Senior IT Audit & Compliance Specialist
Senior IT Audit & Compliance Specialist
Refined job description
ROLE
– Support the annual SOX compliance program, including planning, evidence coordination, deadline monitoring, control‑execution tracking, maintenance of compliance management systems and related repositories, and onboarding of new SOX applications and controls.
– Review compliance evidence and control‑execution documentation for completeness, relevance, accuracy, quality, traceability, and alignment with applicable control objectives.
– Perform independent control evaluations and document conclusions across SOX, Sustainability, Information Security, AI Compliance, and other applicable compliance domains.
– Evaluate IT General Controls, IT application controls, key reports, and Information Produced by the Entity, including coordinating evidence requests and assessing the completeness and relevance of supporting documentation.
– Coordinate with Application Owners, Control Owners, and other stakeholders to obtain appropriate evidence, clarify control execution, resolve documentation gaps, and complete compliance activities within agreed deadlines.
– Track and follow up on deficiencies, findings, remediation actions, audit observations, and related commitments in applicable compliance and remediation tracking systems.
– Track vulnerability‑remediation activities, coordinate follow‑up with responsible stakeholders, and evaluate supporting closure evidence for completeness and adequacy.
– Maintain compliance documentation, procedures, templates, work instructions, training materials, guidance documents, and knowledge repositories.
– Prepare recurring dashboards, management reports, status updates, and summaries covering compliance completion, evidence quality, open findings, remediation progress, overdue actions, and emerging risks or concerns.
– Perform data validation and reconciliation across compliance data sources to support accurate, complete, and reliable reporting.
– Support UAT of changes in GRC tooling.
– Analyze compliance data to identify trends, recurring findings, control‑performance issues, overdue actions, and areas requiring management attention.
– Support annual compliance e‑learning and awareness activities, including tracking completion rates, validating completion data, and coordinating follow‑up where required.
– Support control rationalization, risk assessment, and periodic review activities to help maintain appropriate and risk‑aligned compliance coverage.
– Identify opportunities to standardize, simplify, and automate repetitive compliance activities and support the implementation of appropriate reporting, workflow, and automation improvements.
– Collaborate with global stakeholders across functions, business units, and locations, escalating risks, delays, dependencies, and quality concerns in a timely manner.
REQUIREMENTS
– Bachelor’s degree in Information Technology, Information Systems, Cybersecurity, or a related discipline, or equivalent practical experience.
– Minimum of five years of professional experience in IT audit, IT compliance, risk management, internal controls, information security, or a related GRC function.
– Working knowledge of IT General Controls, IT application controls, audit evidence, control documentation, control execution, and findings and remediation management.
– Experience reviewing evidence and control documentation for completeness, relevance, traceability, and alignment with defined control requirements.
– Experience coordinating compliance, audit, assessment, or remediation activities with Control Owners, Application Owners, auditors, or other business and IT stakeholders.
– Strong analytical skills, including data validation, inconsistency identification, documentation evaluation, and accurate reporting.
– Strong written and verbal communication skills in English.
– Ability to work independently, manage multiple priorities, and appropriately escalate risks, delays, and quality concerns.
– Proactive and accountable work approach with detail‑oriented, structured methodology.
– Ability to manage competing deadlines and follow through on open activities.
– Ability to identify and promptly escalate risks, delays, dependencies, and quality concerns.
– Ability to collaborate effectively with global and cross‑functional stakeholders.
– Commitment to maintaining confidentiality when handling audit, compliance, security, and business information.
– Preferred: Knowledge of SOX compliance, including ITGCs, IT application controls, key reports, and evidence requirements.
– Preferred: Experience in additional compliance domains such as Information Security, Sustainability, AI Governance, regulatory compliance, or technology risk.
– Preferred: Familiarity with frameworks and standards such as NIST SP 800‑53, NIST Cybersecurity Framework, COBIT, ISO 27001, internal control frameworks, or AI governance principles.
– Preferred: Experience working with Internal Audit, External Audit, SOX Controllership, Information Security, or other assurance and governance functions.
– Preferred: Familiarity with tools such as SAP, Workiva, Archer, ServiceNow, Saviynt, Power BI, SharePoint, or equivalent solutions.
– Preferred: Experience supporting compliance process improvement, reporting enhancement, workflow optimization, or automation initiatives.
– Preferred: Professional certification such
Full job description
About the Role
The Senior IT Audit & Compliance Specialist provides operational and analytical support across IT compliance domains including SOX Sustainability Information Security AI Compliance training reporting and compliance administration.
As a senior individual contributor the role independently coordinates compliance activities reviews evidence and control documentation performs control evaluations documents conclusions and drives structured follow-up with relevant stakeholders. The role contributes to the timely completion of compliance activities high-quality and traceable evidence accurate tracking of findings and remediation actions and reliable management reporting.
