
Executive Director, SOX & SOC Compliance
Posted 15 hours ago

Posted 15 hours ago
This is a fully remote position, open to applicants in Virginia.
• Take ownership of CVS Health's enterprise SOX cybersecurity/ITGC and SOC 1/SOC 2 compliance programs from a first-line perspective.
• Establish control scope, requirements, evidence standards, and readiness activities.
• Collaborate with the Controls Assurance Testing (CAT) team to outline the annual testing scope and schedule.
• Oversee testing progress, resolve blockers, and ensure timely evidence and support from control owners.
• Lead readiness initiatives for SOC 1 and SOC 2, including mapping controls to trust services criteria.
• Act as the primary compliance contact for Internal Audit and external auditors.
• Manage audit requests, walkthroughs, evidence requirements, and issue resolution processes.
• Oversee the lifecycle of control deficiencies, including root cause analysis, remediation planning, and readiness for closure.
• Maintain SOX and SOC requirements, scoping documentation, and evidence standards within GRC platforms.
• Promote continuous improvement, facilitate evidence reuse, and minimize duplicate requests.
• Generate and present executive-level reports on compliance status, control readiness, effectiveness, issue trends, and remediation progress.
• Partner with policy and standards owners to adapt to evolving regulatory and framework expectations.
• Assist in security exception and risk acceptance processes related to SOX- and SOC-relevant control gaps.
• Lead, mentor, and develop the SOX & SOC Compliance team.
• Over 10 years of progressive experience leading first-line-of-defense SOX ITGC, SOC 1/SOC 2, technology compliance, or control governance initiatives.
• At least 3 years in a leadership capacity.
• More than 7 years managing SOX ITGC and SOC 1/SOC 2 compliance programs from a first-line-of-defense viewpoint.
• Over 7 years of experience with SOX, SOC 1/SOC 2 trust services criteria, PCAOB/AICPA standards, NIST CSF, ISO 27001, and HITRUST CSF.
• At least 3 years of experience with GRC and compliance management platforms such as Optro, Archer, or ServiceNow.
• More than 3 years of people leadership experience, including building, developing, and retaining a high-performing compliance team.
• Bachelor's degree in Information Security, Accounting, Information Systems, Risk Management, or a related field, or equivalent professional experience.
• Relevant certifications such as CISA, CISSP, CISM, CRISC, or CPA are preferred.
• Experience in healthcare, health insurance, pharmacy, or retail sectors is preferred.
• Familiarity with supporting regulatory examinations, cybersecurity compliance reviews, and external audit engagements is preferred.
• Knowledge of SEC cybersecurity disclosure requirements and materiality assessment processes is preferred.
• Experience operating within a matrixed, multi-business-unit enterprise is preferred.
• Ability to cultivate and manage cross-functional partnerships is preferred.
• Capability to communicate compliance status, control readiness, issue updates, and remediation progress to executive leadership, Internal Audit, and external auditors is preferred.
• CVS Health bonus, commission, or short-term incentive program.
• Equity award program.
• Medical coverage.
• Dental coverage.
• Vision coverage.
• Paid time off.
• Retirement savings options.
• Wellness programs.
• Additional resources supporting physical, emotional, and financial well-being.
American Cancer Society
Humana
Sandvik Group
Sandvik
Get handpicked remote jobs straight to your inbox weekly.