SOX Business Process Controls Testing Lead
United StatesJob Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
The team
Founded in 2011, Kraken is one of the world's longest-standing crypto platforms, trusted by over 10 million individuals and institutions across the globe. It offers spot trading, margin, futures, staking, and OTC services, with products built for both individual investors and institutional clients.
Payward’s Risk & Audit function operates as an Integrated Assurance organization, bringing together Internal Audit and Enterprise Risk Management under a unified risk oversight strategy. The function spans SOX Compliance, Enterprise Risk Management, and Internal Audit across multiple regulated entities and jurisdictions. The team partners with co-sourced providers, maintains direct reporting lines to the Global and Local Audit Committee Chairs, and is building a technology-forward assurance capability at the forefront of crypto and financial innovation.
This role sits within Internal Audit and will lead the independent testing of business process SOX controls. You will assess whether controls over revenue, financial close, and treasury are designed and operating effectively, providing the assurance that the Audit Committee, external auditors, and regulators rely on.
The opportunity
You will lead Internal Audit’s business process SOX controls testing program, building the testing approach, workpapers, and institutional knowledge from the ground up. This is a hands-on role with real program ownership and you’ll be doing it at a crypto exchange — where revenue includes digital asset trading, staking, and custody fees, where treasury manages both fiat and crypto assets, and the financial reporting landscape is evolving in real time. If you want a SOX role where the accounting is interesting and the controls are consequential, this is it.
Responsibilities span the following areas:
SOX business process controls testing
- Lead the execution of independent controls testing across business process areas including revenue, financial close, and treasury.
- Evaluate the design and operating effectiveness of key controls, document testing procedures and results, and ensure workpapers meet Internal Audit and external auditor quality standards.
- Validate the completeness and accuracy of Information Used in Controls (IUC) and Information Produced by the Entity (IPE), ensuring the reliability of data underpinning control performance.
- Build and maintain testing programs, templates, and workpapers that create a repeatable, scalable foundation for business process SOX testing.
- Identify opportunities to leverage AI-enabled workflows and data analytics to improve testing coverage and efficiency.
Remediation validation & issue management
- Independently validate the remediation of open SOX findings, including material weaknesses and significant deficiencies, across business process control areas.
- Evaluate control deficiencies by performing root cause analysis and assessing the severity and pervasiveness of exceptions to inform deficiency classification.
- Assess whether management’s remediation actions are adequately designed and operating effectively before closing findings.
- Track remediation progress, escalate delays or gaps, and report status to Internal Audit leadership and the Audit Committee as required.
- Coordinate with the SOX Compliance team to ensure alignment on remediation expectations, timelines, and evidence requirements.
Stakeholder engagement & reporting
- Serve as a trusted Internal Audit point of contact for business process control owners across Finance, Accounting, and Treasury.
- Contribute to Internal Audit reporting to the Audit Committee, external auditor, and senior leadership on business process SOX testing coverage, findings, and remediation status.
- Partner with the IT SOX tester and co-sourced resources to ensure coordinated testing coverage across the full SOX program.
What you bring
- 8+ years of experience in internal audit, external audit, or SOX compliance, with significant exposure to business process controls testing.
- CPA or ACCA certification required.
- Experience in crypto, fintech, payments, or digital asset accounting — including revenue recognition for trading, staking, or custody services.
- Strong knowledge of US GAAP, SOX compliance requirements, COSO framework, and PCAOB auditing standards as they apply to business process controls.
- Hands-on experience testing controls across revenue, financial close, treasury, or other core financial reporting processes.
- Experience operating across multi-entity structures or multiple jurisdictions.
- Effective communicator who can translate audit findings and control observations for control owners, senior leadership, and external stakeholders.
Nice to haves
- Familiarity with audit management platforms such as AuditBoard or Workiva.
- Exposure to global regulatory environments and multi-entity control structures.
- Familiarity with AI-assisted audit tools and willingness to adopt emerging technologies.
How would you rate this job post?
See what other professionals think about this role.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.