UK remote
IT SOX Scoping and Governance Analyst
About this role
We are looking for an IT SOX expert to join our mission and help us build a global platform that’s scalable, reliable, and secure. The Security Controls team plays a vital role in safeguarding Wise’s complex IT landscape. We specialise in the comprehensive testing, assessment, and continuous improvement of technology-related controls. This role will require you to drive scope rationalization, dependency mapping, and control optimization.
Your Mission Scope Rationalization & Optimization: Analyze and challenge existing IT SOX scope across applications and infrastructure. Identify duplicate, redundant, or over-engineered ITGCs/ITACs and propose enhancements. New System Onboarding: Establish RACMs (Risk and Control Matrices) and identify necessary ITGCs and ITACs for newly in-scope SOX applications and platforms. Dependency & System Mapping: Document and maintain end-to-end dependency maps (upstream/downstream data flows, infrastructure ties, and automated interfaces) for management review.
Controls Testing: Where needed, support control testing (Design & Operating Effectiveness) across our cloud infrastructure and SaaS landscape. Stakeholder Management: Partner with key stakeholders across Finance, Risk, Security, Platform to effectively communicate SOX 404 requirements and expectations. A bit about you: SOX Experience: You have 3+ years of experience in Technology Risk or IT Audit, with a dedicated focus on SOX.
You possess deep knowledge of SOX 404 requirements, COSO framework, and IT control frameworks (NIST, ISO27001). SOX Implementation: You have demonstrable experience with first-time SOX audits in cloud-native environments. You understand how compliance frameworks map to dynamic infrastructures. Cloud-Native Mindset: You understand how Change Management works in a CI/CD pipeline and how Access Management works in a microservices architecture.
Experience with AWS, Terraform, GitHub, Jira, Okta, and SailPoint is preferred. Scope & RACM Quality: You know what a good RACM looks like and can look at a system architecture diagram or control framework and spot where coverage is either missing or excessively duplicative. Clear Communicator: You can translate technical architecture details into audit-ready documentation while explaining compliance "whys" clearly to engineers.