Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 2
Audit @ 6
Communication @ 5
Compliance @ 6
Security @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
GitLab is seeking an individual contributor to support its IT Sarbanes-Oxley (SOX) compliance program. The role reports to the Senior Director, SOX PMO Leader within the Chief Accounting Officer's organization and directly supports the Senior Manager, IT SOX PMO. The position focuses on IT general controls (ITGCs), IT application controls (ITACs), SOX readiness, control improvement, and automation in a high-growth software-as-a-service (SaaS) environment.
Responsibilities
- Serve as an IT SOX subject matter expert for ITGCs and ITACs, providing guidance and supporting compliance with SOX requirements.
- Partner with the business SOX Program Management Office (PMO) to assess SOX readiness for new or changing systems and business processes, and support the annual IT SOX risk assessment.
- Maintain and improve control documentation, including flowcharts, risk and control matrices, and control inventories.
- Facilitate IT control walkthroughs and coordinate remediation of control deficiencies.
- Coordinate with internal and external auditors throughout the SOX audit cycle, clearly presenting positions and supporting appropriate conclusions.
- Review System and Organization Controls (SOC) reports and oversee the key report testing program with contractor support, performing hands-on testing when needed.
- Build cross-functional relationships, including a close partnership with Internal Audit on SOX testing execution.
- Identify opportunities for control automation and monitor emerging risks and regulatory changes, including those related to artificial intelligence (AI).
- Help prepare reports and presentation materials on SOX compliance status.
Requirements
- Bachelor's degree in information technology, computer science, accounting, or a related field.
- IT audit and SOX compliance experience, including deep knowledge of ITGCs, ITACs, and control frameworks such as Control Objectives for Information and Related Technologies (COBIT) and the Committee of Sponsoring Organizations of the Treadway Commission (COSO) framework.
- A current Certified Information Systems Auditor (CISA), Certified Public Accountant (CPA), Certified Internal Auditor (CIA), or Certified Information Systems Security Professional (CISSP) certification.
- Experience working in the SaaS industry.
- Proficiency with governance, risk, and compliance tools; experience with AuditBoard is a plus.
- Professional judgment, critical thinking, and clear written and verbal communication skills, including persuasion, influence, and conflict resolution.
- A practical and creative approach to complex problems, audit findings, and recommendations, with familiarity using AI tools to improve compliance processes.
- Ability to collaborate effectively across US Pacific and Eastern time zones.
Team
The SOX PMO team is a second-line function within GitLab's Chief Accounting Officer organization. It owns and manages the enterprise SOX compliance program across risk assessment, control design, documentation, and coordination with external auditors. Internal Audit operates as the independent third-line function responsible for SOX testing. The team collaborates asynchronously across regions and functions as an all-remote team.
Benefits
- Benefits supporting health, finances, and well-being
- Flexible paid time off
- Team Member Resource Groups
- Equity compensation and Employee Stock Purchase Plan
- Growth and Development Fund
- Parental leave
- Home office support
Salary
The United States base salary range is $115,000–$194,000 USD. The range excludes bonuses, equity, and benefits.