IT SOX/GRC Compliance Analyst

KayDev Technology, LLC
United States
3 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$93,600.0
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Identity and Access Management Information Technology Audit IT Management Information Technology Operations Azure Active Directory Workflow Management Systems IT General Controls (ITGC) Okta Cyberark Enterprise Integration RSA Archer Platform
+3 more
SailPoint Software Version Control Servicenow

Job description

SOX ITProgram Ownership (Primary)

  • Own end-to-end execution of SOX IT General Controls across access management, change management, IT operations, and program development for in-scope applications and infrastructure.
  • Perform control walkthroughs, operating-effectiveness testing, and evidence collection on a quarterly and annual cadence.
  • Serve as primary IT point of contact for Internal Audit and external auditors; manage PBC request lists, sample selections, and testing timelines.
  • Track, root-cause, and remediate control deficiencies; maintain the deficiency log and management action plans.
  • Maintain the IT control matrix, risk-control narratives, flowcharts, and control-owner documentation.

IT Governance, Risk & Compliance (GRC)

  • Conduct IT risk assessments and maintain the IT risk register; map controls to applicable frameworks (SOX, HIPAA, NIST CSF, HITRUST as applicable).
  • Own the IT policy and standards lifecycle, including annual review, approval workflow, and version control.
  • Manage third-party/vendor IT risk reviews and Business Associate Agreement (BAA) compliance evidence.
  • Build and maintain compliance dashboards and status reporting for IT leadership and the Audit Committee.
  • Identify and implement automation to reduce manual evidence collection, control testing, and reporting effort.

HIPAA Security & Privacy (Supporting)

  • Support HIPAA Security Rule compliance, including risk analysis documentation, safeguard evidence, and policy maintenance.
  • Partner with Privacy and InfoSec on ePHI access controls and incident documentation.

Identity & Access Governance Zilla Security (Supporting)

  • Administer Zilla Security for user access reviews (UARs), certification campaigns, and SoD monitoring in support of SOX and HIPAA access controls.
  • Configure application integrations and review workflows; ensure timely campaign completion and produce audit-ready evidence.

ITIL Change Management / CAB (Supporting)

  • Chair the weekly Change Advisory Board (CAB): set agenda, review RFCs, assess risk/impact, and drive approval decisions.
  • Enforce the change management policy so standard, normal, and emergency changes are documented, approved, and auditable as SOX evidence.
  • Report change management KPIs (success rate, unauthorized changes, emergency change volume) to IT leadership.

Requirements

  • 4+ years of experience in IT SOX compliance, IT audit, or IT GRC within a regulated environment.
  • Experience leading CAB meetings and operating within an ITIL-based change management process; ITIL Foundation (v3/v4) or equivalent practical experience.
  • Hands-on experience owning or executing SOX ITGC controls, testing, and external audit coordination.
  • Working knowledge of IT GRC practices: risk assessment, control mapping, policy management, and deficiency remediation.
  • Working knowledge of HIPAA Security and Privacy Rule requirements.
  • Hands-on experience with Zilla Security or a comparable identity governance / access review platform.
  • Experience automating compliance workflows (evidence collection, access review campaigns, control monitoring, or reporting) using scripting, workflow tools, or GRC/IAM platform integrations.
  • Strong documentation, stakeholder communication, and audit-facing presentation skills.
  • Ability to work independently in a fully remote environment., * Healthcare, DME, or health-services industry experience.
  • CISA, CRISC, CISSP, CHPS, or HCISPP certification.
  • Big 4 or internal audit background.
  • Experience with GRC platforms (AuditBoard, ServiceNow IRM/GRC, Workiva, Drata, Vanta).
  • Experience with ServiceNow Change Management.
  • Familiarity with NIST CSF, HITRUST, or ISO 27001 frameworks.
  • Exposure to IAM platforms (Okta, Azure AD/Entra ID, SailPoint, Saviynt, CyberArk)., * Work Authorization: Must be authorized to work in the United States. 1099 independent contractor; no C2C.

Benefits & conditions

Location: 100% Remote (U.S.) Employment Type: 6-Month Contract-to-Hire (1099) Pay Rate: $45/hr 1099; conversion salary commensurate with experience Posted by: KayDev Technology LLC, This is a high-visibility position working with IT leadership, Internal Audit, InfoSec, control owners, and external auditors. The engagement is a 6-month contract with the intent to convert to a full-time permanent role.

About the company

KayDev Technology is seeking an experienced IT SOX/GRC Compliance Analyst to support our client, a leading national healthcare services provider. This role is the hands-on owner of the IT SOX ITprogram and the broader IT governance, risk, and compliance (GRC) function control execution, evidence collection, audit coordination, risk assessment, and policy management with supporting responsibility for HIPAA Security Rule compliance, identity and access governance in Zilla Security, and ITIL-based change management including chairing the Change Advisory Board (CAB)., About KayDev Technology

KayDev Technology LLC is a Service-Disabled Veteran-Owned (SDVOSB) and Native American-Owned cybersecurity, IT services, and staffing firm headquartered in Fort Worth, Texas. We partner with enterprise and public-sector clients to deliver security, compliance, and technology talent.

KayDev Technology is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:24 min

Evaluating remote software roles and compensation structures

Nacho Iacovino · World Congress 2021

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:44 min

Background and career journey in regulated software systems

Martin Hynie · Coffee With Developers

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

2:20 min

Addressing security risks with central single sign-on setups

Gift Egwuenu · World Congress 2023

3:48 min

Balancing developer self-service with strict compliance requirements

Amir Friedman Amir Friedman +2 · World Congress 2025

Videos

See all

Related articles

See all