> Markdown version of [/jobs/ext/2697748-it-sox-grc-compliance-analyst](https://www.wearedevelopers.com/jobs/ext/2697748-it-sox-grc-compliance-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT SOX/GRC Compliance Analyst - **Company:** KayDev Technology, LLC - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $93,600.0 - **Contract:** Temporary to permanent - **Skills:** Cyber Security, Identity and Access Management, Information Technology Audit, IT Management, Information Technology Operations, Azure Active Directory, Workflow Management Systems, IT General Controls (ITGC), Okta, Cyberark, Enterprise Integration, RSA Archer Platform, SailPoint, Software Version Control, Servicenow - **Published:** September 3, 2026 - **Apply:** https://www.dice.com/job-detail/c091f8d1-4eec-4f00-aa9f-097fe4be5738 ## About the Role * 4+ years of experience in IT SOX compliance, IT audit, or IT GRC within a regulated environment. * Experience leading CAB meetings and operating within an ITIL-based change management process; ITIL Foundation (v3/v4) or equivalent practical experience. * Hands-on experience owning or executing SOX ITGC controls, testing, and external audit coordination. * Working knowledge of IT GRC practices: risk assessment, control mapping, policy management, and deficiency remediation. * Working knowledge of HIPAA Security and Privacy Rule requirements. * Hands-on experience with Zilla Security or a comparable identity governance / access review platform. * Experience automating compliance workflows (evidence collection, access review campaigns, control monitoring, or reporting) using scripting, workflow tools, or GRC/IAM platform integrations. * Strong documentation, stakeholder communication, and audit-facing presentation skills. * Ability to work independently in a fully remote environment., * Healthcare, DME, or health-services industry experience. * CISA, CRISC, CISSP, CHPS, or HCISPP certification. * Big 4 or internal audit background. * Experience with GRC platforms (AuditBoard, ServiceNow IRM/GRC, Workiva, Drata, Vanta). * Experience with ServiceNow Change Management. * Familiarity with NIST CSF, HITRUST, or ISO 27001 frameworks. * Exposure to IAM platforms (Okta, Azure AD/Entra ID, SailPoint, Saviynt, CyberArk)., * Work Authorization: Must be authorized to work in the United States. 1099 independent contractor; no C2C. ## Description SOX ITProgram Ownership (Primary) * Own end-to-end execution of SOX IT General Controls across access management, change management, IT operations, and program development for in-scope applications and infrastructure. * Perform control walkthroughs, operating-effectiveness testing, and evidence collection on a quarterly and annual cadence. * Serve as primary IT point of contact for Internal Audit and external auditors; manage PBC request lists, sample selections, and testing timelines. * Track, root-cause, and remediate control deficiencies; maintain the deficiency log and management action plans. * Maintain the IT control matrix, risk-control narratives, flowcharts, and control-owner documentation. IT Governance, Risk & Compliance (GRC) * Conduct IT risk assessments and maintain the IT risk register; map controls to applicable frameworks (SOX, HIPAA, NIST CSF, HITRUST as applicable). * Own the IT policy and standards lifecycle, including annual review, approval workflow, and version control. * Manage third-party/vendor IT risk reviews and Business Associate Agreement (BAA) compliance evidence. * Build and maintain compliance dashboards and status reporting for IT leadership and the Audit Committee. * Identify and implement automation to reduce manual evidence collection, control testing, and reporting effort. HIPAA Security & Privacy (Supporting) * Support HIPAA Security Rule compliance, including risk analysis documentation, safeguard evidence, and policy maintenance. * Partner with Privacy and InfoSec on ePHI access controls and incident documentation. Identity & Access Governance Zilla Security (Supporting) * Administer Zilla Security for user access reviews (UARs), certification campaigns, and SoD monitoring in support of SOX and HIPAA access controls. * Configure application integrations and review workflows; ensure timely campaign completion and produce audit-ready evidence. ITIL Change Management / CAB (Supporting) * Chair the weekly Change Advisory Board (CAB): set agenda, review RFCs, assess risk/impact, and drive approval decisions. * Enforce the change management policy so standard, normal, and emergency changes are documented, approved, and auditable as SOX evidence. * Report change management KPIs (success rate, unauthorized changes, emergency change volume) to IT leadership. ## Related Videos - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Job Boards for Remote Work for Developers](https://www.wearedevelopers.com/magazine/290-best-job-boards-for-remote-work-for-developers)