As a Senior SOX Tester within the SOX Centre of Excellence (CoE), you will be responsible for executing SOX compliance activities across an assigned portfolio building deep end-to-end process knowledge and subject matter expertise while supporting the ongoing maturity of the SOX program.
Working closely with the Team Lead, you will perform and coordinate SOX testing activities, assess control design and operating effectiveness, support control health checks, identify control deficiencies, and assist with remediation efforts. You will partner with control owners and business stakeholders to promote strong control practices, improve SOX awareness, and deliver high-quality and consistent compliance outcomes.
The role will also support the operational development of the SOX CoE through governance reporting, GRC administration, process standardisation, and continuous improvement initiatives, helping establish a scalable, repeatable, and sustainable SOX operating model that supports the organisation's long-term compliance objectives.
Key Accountabilities and main responsibilities
Strategic Focus
- Develop strong knowledge of assigned business processes, risks, controls, and regulatory requirements.
- Support the maturity of the SOX CoE by applying standardised, repeatable, and sustainable SOX practices.
- Contribute improvement opportunities, lessons learned, and insights to enhance program effectiveness.
- Build subject matter expertise within assigned portfolios to support risk identification and control assessment.
- Support SOX planning activities, including risk assessments, scoping reviews, and walkthroughs.
- Contribute to the enhancement of SOX governance, reporting, and GRC capabilities through process improvements, standardisation, and automation initiatives.
Operational Management
- Execute SOX testing activities in accordance with approved methodologies, timelines, and quality standards.
- Conduct walkthroughs and assess control design and operating effectiveness.
- Evaluate supporting evidence and maintain complete, accurate, and audit-ready workpapers.
- Identify testing exceptions, control deficiencies, and documentation gaps, escalating issues where appropriate.
- Support delivery of SOX certification activities and control owner sign-offs, ensuring timely completion and appropriate supporting documentation.
- Facilitate implementation and monitoring of interim mitigating controls to address identified control deficiencies until sustainable remediation is implemented.
- Support remediation activities, root cause analysis, and validation of corrective actions.
- Support external auditor reliance activities, including evidence requests and audit inquiries.
- Perform control health checks and ongoing monitoring activities.
- Prepare governance reporting, dashboards, status updates, and management presentations.
- Maintain risks, controls, testing results, deficiencies, and remediation records within the GRC platform.
- Support GRC administration, enhancements, reporting, and user adoption activities.
People Leadership
- Partner with control owners and business stakeholders to support timely execution of SOX activities and remediation efforts.
- Promote SOX awareness and strengthen understanding of control responsibilities, evidence requirements, and remediation expectations through guidance and knowledge sharing.
- Build effective relationships with control owners, SMEs, risk teams, and auditors
- Support control owners through walkthroughs, testing discussions, remediation activities, and GRC processes.
- Provide guidance and knowledge sharing to junior team members.
- Collaborate across the SOX CoE to drive consistency, knowledge transfer, and continuous improvement.
Governance & Risk
- Ensure testing conclusions are appropriately supported and documented in line with SOX methodology.
- Escalate testing exceptions, control issues, and compliance risks in a timely manner.
- Support deficiency assessment, remediation tracking, and reporting activities.
- Maintain the integrity and quality of SOX documentation, evidence, and governance reporting.
- Support governance forums and stakeholder reporting through preparation of management information.
The above list of key accountabilities is not an exhaustive list and may change from time-to-time based on business needs.
Experience & Personal Attributes
Experience
- Minimum 4-6 years of experience in SOX Compliance, Internal Controls, Internal Audit, External Audit, Risk Advisory, Compliance, or related assurance functions.
- Experience performing control testing, audit procedures, risk assessments, or compliance reviews within a regulated or control-focused environment.
- Good understanding of SOX requirements, COSO principles, and internal control concepts.
- Experience assessing business process controls and/or IT General Controls (ITGCs).
- Experience preparing testing documentation, evaluating evidence, and maintaining audit-quality workpapers.
- Experience supporting issue management, remediation activities, and stakeholder engagement.
- Experience preparing governance reporting, dashboards, and management presentations.
- Experience using Governance, Risk, and Compliance (GRC) platforms.
- Strong proficiency in Microsoft Excel and PowerPoint.
- Exposure to external audit engagements is advantageous.
Personal Attributes
- Strong analytical and problem-solving skills with a risk and control mindset.
- Strong analytical and problem-solving skills with a risk and control mindset.
- High attention to detail and commitment to quality.
- Strong organisational skills and ability to manage competing priorities.
- Effective written, verbal, and presentation skills.
- Strong stakeholder management and relationship-building capability.
- Ability to challenge constructively and communicate control matters confidently.
- Proactive, collaborative, and continuous improvement oriented.
- Demonstrates accountability, integrity, and sound professional judgement.
- Adaptable and resilient in a growing and evolving SOX environment.