IT SOX Controls Specialist

at Stripe
USD 135,000-202,400 per year
MIDDLE
✅ On-site

Tech Stack

Audit @ 3 Communication @ 6 FinTech @ 3 Jira @ 3 Payments @ 3 Reporting @ 2

Details

Who We Are

Stripe is a financial infrastructure platform for businesses. Millions of companies use Stripe to accept payments, grow revenue, and accelerate new business opportunities. Stripe's Finance organization is building a world-class Controllership team responsible for the corporate SOX program.

Responsibilities

  • Own the end-to-end SOX assessment lifecycle for third-party applications in scope for financial reporting, including identification, risk tiering, and control mapping.
  • Lead the evaluation and review of third-party SOC 1 and SOC 2 reports, including SSAE 18 and ISAE 3402 reports, assessing complementary user entity controls (CUECs) and identifying gaps requiring compensating controls.
  • Design and implement controls addressing risks from third-party systems and integrations that affect the financial reporting supply chain.
  • Develop and maintain SOX-ready documentation for third-party control environments, including risk and control matrices (RCMs), narratives, and process flow diagrams.
  • Project manage control definition and implementation for new third-party system implementations, migrations, and integrations with financial reporting impact.
  • Partner with IT, Procurement, business process owners, and Vendor Management teams to embed control requirements into vendor onboarding and periodic review processes.
  • Review Information Produced by the Entity (IPE) sourced from third-party systems for completeness and accuracy.
  • Assess and track control deficiencies identified through third-party reviews, coordinating root cause analysis and corrective action plans with relevant process owners.
  • Support the 302 and 404 sub-certification process relating to third-party application risks and controls.
  • Monitor the third-party application landscape for emerging financial reporting risks and proactively develop control plans.
  • Contribute to SOX program improvements, including automation and optimization of third-party control monitoring.

Requirements

  • Bachelor's degree; a master's degree is a plus in Accounting, Information Systems, Finance, or a related field.
  • Technical certification required, such as CPA, CIA, CISA, or PMP.
  • 10 or more years of experience managing and/or assessing SOX programs.
  • Big Four audit firm or equivalent audit experience.
  • Extensive experience leading and performing SOX business process program design, control implementation, and SOX program monitoring.
  • Hands-on experience evaluating third-party SOC 1 and SOC 2 reports and assessing CUEC coverage and gaps.
  • Familiarity with IT general controls and application-level controls in the context of financial reporting systems.
  • Strong knowledge of technical accounting, order-to-cash, and financial close and reporting controls.
  • Strong communication skills, including presenting to and influencing senior business leaders.
  • Demonstrated success managing concurrent workstreams and projects independently.

Preferred Qualifications

  • Experience implementing internal controls in early-stage public companies.
  • Experience in online payments, ecommerce, SaaS, payments, fintech, or financial services.
  • Experience with JIRA and AuditBoard.
  • Familiarity with third-party risk management (TPRM) frameworks and vendor risk programs.

More jobs at Stripe

Similar jobs