Search Remote Jobs

Executive Director, SOX & SOC Compliance

Job not on LinkedIn

🔥 14 hours ago

⚔️ Virginia – Remote

infoinfo

đź’µ $175.1k - $334.8k / year

⏰ Full Time

đź”´ Lead

đźš” Compliance

đź‘» Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of CVS Health

CVS Health

10,000+ employees

Founded 1963

🏥 Healthcare

⚕️ Healthcare Insurance

đź›’ Retail

Healthcare • Healthcare Insurance • Retail

CVS Health is a leading American healthcare company dedicated to improving health access and affordability. The company focuses on a comprehensive approach that includes health services, health insurance, and pharmacy benefits management. Through its subsidiaries, such as Aetna and CVS Caremark, CVS Health offers a range of services that facilitate wellness, condition management, and affordable prescription drug coverage. CVS Health operates neighborhood pharmacies, provides mail-order pharmacy services, and manages specialty medication programs, aiming to make healthcare convenient and accessible for everyone. Driven by a mission to connect people with essential care services, CVS Health is committed to fostering healthier communities and supporting the wellbeing of all individuals.

đź“‹ Description

• Own CVS Health's enterprise SOX cybersecurity/ITGC and SOC 1/SOC 2 compliance programs end-to-end from a first-line perspective • Define control scope, requirements, evidence standards, and readiness activities • Partner with the Controls Assurance Testing (CAT) team to define annual testing scope and calendar • Monitor testing progress, address blockers, and ensure control owners provide evidence and support on schedule • Lead SOC 1 and SOC 2 readiness activities, including control mapping to trust services criteria • Serve as first-line compliance point of contact for Internal Audit and external auditors • Coordinate audit requests, walkthroughs, evidence needs, and issue resolution • Own the control deficiency lifecycle, including root cause analysis, remediation planning, and closure readiness • Maintain SOX and SOC requirements, scoping documentation, and evidence standards in GRC platforms • Drive continuous improvement, evidence reuse, and reduction of duplicative requests • Produce and present executive-level reporting on compliance posture, control readiness, effectiveness, issue trends, and remediation progress • Partner with policy and standards owners on evolving regulatory and framework expectations • Support security exception and risk acceptance processes for SOX- and SOC-relevant control gaps • Lead, coach, and develop the SOX & SOC Compliance team

🎯 Requirements

• 10+ years of progressive experience leading first-line-of-defense SOX ITGC, SOC 1/SOC 2, technology compliance, or control governance programs • 3+ years in a leadership role • 7+ years managing SOX ITGC and SOC 1/SOC 2 compliance programs from a first-line-of-defense perspective • 7+ years with SOX, SOC 1/SOC 2 trust services criteria, PCAOB/AICPA standards, NIST CSF, ISO 27001, and HITRUST CSF • 3+ years with GRC and compliance management platforms such as Optro, Archer, or ServiceNow • 3+ years of people leadership, including building, developing, and retaining a high-performing compliance team • Bachelor's degree in Information Security, Accounting, Information Systems, Risk Management, or a related field, or equivalent professional experience • Relevant certifications such as CISA, CISSP, CISM, CRISC, or CPA preferred • Experience in healthcare, health insurance, pharmacy, or retail industries preferred • Experience supporting regulatory examinations, cybersecurity compliance reviews, and external audit engagements preferred • Familiarity with SEC cybersecurity disclosure requirements and materiality assessment processes preferred • Experience operating within a matrixed, multi-business-unit enterprise preferred • Ability to build and manage cross-functional partnerships preferred • Ability to communicate compliance posture, control readiness, issue status, and remediation progress to executive leadership, Internal Audit, and external auditors preferred

🏖️ Benefits

• CVS Health bonus, commission or short-term incentive program • Equity award program • Medical coverage • Dental coverage • Vision coverage • Paid time off • Retirement savings options • Wellness programs • Other resources supporting physical, emotional, and financial well-being

Apply Now

Similar Jobs

🔥 15 hours ago

Amgen

10,000+ employees

🏥 Healthcare

🧬 Biotechnology

đź’Š Pharmaceuticals

Regulatory Affairs Manager guiding oncology product promotion and FDA compliance at biotech company Amgen. Formulating evidence-based regulatory positions and mentoring promotional reviewers.

🔥 17 hours ago

Marvell Technology

5001 - 10000

🏭 Manufacturing

đź’Ľ Consulting

🏢 Enterprise

Director leading global trade compliance for Marvell’s semiconductor infrastructure solutions. Scaling export, import, customs, sanctions, and technology compliance programs.

🇺🇸 United States – Remote

đź’µ $167.1k - $247.3k / year

đź’° Post-IPO Equity on 2017-01

⏰ Full Time

đź”´ Lead

đźš” Compliance

🔥 18 hours ago

American Cancer Society

5001 - 10000

🏥 Healthcare

đź’Ľ Consulting

🍽️ Food & Beverage

Compliance director leading the American Cancer Society’s enterprise ethics, investigations, training, and risk governance. Fully remote U.S. role supporting a mission to end cancer.

🔥 23 hours ago

Immuneering Corporation

11 - 50

🏥 Healthcare

đź’Ľ Consulting

🎖️ Defense

Regulatory CMC Director leading global submissions and regulatory strategy for Immuneering's oncology therapies. Guiding CMC development, agency interactions, and product lifecycle management.

🇺🇸 United States – Remote

đź’µ $235k - $270k / year

🔥 Funding within the last year

đź’° $200M Post-IPO Equity - Immuneering on 2025-09

⏰ Full Time

đź”´ Lead

đźš” Compliance

đź•’ Yesterday

INSIGHTEC

201 - 500

🏭 Manufacturing

🏥 Healthcare

đź’Š Pharmaceuticals

Director overseeing global compliance and privacy for Insightec’s incisionless medical technology. Managing healthcare-professional compliance, enterprise risk, investigations, and worldwide data-protection programs.