Job ID 20000D6U
Available Openings 1
PURPOSE AND SCOPE:
Support management of IT SOX compliance and related IT general and application controls at the corporate level and distributed among the FMCNA divisions and locations. Manage the development, implementation and testing of controls for new acquisitions and in-scope entities. Manage the performance of annual internal control testing. Facilitate internal and external IT audits including Financial Statement and Sarbanes Oxley audits. Work with senior management to define remediation/mitigation for internally and externally identified audit and compliance deficiencies and track remediation progress. Assist in the management of the SAP GRC Process Control system used to document and manage financial and IT processes, controls, testing and remediation. Support the SAP access provisioning tool used to request, analyze and approve SAP requests. Assist in the management of SAP roles and the identification and assignment of appropriate SAP role approvers. Provide audit and regulatory guidance, support and subject matter expertise to the IT organization.
PRINCIPAL DUTIES AND RESPONSIBILITIES:
- Perform process and control assessments for new acquisitions and divisions, entities and locations new to the audit scope for potential IT general controls, application controls and process improvements. Assist in the definition of remediation plans, activities and retesting for potential issues and process improvement opportunities.
- Perform assessments of in-scope systems, processes and controls to verify that controls are designed appropriately and operating effectively. Assist in the definition of remediation plans, activities and retesting.
- Facilitate IT management's documentation updates and management assessments of all in-scope FMCNA IT processes based on SOX and audit requirements via meetings with the FMCNA IT Regulatory function and IT management.
- Participate in preparing periodic SOX 404 reporting to the FMC-KGaA SOX 404 Steering Committee.
- Perform the annual SOX 404 scoping exercise to determine if there are any changes to IT data centers, applications or related processes which should be considered to determine what is in scope for SOX 404 purposes.
- Provide regular updates to the department management (VP and Senior Manager) regarding the status of the SOX testing plans, the issues identified, and solutions to address the identified issues or deficiencies.
- With the IT SOX Compliance Senior Manager, serve as the principal interface with the external IT Audit function and the FMCNA IT function regarding SOX IT audit related matters.
- In conjunction with the FMCNA IT Regulatory Compliance function and the IT external auditor, analyze the SOX testing results and work with management to identify, document and test remediation plans for identified deficiencies.
- Responsible for access certifications of financially significant systems, including segregation of duties testing.
- Maintain current knowledge regarding changes to FSA and SOX compliance regulations and ensure that FMCNA adjusts methodologies in response to the changes by issuing guidance and instructions to the appropriate IT stakeholders and personnel. Determine and recommend changes to current controls to address requirement change or issues.
- Play significant role in the implementation of major projects and initiatives related to auditing automation software and applications to manage governance tasks and SOX financial reporting functions, including the implementation of the SAP GRC platform.
- Monitor the SAP provisioning software to ensure that requests with potential risk/violations are appropriately addressed, mitigated or compensated.
- Other duties as assigned.
Additional responsibilities may include focus on one or more departments or locations. See applicable addendum for department or location specific functions.
PHYSICAL DEMANDS AND WORKING CONDITIONS:
- The physical demands and work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- This position will work out of the corporate headquarters in Waltham, MA with on-site meetings also at our IT facility in Lexington, MA. May require 10-20% travel.
- Reporting to IT SOX Compliance Senior Manager
- Supervise SOX Compliance Staff with Senior Manager
- Bachelor's degree in information systems, computer science, business administration.
- Certified Information Systems Auditor or Manager (CISA or CISM) certification preferred.
EXPERIENCE AND REQUIRED SKILLS:
- 8 – 12 years' related experience in an IT audit firm; or a Master's degree with 6 years' experience; or a PhD with 3 years' experience; or equivalent directly related work experience.
- Experience working with or for external audit firm, Big Four IT audit experience preferred
- Experience auditing IT processes, applications and infrastructure (servers, databases, data centers, firewalls, etc.)
- Knowledge of COSO and CoBit control models preferred
- Experience with GRC systems, preferably SAP GRC
- Experience with ERP systems, preferably SAP and PeopleSoft
- Experience with healthcare systems preferably Siemens/Soarian
- Strong interpersonal skills and ability to work with senior level management in an independent manner
- Strong analytical and problem solving skills
- Strong organizational/communication skills
EO/AA Employer: Minorities/Females/Veterans/Disability/Sexual Orientation/Gender Identity
Fresenius Medical Care North America maintains a drug-free workplace in accordance with applicable federal and state laws.
Apply on company website