Analyst II, Tech Governance & Assurance

LPL FinancialFort Mill, SC
$35 - $59Hybrid

About The Position

We are looking for an experienced IT Risk & Controls professional to join our first line of defense. In this role you will own the day-to-day readiness, testing, and audit facilitation for our IT compliance programs — including SOX, SOC 1, SOC 2, CCPA/CPRA cybersecurity audits, and NYDFS (23 NYCRR 500) attestation. You will partner closely with IT, Engineering, Security, Internal Audit, and external auditors to keep our control environment audit-ready year-round, while driving automation that reduces manual testing effort. This is a hands-on, first-line position: you will be embedded with the control owners, performing self-testing and remediation before controls reach internal audit or external assessors.

Requirements

  • 4+ years of experience in IT audit with hands-on exposure to SOX IT General Control and SOC 1 / SOC 2 engagements.
  • 2+ years of IT General Controls and control frameworks (COSO, COBIT, SOC Trust Services Criteria).
  • 2+ years of experience facilitating audits and managing auditor relationships (external, service auditor, or internal audit).
  • Demonstrated experience with control testing automation or continuous controls monitoring.
  • Excellent documentation, organization, and stakeholder-communication skills.

Nice To Haves

  • Data Analytics or automated control testing experience
  • Familiarity with data privacy and cybersecurity regulations such as CCPA/CPRA and NYDFS 23 NYCRR 500.
  • Relevant certifications: CISA, CIA, CISSP, CRISC, or CPA.
  • Hands-on experience with GRC / audit-automation platforms (e.g., ServiceNow GRC, Archer).
  • Scripting/data skills for automation (SQL, Python, Alteryx, or Power BI).
  • Experience in internal audit or Big four accounting firm.
  • Prior experience in the financial services or banking.

Responsibilities

  • Serve as the primary coordinator for SOC 1, SOC 2, and SOX audits — managing PBC (Provided-by-Client) request lists, evidence collection, walkthrough scheduling, and auditor Q&A.
  • Act as the liaison between control owners and external auditors/service auditors, ensuring timely, complete, and accurate responses.
  • Track audit findings, exceptions, and management responses through to remediation and closure.
  • Perform first-line risk assessments and control self-testing across IT General Controls domains, including logical/privileged access management, change management, SDLC, computer operations (backup, job scheduling, incident management), and data management.
  • Identify control gaps and design deficiencies proactively, and work with owners on remediation plans before formal audit periods.
  • Maintain control narratives, risk-and-control matrices (RCMs), and evidence repositories.
  • Support CCPA/CPRA cybersecurity audit requirements, mapping controls to applicable privacy and security obligations.
  • Prepare and support the annual NYDFS (23 NYCRR 500) certification/attestation process, including evidence gathering and compliance validation.
  • Keep control frameworks aligned to evolving regulatory and industry requirements.
  • Design and implement control testing automation and continuous controls monitoring (CCM) to reduce manual sampling and evidence collection.
  • Build automated evidence pulls, testing scripts, and dashboards using GRC platforms and/or scripting/data tools.
  • Recommend process and tooling improvements that increase testing coverage and efficiency.

Benefits

  • 401K matching
  • health benefits
  • employee stock options
  • paid time off
  • volunteer time off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service