58 years of relevant experience in Internal Audit, SOX/K-SOX, Internal Controls, ICFR or Risk & Compliance.
Job Overview
We are looking for an experienced K-SOX / Internal Controls Auditor to support the evaluation and strengthening of the Companys internal control framework. The candidate will be responsible for assessing financial and IT controls, identifying control gaps and supporting timely remediation.
Key Responsibilities
Perform SOX/K-SOX and ICFR control testing and evaluate the design and operating effectiveness of controls.
Conduct process walkthroughs and prepare/review Risk Control Matrices (RCMs).
Assess controls in key finance and business processes including P2P, O2C, R2R, Inventory, Fixed Assets, Treasury and Financial Reporting.
Evaluate Entity Level Controls (ELC) and Process Level Controls (PLC).
Review and test IT General Controls (ITGC), including user access, change management and segregation of duties.
Identify control deficiencies, document audit findings and coordinate with process owners for remediation and closure.
Support internal and external auditors during SOX/K-SOX assessments.
Assist in implementation and monitoring of group-level and common controls across subsidiaries.
Ensure appropriate audit documentation and evidence are maintained.
Required Knowledge & Skills
Strong understanding of COSO Internal Control Framework.
Practical knowledge of SOX / K-SOX and ICFR.
Understanding of ELC, PLC and ITGC.
Experience in internal control testing and RCM preparation.
Valuable knowledge of financial reporting and accounting processes.
Exposure to ERP/SAP controls will be an advantage.
Strong analytical, documentation and communication skills.
Preferred Certifications
CISA Certified Information Systems Auditor
ISO 27001 Lead Auditor / Lead Implementer
COSO Internal Control Framework certification/training
CSOX / K-SOX / SOX certification or relevant practical experience
CIA / CA / CPA / CMA will be an added advantage.
Preferred Candidate Profile
Candidates with hands-on SOX/K-SOX experience, combined with knowledge of COSO, CISA/ITGC and ISO 27001, will be preferred.
Practical experience in internal control testing and remediation will be given more importance than certifications alone.