> Markdown version of [/jobs/ext/2029495-sr-manager-it-control-assurance-sox](https://www.wearedevelopers.com/jobs/ext/2029495-sr-manager-it-control-assurance-sox). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Manager, IT Control, Assurance & SOX - **Company:** Johnson & Johnson - **Location:** New Brunswick, NJ, United States - **Experience:** Expert - **Salary:** $122,000.0 - $245,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Business Process Modeling, Software as a Service, Cloud Computing, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Systems, Information Technology Audit, Oracle (Applications), Systems Development Life Cycle, Information Security Management System, Google Cloud, Cloud Platform System, IT General Controls (ITGC), Delivery Pipeline, Cyber Threat Analysis, Information Technology, SAP S/4HANA, RSA Archer Platform, Meditech, Workday, GXP, Servicenow - **Published:** August 11, 2026 - **Apply:** https://www.juju.com/job/00000000gmnxac ## About the Role + Bachelor's degree in Computer Science, Information Security, Business, Engineering, ora relatedfield (required). + Master's degree in Cybersecurity, Information Systems, or Business Administration (preferred). Experience and Skills: Required: + 10+ years of experience in IT audit, IT controls, SOX, or IT compliance, including experience in a Big 4 or large public company environment + Deepexpertiseacross all three capability areas: IT Controls & Assurance, SOX (ITGCs and IT-dependent business controls), and IT Compliance + Strong working knowledge of control and compliance frameworks - COBIT, COSO, NIST CSF, ISO 27001, and SOC 1/SOC 2 + Proven experience coordinating with External Auditors, Internal Audit, and business process owners on complex, multi-entity audits + Demonstrated ability to evaluate control deficiencies, drive remediation, and communicate risk and compliance status to executive stakeholders + Experience assessing IT controls and compliance in cloud environments (AWS, Azure, GCP) and across ERP and SaaS platforms + Strong leadership, stakeholder management, and cross-functional collaboration skills, including managing global and co-sourced teams Preferred: + Experience supporting a separation, spin-off, IPO, or standalone company standing up its first-year SOX and compliance program + Familiarity with SAP S/4HANA, Workday, Oracle, or other ERP platforms and their control configurations + Experience with GRC platforms (e.g., ServiceNow IRM,AuditBoard, Archer) and continuous controls monitoring / audit analytics + Background in healthcare, MedTech, pharmaceuticals, or other highly regulated industries + Familiarity with regulatory and privacy requirements relevant to IT - SOX, SEC,GxP, HIPAA, GDPR, and emerging AI regulations Other: + Language: Englishproficiencyrequired + Travel: Up to 15% domestic and international travel + Certifications (preferred): CISA, CPA, CIA, CISSP, or equivalent, Business Process Design, Collaboration, Crisis Management, Critical Thinking, Cyber Threat Intelligence, Developing Others, Inclusive Leadership, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Leadership, Managing Managers, People Performance Management, Presentation Design, Process Optimization, Security Architecture Design, Security Policies ## Description DePuy Synthes is recruiting for a(n) Sr. Manager, IT Controls, Assurance & SOX located in New Brunswick, NJ or Palm Beach Gardens, FL or Warsaw, IN or West Chester, PA or Raynham, MA. This role leads the design, execution, and continuous improvement of DePuy Synthes' IT controls, assurance, and (SOX) program within the Governance & Risk function of Cybersecurity. The Sr. Manager will own the enterprise IT SOX control framework, IT general controls (ITGCs), automated application controls, and IT-related assurance activities across financially relevant systems, cloud platforms, and third-party services. This position partners closely with Finance, Internal Audit, External Auditors, Application Owners, and Infrastructure teams to ensure a strong control environment, timely remediation of deficiencies, and audit-ready operations as the company stands up as an independent, publicly traded entity. Key Responsibilities _IT Controls & Assurance_ + Own the enterprise IT control framework - including ITGCs (access, change, operations), automated application controls, and IT-dependent business controls - aligned to COBIT, COSO, NIST CSF, and internal policies + Lead design and operating effectiveness assessments of IT controls across ERP, cloud, SaaS, and infrastructure platforms, and drive remediation ofidentifiedgaps + Partner