Risk and Control Manager - IT SOX, GFRC

Amazon

Boston (MA)

On-site

USD 121,000 - 164,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
401(k) matching
Paid time off
Parental leave

Job summary

Amazon is seeking an IT SOX Program Manager to lead the IT SOX program within GFRC, focusing on control design, implementation, and ongoing assurance of ITGCs across the enterprise. The role emphasizes collaboration with engineering, accounting, and business teams to strengthen ICFR and adapt to a fast-paced, high-growth environment.

Requirements include 5+ years in compliance/audit/risk, COSO 2013 knowledge, and strong ITGC expertise. Experience with ERP systems and GRC platforms is preferred.

Qualifications

  • 5+ years of compliance, audit or risk management experience.
  • Bachelor's degree or equivalent.
  • Deep knowledge of COSO 2013 framework and SEC/PCAOB regulations.
  • Experience with IT general controls (ITGCs) including access management and change management.
  • Ability to design and monitor a global internal control environment.

Responsibilities

  • Execute IT SOX control strategies and improve program policies.
  • Lead IT process risk and controls to address financial reporting risk.
  • Drive continuous improvement through risk assessments and method updates.
  • Support the 302 sub-certification and related reporting.
  • Collaborate with cross-functional teams to embed ITGC requirements.

Skills

ITSOX
COSO 2013
SOX compliance
Auditing
Stakeholder collaboration

Education

Bachelor's degree or equivalent
Master's degree

Tools

GRC platforms
ERP systems

Job description

Description

Are you excited about driving SOX compliance in a fast paced, dynamic, tech-forward environment? Come join our Global Financial Risk and Controls (GFRC) controls team to lead the IT SOX program.

Description

Are you excited about driving SOX compliance in a fast paced, dynamic, tech-forward environment? Come join our Global Financial Risk and Controls (GFRC) controls team to lead the IT SOX program.
GFRC oversees internal controls over financial reporting, subsidiary compliance, internal controls readiness, process improvements, and other enterprise compliance activities. We are a subject matter expertise team that builds, designs, and consults with control owners across the enterprise. This role will require a deep understanding and experience with all aspects of internal controls including financial information technology systems for a complex, high-growth stage, multi-disciplinary organization.

We are currently looking for experienced candidates who have held similar positions in large public companies or who have held a similar position within the advisory practice of a Big 4 public accounting firm serving Fortune 500 clients for +8 years. Requirements for this position also include a deep knowledge the COSO 2013 framework and SEC/PCAOB regulations, as well as the demonstrated ability to design and monitor an effective global risk-based internal control environment. Additionally, demonstrated experience in working collaboratively to accomplish challenges will be expected as this is an ongoing requirement for this position.

Key job responsibilities
IT SOX Program Management
  • Executing on IT SOX controls strategies, including maintaining and improving program policies and procedures
  • Contributing to deep dives on IT process areas to define the set of risks and controls in addressing financial reporting risk
  • Driving continuous improvement of the IT SOX program through risk assessment updates, methodology enhancements, and process optimization
  • Supporting the quarterly 302 sub-certification process and related reporting
  • Assisting in the evaluation of identified control deficiencies and monitoring of remediation efforts
Company-Wide Initiatives
  • Supporting company-wide initiatives that impact ITGC control design and implementation
  • Assisting with system implementation and migration and respective SDLC controls
  • Evaluating control implications for enterprise-wide technology transformations, platform consolidations, and new system launches
  • Partnering with cross-functional teams to ensure ITGC requirements are embedded into large-scale organizational programs
IT SOX Control Consultation (Design & Implementation)
  • Driving control design and implementation with engineering, business, and accounting teams
  • Providing ongoing support to process owners/control owners and cross-functional teams to ensure controls are designed and implemented effectively
  • Advising engineering teams on ITGC requirements for access management, change management, and IT operations controls
  • Consulting on control solutions that balance compliance requirements with operational efficiency and scalability
External Auditor Management
  • Managing auditor inquiries and facilitating timely resolution of identified findings
  • Maintaining ongoing relationships with external audit teams to proactively address emerging IT control concerns
About The Team

