Group IT SOX Analyst
Outside Capital · Johannesburg
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Introduction
We are looking for a Group IT SOX Analyst to support the delivery of the Group’s IT SOX compliance programme.
Working closely with the Group IT SOX Controller , you will play an important role in assessing IT risks, testing IT controls, supporting audit activities and strengthening the organisation’s overall IT control environment.
This is an excellent opportunity for an IT Audit, IT Risk or IT Controls professional looking to build or further develop their experience in IT SOX, IT General Controls (ITGCs), IT Application Controls (ITACs), IPE and third-party assurance within a group environment.
Duties & Responsibilities
IT SOX Compliance & Control Testing
- Execute the annual IT SOX testing programme.
- Perform design and operating effectiveness testing of IT General Controls (ITGCs) and IT Application Controls (ITACs) .
- Review Information Produced by the Entity (IPE) used in SOX controls.
- Prepare clear, accurate and well-supported audit working papers.
- Obtain and review evidence from control owners and follow up on outstanding items.
- Document control exceptions and support remediation activities.
- Perform remediation testing where required.
IT Projects & SOX Impact Assessments
- Support IT projects including system implementations, upgrades, migrations and decommissioning.
- Assess the potential SOX impact of new systems, applications, interfaces and technology changes.
- Identify new or amended IT controls resulting from project activities.
- Assist project teams with SOX documentation and control requirements.
- Maintain project risk assessments, action trackers and supporting documentation.
IT Application Controls
- Support the documentation and maintenance of IT Application Controls across in-scope systems.
- Evaluate automated controls for design effectiveness.
- Test system configurations, automated workflows, interfaces and validation controls.
- Assess the continued effectiveness of automated controls following system changes.
- Identify opportunities to improve or automate controls.
IPE & Third-Party Assurance
- Review system-generated reports used as part of SOX controls.
- Verify report parameters, filters, completeness and accuracy.
- Document IPE validation procedures and maintain supporting evidence.
- Assist with reviewing SOC 1/SOC 2 reports for third-party service providers.
- Assess Complementary User Entity Controls (CUECs) .
- Monitor SOC report expiry dates and support the assessment of third-party control gaps.
Governance & Continuous Improvement
- Support control walkthroughs, risk assessments and audit activities.
- Assist with maintaining Risk and Control Matrices (RACMs) and the IT SOX control library.
- Support SOX reporting, dashboards and management updates.
- Maintain high-quality documentation and version control.
- Identify opportunities to improve SOX processes, templates and procedures.
- Contribute to automation initiatives that improve the efficiency of the SOX programme.
- Keep up to date with developments in SOX, COSO, PCAOB and emerging IT risks .
Desired Experience & Qualification
- Bachelor's degree in Information Systems, Information Technology, Internal Audit or a related field.
- CISA certification will be advantageous.
- 2–4 years' experience in IT Audit, IT SOX, IT Risk, Internal Audit or IT Controls.
- Practical experience performing IT General Controls (ITGC) testing .
- Exposure to IT Application Controls (ITACs), IPE and SOX documentation .
- Experience working with audit, risk or GRC tools.
- Exposure to ERP environments such as Microsoft Dynamics, Sage or similar platforms will be advantageous.
The successful candidate should have knowledge of
- SOX Section 404 requirements
- COSO Internal Control Framework
- IT General Controls (ITGCs)
- IT Application Controls (ITACs)
- Information Produced by the Entity (IPE)
- SOC 1 and SOC 2 reports
- User Access Management
- Change Management
- IT Operations
- Backup and Recovery controls
- SDLC principles
- Microsoft Excel, Word and PowerPoint
- Audit and GRC platforms