Professional, SOX Lead
PharmaMedTechRegulatory AffairsQuality Assurancecroraveinformsapazureaws
Job description
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit. Job Function: Technology Enterprise Strategy & Security Job Sub Function: Security & Controls Job Category: Scientific/Technology All Job Posting Locations: New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raritan, New Jersey, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America Job Description: DePuy Synthes is recruiting for a Professional, SOX Lead, located in New Brunswick, NJ or West Chester, PA or Palm Beach Gardens, FL or Warsaw, IN or Raynham, MA or Raritan, NJ. Job Overview The Professional, SOX Lead is a seasoned individual contributor within the Cybersecurity function, GRC, IT Controls & Cyber Culture sub-function, accountable for the design, execution, and continuous improvement of the IT General Controls (ITGC) and IT Application Controls environment supporting SOX compliance for DePuy Synthes. This role establishes control testing methods based on proven assurance frameworks, evaluates the reliability and effectiveness of internal information systems controls, and partners across IT, Finance, Internal Audit, and external auditors to ensure a clean, defensible control environment. The role applies advanced skills in IT controls and assurance to build industry-leading control practices, and contributes to compliance and remediation programs under general direction. Key Responsibilities Lead the annual SOX IT scoping, risk assessment, and control rationalization exercise across in-scope applications, databases, operating systems, and infrastructure, with direct impact on the achievement of assurance results. Design, document, and maintain ITGC frameworks covering access to programs and data, change management, program development, and IT operations, ensuring alignment with COSO, COBIT, and PCAOB expectations. Plan and execute walkthroughs, control design assessments, and operating effectiveness testing; evaluate results and perform root cause analysis on identified deficiencies. Serve as the primary liaison for external auditors and Internal Audit for all IT-related SOX requests, coordinating PBC (Prepared by Client) deliverables, evidence submission, and issue resolution. Assess and communicate the severity of control deficiencies (deficiency, significant deficiency, material weakness), and drive remediation plans with control owners through to validated closure. Partner with Identity & Access Management and Identity Governance & Administration teams to strengthen user access provisioning, periodic access re-certification, privileged access, and segregation of duties (SoD) controls. Evaluate the SOX control impact of ERP and technology change initiatives — including system implementations, migrations, upgrades, and separation/carve-out activity — and define control requirements prior to go-live. Establish and monitor key control metrics, dashboards, and reporting to provide leadership visibility into control health, testing progress, and remediation status. Assess the control implications of third-party and cloud service providers, including review of SOC 1 / SOC 2 reports and evaluation of complementary user entity controls (CUECs). Interpret evolving regulations as they pertain to information systems, platforms, and IT operating processes, and translate requirements into practical control standards and procedures. Drive automation and continuous controls monitoring opportunities to improve testing efficiency, reduce manual effort, and increase control coverage. Develop and deliver training and awareness materials to control owners, strengthening compliance ownership and cyber culture across the IT organization. Maintain complete and audit-ready documentation including narratives, process flows, RACM (Risk and Control Matrix), test scripts, and evidence repositories. Qualifications Education Bachelor's degree in Information Technology, Computer Science, Accounting, Information Systems, Finance, or a related discipline. Advanced degree or equivalent professional experience in cybersecurity or information systems (preferred). Experience and Skills Required: 6+ years of progressive experience in IT audit, IT controls, SOX compliance, or technology risk and assurance, including hands-on ITGC design and testing. Demonstrated expertise across the four ITGC domains: logical access, change management, program development, and IT operations. Working knowledge of COSO 2013, COBIT, PCAOB auditing standards, and SOX 404 requirements. Experience testing controls over ERP platforms (e.g., SAP, Oracle) and supporting databases, operating systems, and infrastructure layers. Proven ability to assess deficiency severity, articulate risk to non-technical stakeholders, and drive remediation to closure. </ul
Stand out for this role
NoxPharm tailors your CV to this job description by aligning your experience with the role requirements and terminology. Built for pharma & life sciences.
Tailor my CV now — free to trySimilar Pharma jobs
Technical Sales Manager APJ-Applied Analytical Technologies
Thermo Fisher Scientific — Seoul, Korea, Republic of
Team Leader
Thermo Fisher Scientific — Tilburg, Netherlands
Data Analytics Developer
Thermo Fisher Scientific — Quezon City, Philippines
Quality Operations Specialist
Thermo Fisher Scientific — Cincinnati, Ohio, USA
Director Labs - Bioanalytical LCMS Research and Development
Thermo Fisher Scientific — Richmond, Virginia, USA
Senior Manager, Make/Buy Strategy & Execution
Thermo Fisher Scientific — Morrisville, North Carolina, USA