Manager, IT SOX PMO
United StatesJob Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
An overview of this role
As the Manager, IT SOX PMO, you'll own information technology (IT)-specific Sarbanes-Oxley (SOX) compliance activities and serve as a subject matter expert for IT general controls (ITGCs) and IT application controls (ITACs). You will be an individual contributor, reporting to the Senior Director, SOX PMO Leader within the Chief Accounting Officer's organization, you'll directly support the Senior Manager, IT SOX PMO in strengthening GitLab's IT SOX program, preparing new and changing processes and systems for SOX requirements, and advancing automation in a high-growth technology environment. You'll combine strategic guidance with hands-on execution by improving current processes, assessing emerging technologies for SOX impact, and applying practical, scalable control practices.
What you’ll do
- Serve as an IT SOX subject matter expert for ITGCs and ITACs, providing guidance and supporting compliance with SOX requirements.
- Partner with the business SOX Program Management Office (PMO) to assess SOX readiness for new or changing systems and business processes, and support the annual IT SOX risk assessment.
- Maintain and improve control documentation, including flowcharts, risk and control matrices, and control inventories.
- Facilitate IT control walkthroughs and coordinate the remediation of control deficiencies.
- Coordinate with internal and external auditors throughout the SOX audit cycle, clearly presenting positions and supporting appropriate conclusions.
- Review System and Organization Controls (SOC) reports and oversee the key report testing program with contractor support, performing hands-on testing when needed.
- Build cross-functional relationships, including a close partnership with Internal Audit on SOX testing execution.
- Identify opportunities for control automation, monitor emerging risks and regulatory changes, including those related to artificial intelligence (AI), and help prepare reports and presentation materials on SOX compliance status.
What you’ll bring
- A bachelor's degree in information technology, computer science, accounting, or a related field.
- IT audit and SOX compliance experience, including deep knowledge of ITGCs, ITACs, and control frameworks such as Control Objectives for Information and Related Technologies (COBIT) and the Committee of Sponsoring Organizations of the Treadway Commission (COSO) framework.
- A current Certified Information Systems Auditor (CISA), Certified Public Accountant (CPA), Certified Internal Auditor (CIA), or Certified Information Systems Security Professional (CISSP) certification.
- Experience working in the software as a service (SaaS) industry.
- Proficiency with governance, risk, and compliance tools; experience with AuditBoard is a plus.
- Professional judgment, critical thinking, and clear written and verbal communication skills, including persuasion, influence, and conflict resolution.
- A practical and creative approach to complex problems, audit findings, and recommendations, with familiarity using AI tools to improve compliance processes.
- Ability to collaborate effectively across US Pacific and Eastern time zones.
About the team
The SOX PMO team is a second-line function within GitLab's Chief Accounting Officer organization. It owns and manages the enterprise SOX compliance program across risk assessment, control design, documentation, and coordination with external auditors, while Internal Audit operates as the independent third-line function responsible for SOX testing. The team serves as both a subject matter expert group and a business partner to first-line control owners across GitLab, helping build control frameworks that are practical, scalable, and suited to a fast-growing business. As an all-remote team, we collaborate asynchronously across regions and functions, balancing strategic program leadership with hands-on execution as GitLab continues to evolve.
How would you rate this job post?
See what other professionals think about this role.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.