CVS Health Logo

CVS Health

Senior Analyst, Corporate IT SOX Audit

Posted 4 Hours Ago
Be an Early Applicant
In-Office or Remote
44 Locations
Senior level
In-Office or Remote
44 Locations
Senior level
Participate in annual IT SOX audit execution, perform and document ITGC testing, create workflows and work papers, report findings, lead test areas, mentor junior auditors, and recommend process improvements to strengthen IT compliance and controls.
The summary above was generated by AI

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.

Position Summary:
The Senior Analyst, Corp IT Audit will be a key member of the Technology Controls Assurance (TCA) Internal Audit team and will participate in the execution of the annual Sarbanes-Oxley (SOX) internal audit, and promote collaboration with our business partners, external auditors, and management. The position assists with the annual planning process and execution of the ITGC SOX program. This role will be responsible for continually evaluating and recommending operational and process improvements to our IT compliance processes, and the efficiency and effectiveness of the company’s key control structure. This role is responsible for delivering high quality IT SOX internal audit results under the direction of the TCA Manager +.

Primary Job Duties & Responsibilities:

Audit Project Management

  • Effectively perform and document IT SOX audit activities in accordance with professional standards and the organization’s
  • audit methodology.
  • Execute testing and create work paper documentation.
  • Understand procedures, results and business impacts; and document and express such understanding in both written and verbal form.
  • Perform detailed review testing to analyze and validate information and provide constructive feedback to preparers to enhance the quality of testing work papers.
  • Demonstrate the ability to accurately document ITGC process workflows and data flows.
  • Create clear and accurate documentation and workflows of technology processes and test results and exceptions.
  • Work in a fast-paced, collaborative setting with cross-functional teams.
  • Lead individual project components and testing areas; oversee the work of more junior auditors and/or interns.

Audit Reporting/Communication

  • Independently collect facts, utilize strong analytical capabilities to recommend appropriate actions on complex matters, and effectively communicate status and results in a concise, timely manner.
  • Reports related audit findings to audit and business stakeholders.
  • Interacts with various levels of Internal Audit and business line management to resolve issues in a timely manner and to maintain effective communications.
  • Consider SOC reporting and other compliance impact for controls which are tested once and applied for other compliance purposes. 

Audit Team Support

  • Meets administrative reporting requirements and supports department initiatives.
  • Demonstrates a commitment to integrity and the company code of conduct, and a respect for diversity and inclusion.
  • Contribute to overall Internal Audit Department team norms to promote a positive environment and improve team effectiveness.
  • Keep current of relevant technology developments and evolving IT risk areas.

 

Required Qualifications:

  • 2+ years’ experience in IT SOX Audit, IT SOX Compliance, Control Validation, Risk Assessment, or Risk Consultant role.
  • Ability to travel up to 10%.
  • Must be willing to work 8:00am-5:00pm EDT or CDT.

Preferred Qualifications:

  • Professional designations such as CPA, CIA, CISA etc., or progress towards achieving such designations.
  • In-depth knowledge and understanding of Sarbanes Oxley regulation including its requirements, regulations, and implications for financial reporting and internal controls.
  • Prior experience in strategizing, planning, and developing technology audit project plans.
  • Healthcare, Insurance, or Retail industry business practices and risks.
  • Familiarity with Cloud environments and data classification and protection concepts. IT processes - including applications and infrastructure, security and vulnerability assessments, change control, asset management, disaster recovery, data privacy, and IT risk assessment, automated control environments, cybersecurity best practices, cloud security controls etc.
  • Familiarity with the following concepts: Information Risk Frameworks (NIST 800-53, COBIT 5, ISO/IEC 27001/2, HITRUST, PCI DSS), eGRC tools, and IIA Standards, Data Privacy regulations and industry standards (e.g. HIPAA, GDPR, CCPA).
  • Good teamwork and collaboration skills.
  • Strong oral/written communication, critical thinking, problem resolution and interpersonal skills with proven ability to influence and collaborate with external and internal partners at all levels.
  • Excellent analytical and problem-solving abilities.
  • Ability to work independently and manage multiple priorities.
  • Detail-oriented with a high level of integrity and professionalism.
  • Practical knowledge of processes, risks, and internal controls.

Education:

  • Bachelor's Degree or equivalent experience (HS diploma + 4 years relevant experience).

Anticipated Weekly Hours

40

Time Type

Full time

Pay Range

The typical pay range for this role is:

$46,988.00 - $122,400.00

This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls.  The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors.  This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. 
 

Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.

Great benefits for great people

We take pride in our comprehensive and competitive mix of pay and benefits – investing in the physical, emotional and financial wellness of our colleagues and their families to help them be the healthiest they can be. In addition to our competitive wages, our great benefits include:

  • Affordable medical plan options, a 401(k) plan (including matching company contributions), and an employee stock purchase plan.

  • No-cost programs for all colleagues including wellness screenings, tobacco cessation and weight management programs, confidential counseling and financial coaching.

  • Benefit solutions that address the different needs and preferences of our colleagues including paid time off, flexible work schedules, family leave, dependent care resources, colleague assistance programs, tuition assistance, retiree medical access and many other benefits depending on eligibility.

For more information, visit https://jobs.cvshealth.com/us/en/benefits

We anticipate the application window for this opening will close on: 03/14/2026

Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.

Top Skills

Automated Control Environments
Ccpa
Cloud Environments
Cloud Security Controls
Cobit 5
Data Classification And Protection
Egrc Tools
Gdpr
Hipaa
Hitrust
Iia Standards
Iso/Iec 27001
Iso/Iec 27002
It General Controls (Itgc)
Nist Sp 800-53
Pci Dss
Soc Reporting

Similar Jobs

29 Minutes Ago
Remote
USA
Entry level
Entry level
Insurance • Financial Services
The Agent Concierge Representative assists new captive insurance agents in preparing for licensing exams and maintains communication throughout their preparation process to ensure successful completion.
Top Skills: ExcelMs AccessMS Office
32 Minutes Ago
Remote
United States
Senior level
Senior level
Artificial Intelligence • HR Tech • Information Technology • Software • Business Intelligence
Drive partner-sourced and co-sold revenue by developing strategic partner GTM plans, managing partner deal cycles and pipeline (forecasting, MEDDICCC), enabling partner sellers, collaborating cross-functionally, and ensuring partner accountability to hit sales targets.
33 Minutes Ago
Easy Apply
Remote
United States of America
Easy Apply
Junior
Junior
Cloud • Information Technology
Manage and close SMB opportunities through channel partners and outbound prospecting. Qualify leads, maintain pipeline and forecasts, upsell/cross-sell, capture CRM data, and collaborate with Channel Account Managers to drive revenue.
Top Skills: Cloud StorageOutreachSalesforce (Sfdc)

What you need to know about the Ottawa Tech Scene

The capital city of Canada and the nation's fourth-largest urban area, Ottawa has proven a rapidly growing global tech hub. With over 1,800 tech companies, many of which are leaders in their sectors, the city's tech talent now makes up more than 13 percent of its total workforce. This growth is driven not only by the big players like UL Solutions and Dropbox, but also by a thriving startup ecosystem, as new businesses emerge to follow in the footsteps of those that came before them.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account