Executive Director, SOX & SOC Compliance

CVS HealthWork At Home-Virginia, VA
$175,100 - $334,750

About The Position

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time. Position Summary The Executive Director, SOX & SOC Compliance owns CVS Health's first-line SOX cybersecurity and IT general controls (ITGC) compliance program and SOC 1/SOC 2 readiness and attestation program, ensuring control scope, requirements, and evidence standards meet enterprise, regulatory, Internal Audit, and external audit expectations. Reporting to the AVP, Governance, Risk & Compliance (GRC), this leader manages the SOX and SOC compliance lifecycle as a first-line owner — including control scoping, requirements definition, evidence standards, deficiency management, and readiness for assurance activities — and serves as the primary compliance partner for Finance, Internal Audit, and external auditors on SOX and SOC matters. Control testing for design and operating effectiveness is performed by the Controls Assurance Testing (CAT) team; this role does not execute independent testing directly but sets requirements, engages closely with CAT throughout the testing cycle, and is accountable for the overall compliance outcome. The Executive Director builds and leads a team focused on scoping, evidence governance, audit coordination, and executive reporting, and drives close partnership with CAT to ensure testing is scoped, resourced, and completed on schedule.

Requirements

  • 10+ years of progressive experience leading first-line-of-defense SOX ITGC, SOC 1/SOC 2, technology compliance, or control governance programs, including 3+ years in a leadership role.
  • 7+ years of experience managing SOX ITGC and SOC 1/SOC 2 compliance programs from a first-line-of-defense perspective, including control scoping, requirements definition, evidence standards, deficiency remediation, and coordination with Internal Audit and external auditors.
  • 7+ years of experience with relevant control and framework requirements, including SOX, SOC 1/SOC 2 trust services criteria, PCAOB/AICPA standards as applicable to management readiness and evidence expectations, NIST CSF, ISO 27001, and HITRUST CSF.
  • 3+ years of experience with GRC and compliance management platforms (e.g., Optro, Archer, ServiceNow) for control scoping, evidence management, issue tracking, and executive reporting.
  • 3+ years of experience with people leadership, including building, developing, and retaining a high-performing compliance team.

Nice To Haves

  • Relevant certifications such as CISA, CISSP, CISM, CRISC, or CPA.
  • Experience in healthcare, health insurance, pharmacy, or retail industries with large, complex vendor ecosystems and regulated data environments.
  • Experience supporting regulatory examinations, cybersecurity compliance reviews, and external audit engagements through first-line readiness, evidence coordination, issue management, and partnership with Internal Audit and independent testing functions.
  • Familiarity with SEC cybersecurity disclosure requirements and their intersection with SOX and SOC control environments, and materiality assessment processes.
  • Experience operating within a matrixed, multi-business-unit enterprise (e.g., retail, pharmacy, health services, or similarly complex organizational structures).
  • Demonstrated ability to build and manage effective cross-functional partnerships across first-line control owners, control testing teams, Internal Audit, Finance, and external auditors to drive aligned compliance outcomes.
  • Proven ability to communicate compliance posture, control readiness, issue status, and remediation progress clearly to executive leadership, Internal Audit, and external auditors.

Responsibilities

  • Own the enterprise SOX cybersecurity/ITGC and SOC 1/SOC 2 compliance programs end-to-end from a first-line perspective, including control scope definition, requirements, evidence standards, and readiness activities, in coordination with Finance, control owners, Internal Audit, and external auditors.
  • Partner closely with the Controls Assurance Testing (CAT) team to define the annual testing scope and calendar, ensure testing requirements and evidence standards are clearly understood, and resolve scoping or interpretation questions; engage with CAT throughout the testing cycle to monitor progress, address blockers, and ensure control owners provide evidence and support on schedule.
  • Lead SOC 1 and SOC 2 readiness activities, including control mapping to trust services criteria and coordination with CAT and control owners on evidence collection ahead of attestation testing.
  • Serve as the first-line compliance point of contact for Internal Audit and external auditors on SOX and SOC engagements, coordinating requests, walkthroughs, evidence needs, and issue resolution while channeling testing-related questions to CAT as needed.
  • Own the control deficiency lifecycle from a first-line compliance-program perspective — reviewing CAT's testing results, driving root cause analysis and remediation planning with control owners, and coordinating closure readiness with Internal Audit and external auditors — with clear accountability assigned to control and process owners.
  • Maintain SOX and SOC control requirements, scoping documentation, and evidence standards within GRC platforms (e.g., AuditBoard, Archer), ensuring CAT and control owners are working from current, assurance-ready requirements.
  • Drive continuous improvement of SOX and SOC compliance processes, including evidence-reuse and reduction of duplicative requests to control owners, in partnership with CAT and GRC tooling teams.
  • Produce and present executive-level reporting on SOX and SOC compliance posture, control readiness, tested control effectiveness (sourced from CAT's testing results), issue trends, and remediation progress to AVP GRC, Deputy CISO, and relevant governance forums.
  • Partner with policy and standards owners to ensure SOX and SOC control requirements reflect current regulatory and framework expectations as they evolve.
  • Support the security exception and risk acceptance process for SOX- and SOC-relevant control gaps identified through CAT's testing, ensuring appropriate documentation and executive visibility.
  • Lead, coach, and develop the SOX & SOC Compliance team, building bench strength and a culture of accountability, precision, and strong cross-team partnership with CAT.

Benefits

  • medical
  • dental
  • vision coverage
  • paid time off
  • retirement savings options
  • wellness programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service