01 Oct
|
Baseel Partners
|
Bengaluru
01 Oct
Baseel Partners
Bengaluru
SOX & IT Compliance Specialist
About the Role
Baseel is a Technology and compliance consultancy company. We work as an extended offshore team for US customers across integration engineering, finance systems, and support.
This role supports one of our US customers, a SaaS company that runs two platforms for its own clients:
- Integration platform: builds, hosts, manages, upgrades, and monitors integrations between many customers' ERP systems and finance applications.
- AI agent platform: hosts AI agents that help finance teams with day-to-day work such as invoice processing, reconciliations, and reporting.
Both platforms touch customers' financial data. That makes them in scope for SOX-related controls, SOC 1 and SOC 2 reports, and customer security reviews. You will be the dedicated compliance resource who keeps these controls working, evidenced, and audit-ready.
Key Responsibilities
SOX and SOC Audit Support
- Own the IT General Controls (ITGC) program: access management, change management, program development, and computer operations.
- Prepare and maintain control matrices (RCMs), narratives, and process flowcharts for the integration and AI platforms.
- Coordinate SOX walkthroughs, PBC (provided-by-client) requests, and evidence collection with internal and external auditors.
- Support SOC 1 Type II and SOC 2 Type II audits from readiness through report issuance.
- Track control deficiencies and exceptions, drive remediation plans, and verify closure.
- Help customers map their own SOX controls to our client's platform through complementary user entity controls (CUECs) and SOC report bridge letters.
Integration Platform Controls
- Review change management for integration builds, upgrades, and code promotions (DEV UAT PROD) to confirm approvals, segregation of duties, and testing evidence.
- Monitor controls over data completeness and accuracy for financial data moving between ERPs, including interface reconciliations,
error handling, and job monitoring.
- Run periodic user access reviews across cloud (AWS), application, and database layers.
AI Platform Governance
- Help design controls for AI agents that act on financial data: human-in-the-loop approvals, audit logging, access boundaries, and change control over prompts and models.
- Support alignment with frameworks such as the NIST AI Risk Management Framework and ISO/IEC 42001.
- Document how AI-generated outputs are reviewed so they can be relied on in customers' financial close and reporting.
Cybersecurity and Broader Compliance
- Maintain security policies and procedures and map them to SOC 2, ISO 27001, and NIST CSF.
- Complete customer security questionnaires, vendor due-diligence requests, and RFP security sections.
- Support vendor and third-party risk assessments, including review of sub-service providers' SOC reports.
- Track compliance with privacy and data-protection requirements such as GDPR and CCPA where they apply.
- Coordinate evidence for vulnerability management, incident response, backup, and business continuity controls.
- Run the compliance calendar and report status and risks to Baseel and client leadership.
Required Qualifications
- Bachelor's degree in Accounting, Finance, Information Systems, Computer Science, or a related field.
- 58 years of hands-on experience in SOX compliance, IT audit, or GRC, at a Big 4 / audit firm, a SaaS company, or a US public company.
- Strong working knowledge of SOX 404, ITGCs, COSO 2013, and the PCAOB audit approach.
- Direct experience supporting SOC 1 and SOC 2 Type II audits, including evidence preparation and auditor coordination.
- Understanding of cloud environments (AWS preferred) and SaaS delivery: IAM, logging, change pipelines, and environment separation.
- Familiarity with ERP and finance processes such as procure-to-pay, order-to-cash, and record-to-report.
- Clear written and spoken English; comfortable leading calls with US auditors, client managers, and security teams.
- Able to work US Eastern Time hours consistently from a home setup with reliable internet and power backup.
Preferred Qualifications
- Certifications: CISA (strongly preferred); any of CISSP, CISM, CRISC, CPA/CA, ISO 27001 Lead Auditor/Implementer, or ISO/IEC 42001.
- Experience with integration or iPaaS platforms and ERPs such as Oracle, SAP, NetSuite, Microsoft Dynamics, Workday, or Coupa.
- Exposure to AI governance, model risk management, or controls over automated decision-making.
- Hands-on use of GRC and compliance tools such as AuditBoard, Vanta, Drata, or ServiceNow GRC.
- Working knowledge of Jira, Confluence, and ticket-based change management.
- Experience writing security policies and answering customer security questionnaires (SIG, CAIQ).
Compensation:
- Full time Role INR 16 lakh per annum
- Immediate start
- This is a Full time consultant role.
- Possibility of onsite travel
Baseel: Baseel Partners LLP (Baseel.com) is a company initially focused on cybersecurity and data protection. Today, Baseel Group has expanded significantly, providing a comprehensive suite of IT services and products to clients in over 100 countries. A distinguished global entity, Baseel Partners LLP has established a robust network of partners across Europe, the UK, Asia, and MENA countries. Baseel has some clients in the area of Data Governance who are looking for MDM implementation.
📌 Sox Auditor (Bengaluru)
🏢 Baseel Partners
📍 Bengaluru