with application, cloud, and infrastructure teams to embed preventive and detective controls by design in the SDLC, DevOps pipelines, and cloud landing zones + Extend the assurance program to third parties and managed service providers, including review of SOC 1/SOC 2 reports, complementary user entity controls (CUECs), and bridge letters + Serve as the primary IT liaison for Internal Audit, External Auditors, and regulatory examiners - coordinating walkthroughs, evidence, testing, and management responses + Advance continuous controls monitoring (CCM), analytics, and automation to expand control coverage and reduce manual testing effort _SOX_ + Own the end-to-end IT SOX program - scoping, risk assessment, control design, management testing, deficiency evaluation, and reporting across in-scope financial systems and supporting IT infrastructure + Define the annual IT SOX plan in partnership with Finance, Internal Audit, and External Auditors, including in-scope applications, ITGCs, key reports, and automated controls + Lead management testing of ITGCs and IT-dependent business controls, ensuringtimelycompletion, quality of evidence, and consistent workpaper standards + Drive deficiency evaluation, root cause analysis, remediation planning, and status reporting to leadership and the Audit Committee + Stand up andoperatethe first-year SOX program for the standalone DePuy Synthes entity, including RCMs, narratives, and control ownership across the new operating model + Modernize the SOX program through GRC tooling (e.g., ServiceNow IRM,AuditBoard, Archer), risk-based sampling, and automated evidence collection _Compliance_ + Lead IT compliance activities across applicable regulatory, contractual, and internal policy requirements - including SOX, SEC,GxP, HIPAA, GDPR, and other data protection and industry regulations + Maintain an integrated IT policy, standard, and control library, and drive alignment across Cybersecurity, IT, Legal, Privacy, and Compliance functions + Track regulatory change, assess IT impact, and update controls, policies, and evidence to keep the environment continuously compliant + Coordinate IT responses to customer, partner, and regulator due diligence requests, security questionnaires, and certification programs (e.g., ISO 27001, HITRUST where applicable) + Assess compliance implications of emerging technologies (cloud, AI/ML, GenAI, automation) and update the control and compliance framework accordingly + Provide training, guidance, and clear escalation paths to IT and business control owners to reinforce a strong compliance culture _Governance, Reporting & Team Leadership_ + Provide regular reporting to the CISO, Director of Governance & Risk, Finance leadership, and the Audit Committee on IT controls, SOX status, and compliance posture + Support Day-1 readiness and post-separation BAU operations for controls, assurance, SOX, and compliance across the standalone DePuy Synthes environment + Build, lead, and develop a global team across the US and the GCC in India, and manage co-source/outsourced testing partners for quality, consistency, and efficiency + Coach and mentor team members, fostering technical depth, audit acumen, and strong business partnership skills, Johnson & Johnson announced plans to separate our Orthopaedics business to establish a standalone orthopaedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may be required, regulatory approvals and other customary conditions and approvals. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes. ## Related Videos - [Blueprints for Success: Steering a Global Data & AI Architecture](https://www.wearedevelopers.com/videos/1577-blueprints-for-success-steering-a-global-data-ai-architecture) - [Destigmatizing the Workplace: Building Real Inclusion](https://www.wearedevelopers.com/videos/1492-destigmatizing-the-workplace-building-real-inclusion) - [Navigating the Corporate Jungle: Life as a Developer in a large Company](https://www.wearedevelopers.com/videos/621-navigating-the-corporate-jungle-life-as-a-developer-in-a-large-company) - [The Future of Employee Wellbeing: Benefits, Trust & Performance](https://www.wearedevelopers.com/videos/1808-the-future-of-employee-wellbeing-benefits-trust-performance) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Employee Happiness: The Underrated Growth Engine](https://www.wearedevelopers.com/videos/1310-employee-happiness-the-underrated-growth-engine) ## Related Articles - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Best Job Search Websites of 2025](https://www.wearedevelopers.com/magazine/368-the-best-job-search-websites-of-2025)