

McKesson • Cork

Hybrid
EUR 56,000 - 94,000
Strategic SOX & GRC Compliance Analyst
Strategic SOX & GRC Compliance Analyst

McKesson’s Corporate • Cork

On-site
EUR 56,000 - 94,000
Sr IAM Engineer - SAP Security (Integration)
Sr IAM Engineer - SAP Security (Integration)

McKesson Corporation • Ireland

On-site
EUR 66,000 - 110,000
Comprehensive benefits package
Performance-based bonuses
Long-term incentive opportunities
Sr. IAM Engineer – SAP Security HANA
Sr. IAM Engineer – SAP Security HANA

McKesson • Cork

On-site
EUR 66,000 - 110,000
Comprehensive benefits
Competitive compensation package
SAP GRC Analyst: SOX & Access Control on SAP Platform
SAP GRC Analyst: SOX & Access Control on SAP Platform

McKesson’s Corporate • Cork

On-site
EUR 56,000 - 94,000
SAP GRC Analyst — SoD & SOX Compliance
SAP GRC Analyst — SoD & SOX Compliance

McKesson • Cork

Hybrid
EUR 56,000 - 94,000