Executive Director, SOX & SOC Compliance

atCVS HealthRemoteUS flagVirginiaFull-timeComplianceLead$175.1k – $334.8k/year

Posted 15 hours ago

This is a fully remote position, open to applicants in Virginia.

📋 Description

• Take ownership of CVS Health's enterprise SOX cybersecurity/ITGC and SOC 1/SOC 2 compliance programs from a first-line perspective.

• Establish control scope, requirements, evidence standards, and readiness activities.

• Collaborate with the Controls Assurance Testing (CAT) team to outline the annual testing scope and schedule.

• Oversee testing progress, resolve blockers, and ensure timely evidence and support from control owners.

• Lead readiness initiatives for SOC 1 and SOC 2, including mapping controls to trust services criteria.

• Act as the primary compliance contact for Internal Audit and external auditors.

• Manage audit requests, walkthroughs, evidence requirements, and issue resolution processes.

• Oversee the lifecycle of control deficiencies, including root cause analysis, remediation planning, and readiness for closure.

• Maintain SOX and SOC requirements, scoping documentation, and evidence standards within GRC platforms.

• Promote continuous improvement, facilitate evidence reuse, and minimize duplicate requests.

• Generate and present executive-level reports on compliance status, control readiness, effectiveness, issue trends, and remediation progress.

• Partner with policy and standards owners to adapt to evolving regulatory and framework expectations.

• Assist in security exception and risk acceptance processes related to SOX- and SOC-relevant control gaps.

• Lead, mentor, and develop the SOX & SOC Compliance team.


⛳️ Requirements

• Over 10 years of progressive experience leading first-line-of-defense SOX ITGC, SOC 1/SOC 2, technology compliance, or control governance initiatives.

• At least 3 years in a leadership capacity.

• More than 7 years managing SOX ITGC and SOC 1/SOC 2 compliance programs from a first-line-of-defense viewpoint.

• Over 7 years of experience with SOX, SOC 1/SOC 2 trust services criteria, PCAOB/AICPA standards, NIST CSF, ISO 27001, and HITRUST CSF.

• At least 3 years of experience with GRC and compliance management platforms such as Optro, Archer, or ServiceNow.

• More than 3 years of people leadership experience, including building, developing, and retaining a high-performing compliance team.

• Bachelor's degree in Information Security, Accounting, Information Systems, Risk Management, or a related field, or equivalent professional experience.

• Relevant certifications such as CISA, CISSP, CISM, CRISC, or CPA are preferred.

• Experience in healthcare, health insurance, pharmacy, or retail sectors is preferred.

• Familiarity with supporting regulatory examinations, cybersecurity compliance reviews, and external audit engagements is preferred.

• Knowledge of SEC cybersecurity disclosure requirements and materiality assessment processes is preferred.

• Experience operating within a matrixed, multi-business-unit enterprise is preferred.

• Ability to cultivate and manage cross-functional partnerships is preferred.

• Capability to communicate compliance status, control readiness, issue updates, and remediation progress to executive leadership, Internal Audit, and external auditors is preferred.


🏝️ Benefits

• CVS Health bonus, commission, or short-term incentive program.

• Equity award program.

• Medical coverage.

• Dental coverage.

• Vision coverage.

• Paid time off.

• Retirement savings options.

• Wellness programs.

• Additional resources supporting physical, emotional, and financial well-being.

People also viewed

American Cancer Society14 hours ago

Director, Compliance & Ethics

US flagFlorida, +2 more statesFull-timeCompliance$130k – $140k/year
ApplyView job
Humana14 hours ago

Insurance Product Compliance Professional

US flagUnited States OnlyFull-timeCompliance$59.3k – $80.9k/year
ApplyView job
Sandvik Group15 hours ago

License Compliance Manager

IT flagItaly, +3 more countriesFull-timeCompliance
ApplyView job
Sandvik15 hours ago

License Compliance Manager

IT flagItaly, +3 more countriesFull-timeCompliance
ApplyView job
VikingCloud16 hours ago

PCI Compliance Specialist, PDS Program

US flagIllinois, +2 more statesFull-timeCompliance$16 – $18/hour
ApplyView job
VikingCloud16 hours ago

PCI Compliance Specialist – PDS Program

US flagIllinois, +2 more statesFull-timeCompliance$16 – $18/hour
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers