> Markdown version of [/jobs/ext/2153171-it-sox-manager](https://www.wearedevelopers.com/jobs/ext/2153171-it-sox-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT SOX Manager - **Company:** Atlas Energy Solutions - **Location:** Austin, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Access, JIRA, Microsoft Azure, Cloud Computing, Control Objectives for Information and Related Technology (COBIT), Databases, Custom Software, Programming Tools, Identity and Access Management, Information Technology Audit, IT Management, Systems Development Life Cycle, Software Engineering, User Provisioning Software, IT General Controls (ITGC), Okta, RSA Archer Platform - **Published:** August 20, 2026 - **Apply:** https://www.austinjobsite.com/job.asp?id=3360726869&tx=KK3333FFF&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Strong knowledge of SOX, IT General Controls (ITGCs), and the COSO framework * Understanding of how IT controls support internal controls over financial reporting (ICFR) * Working knowledge of IT environments, including applications, databases, operating systems, infrastructure, and access/security controls. * Strong understanding of Software Development Life Cycle (SDLC) processes and related controls. * Strong analytical and problem-solving skills with the ability to identify risks and develop effective solutions. * Excellent communication and interpersonal skills with the ability to work effectively across IT, Accounting, Audit, and business teams. * Strong organizational skills with the ability to manage multiple priorities and deadlines. * Ability to work independently, exercise sound judgment, and take ownership of assigned responsibilities. * CISA, CIA, CPA, CISSP, Security+, or progress toward a relevant certification is preferred. Minimum Requirements * 4â??7 years of experience in IT audit, IT compliance, IT risk management, or a related field. * Experience working in public accounting, internal audit, or a corporate SOX environment. * Hands-on experience supporting SOX ITGC testing and IT audits * 3â??5 years of end-to-end audit experience, including planning, fieldwork, testing, reporting, and follow-up. * Experience with SDLC controls, including application development, testing, change management, and implementation. * Experience identifying control gaps and supporting remediation efforts. * Experience working with both technical and non-technical stakeholders., * Hands-on experience applying leading IT governance and security frameworks, including COBIT, NIST, ISO 27001, or SOC 1/SOC 2 * Proven experience leveraging GRC platforms such as AuditBoard or Archer to manage controls, evidence, testing, and remediation activities. * Experience working with identity and access management tools such as Okta or Microsoft Azure AD/Entra ID to support access controls and user provisioning processes. * Familiarity with change management and development tools such as Jira, with an understanding of how these tools support SDLC and change control processes. * Exposure to complex technology environments, including ERP, CRM, custom applications, and cloud platforms such as Microsoft Azure * Knowledge of ITIL principles and IT service management processes. * Experience supporting SOX compliance within a public company environment ## Description This individual contributor role will own key aspects of the IT SOX program, including control assessments, testing, documentation, risk identification, and remediation. The IT SOX Manager will work closely with IT, Accounting, Internal Audit, and external auditors to ensure that in-scope systems and processes support effective internal controls over financial reporting., * Lead the execution of the IT SOX program, including scoping, planning, walkthroughs, testing, and reporting. * Assess the design and operating effectiveness of IT General Controls and relevant application controls. * Perform end-to-end IT audit activities, including risk assessment, control testing, issue identification, and follow-up. * Maintain accurate SOX documentation, including control matrices, process narratives, flowcharts, and testing workpapers. * Partner with IT control owners to understand processes, collect evidence, address questions, and resolve control issues. * Identify control deficiencies and recommend practical improvements to strengthen the overall IT control environment. * Track remediation activities and work with control owners to ensure identified issues are appropriately addressed and documented. * Support Internal Audit and external auditors by coordinating requests, facilitating walkthroughs, and providing supporting documentation. * Prepare SOX status reports, dashboards, and updates for IT leadership and other stakeholders. * Support IT risk assessments and evaluate changes to systems, applications, and processes that may impact SOX controls. * Develop training and guidance to help IT control owners understand their SOX responsibilities and control requirements. * Contribute to continuous improvement initiatives that increase the efficiency and maturity of the IT SOX program. * Perform other duties and special projects as assigned. ## Related Videos - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)