< Back to job list

IT Compliance Sr. Analyst (SOX)

Charlotte, NC, United States

Ref#: 1084285

Date published: 26-Feb-2015

Share with: Facebook Twitter Viadeo Send to a friend

Position Summary:

Charlotte, N.C.-based Belk, Inc. (www.belk.com) is the nation’s largest family owned and operated department store with more than $4 billion in sales and 300 Belk stores located in 16 Southern states and a growing digital presence on belk.com. Founded on May 29, 1888 by William Henry Belk in Monroe, N.C., the company is in the third generation of Belk family leadership. Our mission is to satisfy the modern Southern lifestyle like no one else, so that customers get the fashion they desire and the value they deserve. Our vision is for the modern Southern woman to count on Belk first – for her, for her family, for life. Belk has been committed to community involvement since its inception and today gives 2.5 percent of its pretax income back to the communities it serves. During the past fiscal year the company and its associates, customers and vendors donated more than $20.9 million to those communities.

Essential Functions/Responsibilities:

The IT Compliance Sr. Analyst (SOX) will be responsible for assisting the Manager of Compliance in both daily and long-term administration of the IT Compliance Program. They will also assist and lead various compliance related initiatives, including developing conceptual ideas into actionable implementation plans, monitoring, analyzing and execution of compliance projects based on requirements including but not limited to PCI, HIPAA, SOX, SANS, COBIT, ITIL, etc. This position helps facilitate the creation of many of these initiatives as well as the regular operation of the activities defined.

 

This role is also one that requires an ability to work independently and build and maintain strong working relationships with Belk IT service providers and business users.  The Compliance Analyst must be sensitive to the business and contractual relationships that Belk IT has with these organizations. The Compliance Analyst’s role requires tact, diplomacy, and strong written and verbal communication skills to address audiences from entry level to executive employees.  The Compliance Analyst must demonstrate critical thinking skills, sound judgment, and an ability to influence others over whom there is no direct authority.

 

Project management experience managing multiple tasks and projects simultaneously will be critical to the professional’s success. A background in the retail industry is strongly encouraged.

Responsibilities & Essential Functions

·         Acts as a subject matter expert for IT Compliance items. Assists with the administration and maintenance of policies and procedures for effective compliance management for all applicable IT related rules and regulations.

·         Creates and monitors systems and management processes for effective compliance reporting and remediation.

·         Manages audits and remediation activities to ensure ongoing regulatory processes are followed.

·         Collaborates with internal customers including HR, Finance, Internal Audit, users, staff members, and IT colleagues to assist in the definition, development, and documentation of compliance related business requirements; objectives; deliverables; and specifications for projects and activities.

·         Manages scheduled and non-scheduled audits and reviews IT processes to ensure compliance with mandated service levels (all high/critical patches within 30 days of patch release). Must lead resolution teams to address any non-compliance items.

·         Work closely with the Change Management process and applicable parties to ensure SOX, PCI and Internal Controls compliance and minimize change risks of IT production environment and report situations of non-compliance.

·         Enforce policies, standards and processes for information security and business continuity.

·         Support the use of software and other tools, to manage security and business continuity objectives.

·         Maintain contact with and represent Belk in professional organizations, industry groups, and local/regional emergency response groups as appropriate.

·         Implement and support Identity and Access Management processes and tools for Belk.

·         Develop roadmaps, strategies and project lists to achieve IT Compliance objectives.  Manage these projects to achieve these objectives on time and on budget.

·         Ensure systems, databases, applications, and IT processes comply with all SOX IT General Computing Controls (GCC)

·         Implement new SOX requirements, working closely with IT management and Internal Audit staff

·         Manage segregation of duties (SOD) monitoring processes and controls, identify mitigating controls, and ensure compliance with company policies

·         Support new system implementation and ensure compliance with existing policies

·         Provide guidance and facilitate understanding of SOX and compliance controls throughout the IT organization

·          Performs other duties as assigned.

·         Special projects and other duties as assigned.

·         All employees are expected to be in compliance with government and corporate laws, rules, regulations, policies, and procedures

Requirements/Qualifications:

Education, Training, and/or Certifications:

Minimum Required:

· Bachelors degree and/or equivalent years of experience

· Specific Degree: in Accounting, Information Systems, Business Administration, Computer Science or other relative Technical Degree

· Specific Certifications: CPA, CISSP, CISM, CIA

Experience:

Minimum Required:

· 2 or more years of applicable experience

· 3+ Years specific work or project experience: IT SOX Control Auditing

· Industry experience: Retail

· Preferred:

· 2 or more years of applicable experience

· 5+ years specific work or project experience: External Audit, Internal Audit, Consulting

Knowledge, Skills, and Abilities:

Minimum Required:

· Bachelor’s Degree in Accounting, Information Systems, Business Administration, Computer Science or other relative Technical Degree

· At least 3 years’ experience in Information Technology

· Experience performing enterprise risk management, risk identification, risk assessment, and risk mitigation.

· Familiarity with the following:

· Strategies and techniques for network security and intrusion detection.

· Strategies and techniques for enterprise identity and access management.

· Strategies and techniques for meeting compliance objectives.

· Strategies and techniques for end user awareness.

· Proficient in the use of Microsoft Office Products: Word, PowerPoint, Excel and Project

· Proficient in the use of Auditing Software: IDEA, ACL, etc…

· Excellent verbal and written communication and presentation skills

· Ability to interface with executives as necessary

· Strong interpersonal and communication skills.

· Ability to manage activities performed by multiple 3rd parties.

· Ability to properly tailor communication to and work effectively with both business and technical teams.

· Strong troubleshooting and problem solving skills.

· Ability to think and act both strategically and tactically.

· Ability to effectively multi-task.

For reasonable accommodation information for an ADAAA qualified disability please see Belk Associate Handbook for policy and procedures.