Sr. ITGC / IT SOX Analyst
hace 11 horas
New York
Job Description Datavant is a data platform company and the world's leader in health data exchange. Our vision is that every healthcare decision is powered by the right data, at the right time, in the right format. Our platform is powered by the largest, most diverse health data network in the U.S., enabling data to be secure, accessible and usable to inform better health decisions. Datavant is trusted by the world's leading life sciences companies, government agencies, and those who deliver and pay for care. By joining Datavant today, you're stepping onto a high-performing, values-driven team. Together, we're rising to the challenge of tackling some of healthcare's most complex problems with technology-forward solutions. Datavanters bring a diversity of professional, educational and life experiences to realize our bold vision for healthcare. What We're Looking For As a Sr ITGC / IT SOX Analyst (GRC) within the Security Governance, Risk, and Compliance (GRC) organization, you will lead implementation, remediation, and ongoing management of Information Technology General Controls (ITGCs) within our organization. This is a hands-on role suited for a self-starter who enjoys solving problems, collaborating cross-functionally, and ensuring compliance excellence in a fast-paced environment.This role will be responsible for ensuring that our IT processes and controls are maintained, compliant with regulatory standards, and aligned with best practices. This role reports to the Sr Manager of IT Assurance (Security GRC) and will work cross-functionally with IT, GRC, Information Security, Finance, and Compliance teams to address any ITGC deficiencies and assessments to drive continuous improvement in compliance programs. What You Will Do • ITGC Program Execution, • Lead and monitor ITGC testing (access, change management, computer operations, backup/recovery, interfaces)., • Execute walkthroughs, control design assessments, and test-of-one/ongoing effectiveness procedures., • Validate completeness and accuracy (C&A) for key reports and data flows; assess IPE., • Controls Design & Remediation, • Advise on control design and documentation (risk/control matrices, narratives, process maps)., • Track deficiencies; partner on root cause analysis and target-state remediation plans., • Independently verify remediation effectiveness and maintain evidence quality., • Stakeholder Management, • Coordinate with external auditors and co-sourced providers; align on scope, reliance, and timelines., • Communicate findings and status to management; escalate risks proactively., • Governance & Continuous Improvement, • Maintain ITGC program artifacts (RACM, population and sample evidence, issue logs)., • Contribute to controls automation, segregation of duties (SoD) governance, and periodic access recertifications., • Support IT policy/standard refreshes and control rationalization., • Assessment Execution, • Perform end-to-end assessment: scoping, risk & control assessments, test plans, fieldwork, and reporting., • Assess IT processes including identity & access management, change/release management, backup/recovery, incident/problem management, vulnerability management, patching, disaster recovery/business continuity, interfaces/integrations, and data quality., • Perform cybersecurity-themed reviews (e.g., endpoint security, logging/monitoring, vulnerability & patch management, configuration baselines)., • Advisory & Continuous Improvement, • Provide practical recommendations that balance risk with operational realities., • Monitor remediation progress; validate closure and sustainment of fixes., • Support integrated audits with operational/financial teams; contribute to annual risk assessment and audit plan., • Reporting & Governance, • Draft clear reports with prioritized findings, risk ratings, and management action plans., • Present results to stakeholders; communicate clearly to technical and non-technical audiences., • 4+ years of progressively responsible IT General Controls experience via IT audit/assurance, SOX 404 testing, or IT risk & controls (Big 4 or industry)., • Hands-on experience testing ITGCs and automated application controls; working with internal and external auditors., • Strong understanding of access management, change management, computer operations, IPE/C&A, and segregation of duties., • Excellent communication skills—you can explain control requirements to engineers and translate technical speak for auditors., • Demonstrated ability to juggle competing priorities in a fast-moving environment., • Strong analytical, organizational, and project management capabilities., • GRC/Audit Platforms: TrustCloud, AuditBoard/SoxHub, • Ticketing Systems: Jira, • Collaboration Tools: Slack, Confluence, • Cloud Platforms: AWS, Azure, GCP, • Proficiency with common ERP systems (e.g., Oracle, NetSuite), • Certifications: CISA, CISSP, CIA, CPA, CRISC (one or more strongly preferred)., • Familiarity with NIST, AICPA / SOC 1 & 2, COBIT, COSO, ITIL, PCI, or ISO 27001., • Technical Exposure to cloud controls (Azure/AWS/GCP), DevOps (CI/CD) controls, and data governance. At Datavant our total rewards strategy powers a high-growth, high-performance, health technology company that rewards our employees for transforming health care through creating industry-defining data logistics products and services. The range posted is for a given job title, which can include multiple levels. Individual rates for the same job title may differ based on their level, responsibilities, skills, and experience for a specific job. The estimated total cash compensation range for this role is:$136,000—$170,000 USD To ensure the safety of patients and staff, many of our clients require post-offer health screenings and proof and/or completion of various vaccinations such as the flu shot, Tdap, COVID-19, etc. Any requests to be exempted from these requirements will be reviewed by Datavant Human Resources and determined on a case-by-case basis. Depending on the state in which you will be working, exemptions may be available on the basis of disability, medical contraindications to the vaccine or any of its components, pregnancy or pregnancy-related medical conditions, and/or religion. This job is not eligible for employment sponsorship. Datavant is committed to a work environment free from job discrimination. We are proud to be an Equal Employment Opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, or other legally protected status. To learn more about our commitment, please review our EEO Commitment Statement here. Know Your Rights, explore the resources available through the EEOC for more information regarding your legal rights and protections. In addition, Datavant does not and will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay. At the end of this application, you will find a set of voluntary demographic questions. If you choose to respond, your answers will be anonymous and will help us identify areas for improvement in our recruitment process. (We can only see aggregate responses, not individual ones. In fact, we aren't even able to see whether you've responded.) Responding is entirely optional and will not affect your application or hiring process in any way. Datavant is committed to working with and providing reasonable accommodations to individuals with physical and mental disabilities. If you need an accommodation while seeking employment, please request it here, by selecting the 'Interview Accommodation Request' category. You will need your requisition ID when submitting your request, you can find instructions for locating it here. Requests for reasonable accommodations will be reviewed on a case-by-case basis. For more information about how we collect and use your data, please review our Privacy Policy.