Sr. SOX and Compliance Analyst, SAP Applications

McKesson

Cork

Hybrid

EUR 72,000 - 120,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Total Rewards package
Competitive compensation

Job summary

McKesson, a Fortune 10 health care leader, seeks a Sr. SOX and Compliance Analyst, SAP Applications, to strengthen enterprise governance, risk, and compliance.

You will lead SAP GRC modules, perform SOX testing, and work with IAM and auditors to drive continuous improvements across SAP environments. The role requires 7+ years in GRC/SOX, strong SAP GRC/SailPoint experience, and deep ITGC knowledge, with broad cyber risk awareness.

Qualifications

  • 7+ years of experience in GRC, IT Audit, Information Security, SOX or related fields.
  • Bachelor's degree or equivalent experience in a relevant domain.
  • Hands-on experience configuring SAP GRC Access Control and/or SAP Process Control.
  • Experience with SOX controls testing, evidence collection, documentation, and remediation.
  • Experience with IT General Controls (ITGC) testing, monitoring, and reporting.
  • Experience supporting Identity Governance and Administration (IGA) programs such as SailPoint.
  • Knowledge of cybersecurity risk management, vulnerabilities, and security controls.

Responsibilities

  • Lead SAP GRC Access Control and SAP Process Control configuration and optimization.
  • Perform SOX control testing including evidence collection and audit support.
  • Collaborate with Identity & Access Management to enhance SailPoint for SAP environments.
  • Conduct cybersecurity vulnerability assessments and resiliency testing.
  • Monitor ITGCs and coordinate remediation of control deficiencies.
  • Analyze compliance risks and recommend corrective actions for improvements.
  • Develop compliance reports and risk metrics for executives.

Skills

GRC & Compliance
SOX Compliance
IT Audit
Cybersecurity
Stakeholder Mgmt
Data analysis
Communication

Education

Bachelor's degree in Information Systems, Cybersecurity, Accounting, Risk Management, or related field

Tools

SAP GRC
SAP Process Control
SailPoint
ITGC Testing
Active Directory

Job description

McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve - we care.

What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow’s health today, we want to hear from you.

McKesson is seeking a Sr. SOX and Compliance Analyst, SAP Applications to support and advance enterprise governance, risk, and compliance programs. This role partners across Security, Audit, Technology, and Business teams to strengthen internal controls, reduce risk, and maintain compliance with regulatory and organizational requirements.

The ideal candidate brings hands-on expertise with SAP GRC Access Control and Process Control, SOX compliance testing, SailPoint identity governance integration, cybersecurity risk assessments, and IT General Controls (ITGC). This position plays a key role in driving control effectiveness, audit readiness, and continuous compliance improvement across the enterprise.