GFRC team's key purpose is to preserve Amazon's financial reputation by promoting strong controllership that supports internal controls over financial reporting (ICFR) designed to provide reasonable assurance that Amazon's consolidated and statutory financial statements are complete and accurate. We partner closely with our global customers to identify and mitigate key financial reporting risks to achieve the company's control objectives. We do this by maintaining the overall ICFR framework in the GRC platform and supporting the teams responsible for designing, documenting, executing, and assessing their processes, systems, and controls in their respective business environments.

Basic Qualifications
  • 5+ years of compliance, audit or risk management experience
  • Bachelor's degree or equivalent
Preferred Qualifications
  • Master's degree or equivalent
  • Deep knowledge of IT general controls (ITGCs), including access management, change management, and IT operations
  • Experience with IT SOX scoping, risk assessment, control design, testing, and remediationUnderstanding of the COSO 2013 framework and SEC/PCAOB regulations as they relate to IT controls
  • Familiarity with ERP systems, databases, and IT infrastructure relevant to financial reporting
  • Experience working with GRC platforms and audit management tools
  • Strong understanding of SDLC controls and system implementation lifecycle
  • Excellent written and verbal communication skills

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.

USA, CA, Culver City - 121,200.00 - 163,900.00 USD annually

USA, MA, Boston - 121,200.00 - 163,900.00 USD annually

USA, OR, Portland - 121,200.00 - 163,900.00 USD annually

USA, TN, Nashville - 109,000.00 - 155,400.00 USD annually

USA, TX, Austin - 121,200.00 - 163,900.00 USD annually

USA, VA, Arlington - 121,200.00 - 163,900.00 USD annually

USA, WA, Seattle - 121,200.00 - 163,900.00 USD annually

Company

Amazon.com Services LLC

Job ID: A10459506

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Risk and Control Manager - IT SOX, GFRC
Risk and Control Manager - IT SOX, GFRC

Amazon • Austin (TX)

On-site
USD 121,000 - 164,000
Risk and Control Manager - IT SOX, GFRC
Risk and Control Manager - IT SOX, GFRC

Amazon • Culver City (CA)

On-site
USD 121,000 - 164,000
Risk and Control Manager - IT SOX, GFRC
Risk and Control Manager - IT SOX, GFRC

Amazon • Seattle (WA)

On-site
USD 121,200 - 163,900
Health insurance
401(k) matching
Parental leave
+1
Risk and Control Manager - IT SOX, GFRC
Risk and Control Manager - IT SOX, GFRC

Amazon • Nashville (TN)

On-site
USD 109,000 - 156,000
Sr. Manager, Internal Controls, Global Financial Risk & Controls
Sr. Manager, Internal Controls, Global Financial Risk & Controls

Amazon • Portland (OR)

On-site
USD 153,000 - 207,000
Sr. Manager, Internal Controls, Global Financial Risk & Controls
Sr. Manager, Internal Controls, Global Financial Risk & Controls

Amazon • Seattle (WA)

On-site
USD 153,000 - 207,000
Controls and Compliance Lead, AWS Controls
Controls and Compliance Lead, AWS Controls

Amazon Web Services (AWS) • Arlington (VA)

On-site
USD 67,000 - 117,000
Health insurance
401(k) matching
Paid time off
+1
Controls and Compliance Lead, AWS Controls
Controls and Compliance Lead, AWS Controls

Amazon Web Services (AWS) • Culver City (CA)

On-site
USD 73,000 - 117,000
Controls and Compliance Lead, AWS Controls
Controls and Compliance Lead, AWS Controls

Amazon Web Services (AWS) • Nashville (TN)

On-site
USD 60,000 - 105,000
Controls and Compliance Lead, AWS Controls
Controls and Compliance Lead, AWS Controls

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 83,000 - 117,000
Health insurance
RSUs
Paid time off