Sarbanes-Oxley (SOX) Governance Consultant

Truist BankCharlotte, NC
Onsite

About The Position

In this role, you will serve as a member of the Technology, Data, and Operations (TD&O) Sarbanes-Oxley (SOX) Governance team, supporting Truist’s TD&O business unit in meeting requirements under Sections 404 and 302 of the Sarbanes-Oxley Act of 2002 and the Federal Deposit Insurance Corporation Improvement Act of 1991. TD&O SOX Governance teammates serve as subject matter experts for SOX IT general controls and act as primary liaisons across TD&O leadership, process and control owners, SOX Program Management (SPM), the Business Execution and Risk Organization (BERO), and internal and external auditors. This role is responsible for coordinating SOX audit-related activities, managing and tracking audit requests, supporting audit readiness, and partnering with TD&O stakeholders to help ensure timely, accurate, and well-supported audit execution. The role also requires openness to learning and responsibly embedding AI-enabled capabilities and identifying automation opportunities to improve the efficiency, consistency, and sustainability of SOX governance processes.

Requirements

  • Bachelor’s degree in Information Technology, Information Security, Engineering, or related field.
  • Minimum of 5 years of professional experience in technology governance.
  • Knowledge of regulatory requirements and compliance frameworks.
  • Experience applying governance assessment methodologies and control frameworks.

Nice To Haves

  • Master’s degree in Accounting, Finance, Information Technology, Information Systems, Cybersecurity, or a related field, or equivalent education and related training.
  • Five or more years of experience performing, overseeing, or managing IT components of SOX audits, including IT general controls, automated controls, key reports, and audit evidence management.
  • Experience working with internal audit, external audit, SOX program management, technology control owners, and risk partners to support audit execution, issue remediation, and control readiness.
  • Strong understanding of technology risk, IT governance, change management, access management, SDLC, cybersecurity, infrastructure, cloud, and data-related control environments.
  • Experience managing audit requests, tracking deliverables, monitoring remediation activities, and communicating status, risks, and escalations to stakeholders and leadership.
  • Proficiency with Microsoft Office and Microsoft 365 collaboration and workflow tools, including Excel, PowerPoint, Word, Teams, SharePoint, and related reporting or automation capabilities.
  • Relevant professional certification, such as CISA, CRISC, CISSP, CISM, CPA, CIA, or similar credential.

Responsibilities

  • Demonstrate knowledge of SOX IT general controls and coordinate with internal and external auditors to manage audit requests, track deliverables, and support timely, accurate audit execution.
  • Partner with TD&O process and control owners, SOX Program Management, BERO, auditors, and other risk partners to support audit readiness, resolve request-related issues, and promote consistent SOX governance routines.
  • Apply technology risk, IT control, and TD&O operational knowledge to evaluate SOX-related matters, advise business and technology partners, and identify practical, risk-informed solutions.
  • Support documentation of SOX issues, development of remediation plans, and monitoring of remediation activities through timely resolution.
  • Identify responsible opportunities to streamline, automate, and enhance SOX governance activities, reporting, audit request management, and related control support processes, including through appropriate use of AI-enabled capabilities.
  • Identifies, assesses, and mitigates technology-related risks to maintain compliance with regulatory requirements and internal policies.
  • Implements and monitors governance processes, controls, and procedures to manage technology risks effectively.
  • Conducts governance analysis, vulnerability assessments, and/or control testing to protect critical technology infrastructure and data.
  • Provides detailed reporting on technology risk posture and compliance status to internal stakeholders.
  • Manages and supports technology governance projects and assignments while collaborating with cross‑functional teams to ensure controls are integrated into technology projects and operations.
  • May support audits or remediation activities by preparing documentation and responding to inquiries related to technology governance.
  • Maintains awareness of industry best practices, regulatory changes, and evolving risk landscapes to update governance strategies.

Benefits

  • medical
  • dental
  • vision
  • life insurance
  • disability
  • accidental death and dismemberment
  • tax-preferred savings accounts
  • 401k plan
  • vacation
  • sick days
  • paid holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service