What You'll Do
  • Lead SAP GRC Access Control and SAP Process Control configuration, administration, and continuous optimization.
  • Execute SOX control testing activities, including evidence collection, documentation, control evaluation, and audit support.
  • Partner with Identity and Access Management teams to integrate and enhance SailPoint governance processes for SAP environments.
  • Conduct cybersecurity vulnerability assessments and resiliency testing to identify, assess, and mitigate technology risks.
  • Monitor IT General Controls (ITGCs) and coordinate remediation activities for identified control deficiencies.
  • Analyze compliance risks, perform root-cause investigations, and recommend corrective actions to improve control effectiveness.
  • Develop compliance reports, risk metrics, and executive-ready presentations that communicate trends, findings, and remediation progress.
  • Collaborate with internal and external auditors, technology teams, and business stakeholders to support regulatory and compliance requirements.
Basic Requirements
  • 7+ years of experience in Governance, Risk & Compliance (GRC), IT Audit, Information Security, SOX Compliance, or related disciplines.
  • Bachelor's degree in Information Systems, Cybersecurity, Accounting, Risk Management, Business Administration, or a related field, or equivalent experience.
  • Hands-on experience administering and configuring SAP GRC Access Control and/or SAP Process Control.
  • Experience performing SOX controls testing, audit evidence collection, documentation, and remediation validation.
  • Experience with IT General Controls (ITGC) testing, monitoring, and compliance reporting.
  • Experience supporting Identity Governance and Administration (IGA) programs, including SailPoint or similar platforms.
  • Knowledge of cybersecurity risk management, vulnerability assessment, and security control frameworks.
  • Strong analytical, problem-solving, communication, and stakeholder management skills.
  • Technical foundation across SAP Basis, HANA, Oracle, MSSQL DBA, Business Objects, Linux administration, and Windows administration.
  • Experience with SAP platform models, including SAP RISE, SAP BTP, and other SAP SaaS deployments.
  • Experience working with hyperscaler platforms, including Microsoft Azure and Google Cloud Platform (GCP).
  • Advanced Identity and Access Management experience, including SSO, MFA, OpenID, SAML, Kerberos, SPNego, LDAP, Active Directory, Okta, and SAP Identity Provider.
  • Privileged Access Management experience across operating system, database, and application layers in SAP and non-SAP environments, including CyberArk.
  • Expertise in Identity Governance and Administration (IGA), SAP GRC, and SailPoint.
  • Experience with SOX and SOC controls across operating system, database, and application layers in SAP and non-SAP environments.
Preferred Skills/Experience
  • Experience in large-scale enterprise SAP environments.
  • Knowledge of SAP authorization concepts, Segregation of Duties (SoD), access risk analysis, and emergency access management.
  • Experience supporting external audits, internal audits, and regulatory examinations.
  • Relevant certifications such as CISA, CRISC, CISSP, CIA, SAP GRC, Security+, or SailPoint certifications.
  • Experience with continuous controls monitoring and risk analytics tools.
  • Familiarity with NIST, COBIT, ISO 27001, COSO, and related governance frameworks.
  • Experience leading compliance initiatives, cross-functional projects, or remediation programs.
  • Healthcare, pharmaceutical, distribution, or regulated-industry experience.
  • At McKesson, we care about the well-being of the patients and communities we serve, and that starts with caring for our people. That's why we have a Total Rewards package that includes comprehensive benefits to support physical, mental, and financial well-being. Our Total Rewards offerings serve the different needs of our diverse employee population and ensure they are the healthiest versions of themselves.
  • As part of Total Rewards, we are proud to offer a competitive compensation package at McKesson. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered.

Our Base Pay Range for this position

€72,000 - €120,000

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOX and Compliance Analyst
SOX and Compliance Analyst

McKesson • Cork

Hybrid
EUR 56,000 - 94,000
Cybersecurity GRC Analyst, SAP Platform
Cybersecurity GRC Analyst, SAP Platform

McKesson • Cork

Hybrid
EUR 56,000 - 94,000
Operations Manager, SOX and Compliance
Operations Manager, SOX and Compliance

McKesson • Cork

Hybrid
EUR 56,000 - 94,000
Senior SAP GRC & SOX Compliance Analyst
Senior SAP GRC & SOX Compliance Analyst

McKesson • Cork

Hybrid
EUR 72,000 - 120,000
Total Rewards package
Competitive compensation
Sr IAM Engineer – SAP Security (Integration)
Sr IAM Engineer – SAP Security (Integration)

McKesson • Cork

On-site
EUR 66,000 - 110,000
Sr IAM Engineer - SAP Security (Integration)
Sr IAM Engineer - SAP Security (Integration)

McKesson Corporation • Ireland

On-site
EUR 66,000 - 110,000
Comprehensive benefits package
Performance-based bonuses
Long-term incentive opportunities
Sr. IAM Engineer – SAP Security HANA
Sr. IAM Engineer – SAP Security HANA

McKesson • Cork

On-site
EUR 66,000 - 110,000
Comprehensive benefits
Competitive compensation package
SOX & GRC Compliance Analyst (SAP & IAM)
SOX & GRC Compliance Analyst (SAP & IAM)

McKesson • Cork

Hybrid
EUR 56,000 - 94,000
SOX & Compliance Operations Lead (SAP GRC & Audit)
SOX & Compliance Operations Lead (SAP GRC & Audit)

McKesson • Cork

Hybrid
EUR 56,000 - 94,000
Sr. IAM Engineer - SAP Security HANA
Sr. IAM Engineer - SAP Security HANA

McKesson Corporation • Ireland

On-site
EUR 66,000 - 110,000
Comprehensive benefits package