Lead BA Supply Chain Compliance and SOX
McKesson · Irving, TX · Yesterday
Analyst$128k–$213k/yrFull-time
Key Responsibilities
- SOX Compliance & IT General Controls (ITGC)
- Maintain and enhance control documentation (narratives, RCMs, flow diagrams)
- Clock SOX testing activities including walkthroughs and evidence collection
- Identify control gaps and drive remediation to closure
- Ensure ongoing compliance with regulatory requirements
- Audit & Risk Management
- Act as primary liaison for Internal Audit and External Auditors
- Support SOX, SOC, and internal audit engagements
- Track audit findings and remediation activities through resolution
- Provide audit-ready documentation and timely responses to audit requests
- User Access Management & Governance
- Manage user provisioning, de-provisioning, and access changes
- Enforce least privilege and segregation of duties (SoD) policies
- Lead periodic access certifications and reviews
- Support IAM tools (e.g., SailPoint, CyberArk, Okta) and access governance processes
- Process Governance & Continuous Improvement
- Define and standardize IT control and access management processes
- Maintain audit-ready documentation and evidence repositories
- Identify automation opportunities to enhance compliance efficiency
- Improve traceability and control execution consistency
- Stakeholder Engagement
- Collaborate with IT, Security, Finance, and business partners
- Provide guidance on compliance requirements and audit readiness
- Deliver executive-ready reporting on compliance status and risks
- Mentor junior analysts and promote compliance best practices
Qualifications
- Minimum Requirements: Degree or equivalent and typically requires 7+ years of relevant experience.
- Critical Skills: 5+ years of experience in IT compliance, SOX, audit, or business systems analysis; strong knowledge of IT General Controls (ITGC) and SOX frameworks; experience with user access management and segregation of duties; demonstrated experience in regulated environments.
- Preferred Qualifications: Bachelor’s degree in Information Systems, Computer Science, Accounting, or related field; experience with enterprise systems (SAP, Oracle, Workday, IBMi software platforms etc.); familiarity with GRC and audit tools (Workiva, ServiceNow GRC, SailPoint, CyberArk); knowledge of Identity & Access Management (IAM) frameworks; professional certifications: CISA, CISSP, CPA (or equivalent); risk assessment and compliance expertise; strong analytical and problem-solving capabilities; high attention to detail and documentation discipline; ability to influence and lead cross-functional initiatives; excellent communication and stakeholder management skills.