FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in leading IT SOX programs, implementing IT General Controls, and ensuring compliance with HIPAA and NIS2 regulations. Proficient in conducting risk assessments and translating security policies into actionable practices for diverse stakeholders.
Highest-signal resume keywords
IT AuditIT ComplianceCyber RiskSOX 404 (ITGCs)HIPAA Security Rule
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
NIST 800-53ISO 27001NIST CSFCOBITERP Systems (SAP ECC/S4 HANA)Cloud Environments (Microsoft Azure, AWS)GRC Systems (AuditBoard, Workiva)
Soft Skills
Stakeholder CommunicationRoot-Cause AnalysisContent Creation
Certifications & Qualifications
CISACISSPCRISC
Industry Keywords
IT General ControlsIT Application ControlsSecurity Awareness ProgramNIS2 DirectivePHI Protection
Tech Stack
Tools & technologiesAWSAzureCloudERP
About the role
Key responsibilities & impact- Lead the IT SOX program and design, implement, and test IT General Controls, IT Application Controls, and Key Reports across enterprise applications, databases, and infrastructure
- Serve as the primary translator between technical teams and external auditors
- Ensure audit evidence is accurate, timely, and defensible
- Lead root-cause analysis for control failures and partner with stakeholders on long-term remediation plans
- Act as the technical SME for the HIPAA Security Rule and ensure controls protect PHI
- Monitor controls and provide management guidance for new systems
- Lead alignment of the security posture with the NIS2 Directive for European operations
- Conduct strategic risk assessments for new technologies and vendors
- Manage the security awareness program and create engaging content for diverse audiences
- Translate Information Security Policies into actionable good practices for IT administrators and data owners
- Design targeted communication campaigns to increase internal reporting of security incidents and reinforce compliance
Requirements
What you’ll need- 5–7 years in IT Audit, IT Compliance, or Cyber Risk
- Expert-level understanding of SOX 404 (ITGCs)
- Strong working knowledge of the HIPAA Security Rule and NIS2
- Proficiency in applying NIST 800-53, ISO 27001, NIST CSF, or COBIT
- CISA is highly preferred
- CISSP or CRISC is a major plus
- Ability to explain why controls are necessary to key stakeholders without sounding like an auditor
- Experience with ERP systems such as SAP (ECC/S4 HANA)
- Experience with cloud environments such as Microsoft Azure and AWS
- Experience with GRC systems such as AuditBoard and Workiva or other comparable systems
Benefits
Comp & perks- Equality and diversity commitment
- Fair, transparent, and non-discriminatory recruitment process