The position offers broad exposure to global compliance activities emerging governance areas and opportunities to improve and streamline compliance processes.
Key Responsibilities
Experience: 7+ years
Support the annual SOX compliance program including planning evidence coordination deadline monitoring control-execution tracking maintenance of compliance management systems and related repositories and onboarding of new SOX applications and controls.
Review compliance evidence and control-execution documentation for completeness relevance accuracy quality traceability and alignment with applicable control objectives.
Perform independent control evaluations and document conclusions across SOX Sustainability Information Security AI Compliance and other applicable compliance domains.
Evaluate IT General Controls IT application controls key reports and Information Produced by the Entity including coordinating evidence requests and assessing the completeness and relevance of supporting documentation.
Coordinate with Application Owners Control Owners and other stakeholders to obtain appropriate evidence clarify control execution resolve documentation gaps and complete compliance activities within agreed deadlines.
Track and follow up on deficiencies findings remediation actions audit observations and related commitments in applicable compliance and remediation tracking systems.
Track vulnerability-remediation activities coordinate follow-up with responsible stakeholders and evaluate supporting closure evidence for completeness and adequacy.
Maintain compliance documentation procedures templates work instructions training materials guidance documents and knowledge repositories.
Prepare recurring dashboards management reports status updates and summaries covering compliance completion evidence quality open findings remediation progress overdue actions and emerging risks or concerns.
Perform data validation and reconciliation across compliance data sources to support accurate complete and reliable reporting.
Support UAT of changes in GRC tooling
Analyze compliance data to identify trends recurring findings control-performance issues overdue actions and areas requiring management attention.
Support annual compliance e-learning and awareness activities including tracking completion rates validating completion data and coordinating follow-up where required.
Support control rationalization risk assessment and periodic review activities to help maintain appropriate and risk-aligned compliance coverage.
Identify opportunities to standardize simplify and automate repetitive compliance activities and support the implementation of appropriate reporting workflow and automation improvements.
Collaborate with global stakeholders across functions business units and locations escalating risks delays dependencies and quality concerns in a timely manner.
Required Qualifications and Experience
Bachelor’s degree in Information Technology Information Systems Cybersecurity or a related discipline or equivalent relevant practical experience.
Minimum of five years of relevant professional experience in IT audit IT compliance risk management internal controls information security or a related governance risk and compliance function.
Working knowledge of IT General Controls IT application controls audit evidence control documentation control execution and findings and remediation management.
Experience reviewing evidence and control documentation for completeness relevance traceability and alignment with defined control requirements.
Experience coordinating compliance audit assessment or remediation activities with Control Owners Application Owners auditors or other business and IT stakeholders.
Strong analytical skills including the ability to validate data identify inconsistencies evaluate supporting documentation and prepare accurate reports and management updates.
Strong written and verbal communication skills in English.
Ability to work independently as an individual contributor manage multiple priorities and escalate risks delays and quality concerns appropriately.
Preferred Qualifications and Experience
Knowledge of SOX compliance including ITGCs IT application controls key reports and Information Produced by the Entity testing evidence requirements and deficiency remediation.
Experience in one or more additional compliance domains such as Information Security Sustainability AI Governance regulatory compliance or technology risk.
Familiarity with frameworks and standards such as NIST SP 800-53 NIST Cybersecurity Framework COBIT ISO 27001 internal control frameworks or AI governance principles.
Experience working with Internal Audit External Audit SOX Controllership Information Security or other assurance and governance functions.
Familiarity with tools such as SAP Workiva Archer ServiceNow Saviynt Power BI SharePoint or equivalent solutions. Prior knowledge of a specific platform is not mandatory.
Experience supporting compliance process improvement reporting enhancement workflow optimization or automation initiatives.
Professional certification such as CISA or CISSP. Certification is preferred but not mandatory.
Skills and Competencies
Proactive and accountable approach to work.
Strong analytical and problem-solving skills.
Clear and effective stakeholder communication.
Structured and detail-oriented way of working.
Sound professional judgment when evaluating compliance evidence and documentation.
Ability to manage competing deadlines and follow through on open activities.
Ability to identify and escalate risks delays dependencies and quality concerns promptly.
Ability to collaborate effectively with global and cross-functional stakeholders.
Commitment to maintaining appropriate confidentiality when handling audit compliance security and business information.
Success Measures
Success in the role is measured by:
Timely completion of assigned compliance activities.
Complete accurate and traceable compliance documentation.
High-quality evidence and assessment documentation aligned with applicable control objectives.
Accurate tracking and timely follow-up of findings deficiencies remediation actions and audit observations.
Timely escalation of risks delays dependencies and evidence-quality concerns.
Effective collaboration with global stakeholders and Control Owners.
Meaningful contribution to the standardization simplification and continuous improvement of compliance processes.
More information about NXP in India...
#LI-29f4
