IT SOX Controls Specialist
Stripe•3h ago
United StatesOnsiteFull-time
H-1B sponsor
- Who we are
- About Stripe
- Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue
- accelerate new business opportunities. Our mission is to increase the GDP of the internet
- we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.
- About the team
- Finance is the strategic engine that drives rigorous decision making and acts as the financial stewards of Stripe's businesses - and we'd like your help. Stripe is building a world class Controllership team
- is responsible for the corporate SOX program. Stripe is seeking a bar-raising IT SOX Controls Specialist to join its SOX team. This growing team is responsible for the global implementation and operation of Stripe's SOX program. We seek a candidate that is excited by the challenge of working for a hyper-growth company that is focused on expanding the economic infrastructure of the internet.
- What you’ll do
- The IT SOX Controls Specialist is a key member of Stripe's SOX Compliance function within the Chief Accounting Organization, building confidence for our investor community through a strong and scalable SOX program. In this role, you will own the design, implementation
- monitoring of controls over third-party applications and service providers that impact Stripe's financial reporting. You will work closely with business process owners, IT, Procurement
- Vendor Management teams, reporting to the Head of SOX Compliance.
- Responsibilities
- Own the end-to-end SOX assessment lifecycle for third-party applications in scope for financial reporting, including identification, risk tiering, and control mapping
- Lead the evaluation and review of third-party SOC 1 and SOC 2 reports (SSAE 18 / ISAE 3402), assessing complementary user entity controls (CUECs) and identifying gaps that require compensating controls at Stripe
- Design and implement controls to address risks arising from third-party systems and integrations that impact the financial reporting supply chain
- Develop and maintain SOX-ready documentation for third-party control environments, including risk and control matrices (RCMs), narratives, and process flow diagrams
- Project manage control definition and implementation for new third-party system implementations, migrations, and integrations with financial reporting impact
- Partner with IT, Procurement, and business stakeholders to embed control requirements into the vendor onboarding and periodic review process
- Review IPE (Information Produced by the Entity) sourced from third-party systems for completeness and accuracy
- Assess and track control deficiencies identified through third-party reviews, coordinating root cause analysis and corrective action plans with relevant process owners
- Support the 302 and 404 sub-certification process as it relates to third-party application risks and controls
- Monitor the third-party application landscape for emerging financial reporting risks as Stripe scales, and proactively develop control plans to address them
- Contribute to ongoing SOX program improvements, including automation and optimization of third-party control monitoring
- Who you are
- We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
- Minimum requirements
- Bachelor's degree; Master's degree a plus in Accounting, Information Systems, Finance, or related field
- Technical certification required (e.g., CPA, CIA, CISA, PMP)
- 10+ years of work experience in managing and/or assessing SOX programs
- Big 4 audit firm or equivalent audit experience
- Developed expertise and extensive experience with leading and performing SOX business process program design, control implementation, and monitoring of SOX program
- Hands-on experience evaluating third-party SOC reports (SOC 1 / SOC 2) and assessing CUEC coverage and gaps
- Familiarity with IT general controls and application-level controls in the context of financial reporting systems
- Strong knowledge of technical accounting, order to cash, and financial close & reporting controls
- Strong communication skills, including presenting to and influencing senior business leaders
- Demonstrated success managing concurrent workstreams/projects independently
- Preferred qualifications
- Experience in implementing internal controls in early-stage public companies is strongly preferred
- Experience with an online payments company, ecommerce, SaaS, Payments, Fintech, or Financial Services industries is desirable
- Experience working with JIRA and AuditBoard is a plus
- Familiarity with third-party risk management (TPRM) frameworks and vendor risk programs is a plus