Manager - IT Internal Controls
Novi, MI, US, 48377 Maumee, OH, US, 43537
Job Purpose
The Senior Manager - IT Controls and SOX Compliance will report to the Senior Director - Corporate Accounting and will lead the Company’s IT controls program supporting internal control over financial reporting. This role is responsible for the strategy, execution, documentation, and continuous improvement of IT general controls, IT application controls, IT-dependent business controls, and related SOX compliance activities across the Company’s global systems environment.
The Senior Manager will partner closely with finance, information technology, internal audit, external auditors, business process owners, and global control owners to assess risk, evaluate control design and operating effectiveness, coordinate testing, monitor remediation, and support timely completion of management and external audit requirements. This role will also provide leadership over co-source providers and global stakeholders, promote consistent testing and documentation standards, and identify opportunities to improve the efficiency, quality, and sustainability of the IT controls program.
Job Duties and Responsibilities
IT Controls and SOX Program Leadership
· Lead the Company's IT controls program supporting internal control over financial reporting, including IT general controls, IT application controls, IT-dependent business controls, key reports, interfaces, and financially relevant systems.
· Develop and execute a risk-based annual IT SOX plan, including scoping, risk assessment, control design evaluation, management testing, and documentation requirements.
· Maintain and enhance IT control documentation, including risk and control matrices, process narratives, walkthrough materials, testing procedures, and evidence standards.
· Partner with finance, IT, internal audit, business process owners, and control owners to evaluate the impact of new systems, system upgrades, process changes, and control changes on the SOX program.
Testing, Documentation, and Quality Review
· Oversee the execution of IT control testing, including walkthroughs, design effectiveness assessments, operating effectiveness testing, and review of supporting evidence.
· Manage co-source providers and global testing resources, including budget planning, resource coordination, workpaper review, and evaluation of testing conclusions.
· Ensure control testing is completed timely, consistently, and in accordance with Company methodology, professional standards, and external audit expectations.
· Use data analytics, automated audit tools, GRC platforms, and continuous controls monitoring techniques to improve testing efficiency, evidence quality, and control coverage.
· Coordinate with external auditors on procedures performed to increase efficiency between management testing and external audit testing.
Deficiency Evaluation and Remediation
· Evaluate IT control deficiencies, including root cause analysis, severity assessment, remediation planning, and impact on internal control over financial reporting.
· Track remediation activities and provide timely status updates to finance leadership, IT leadership, internal audit, and external auditors.
· Support the design and implementation of sustainable remediation plans that address control gaps and strengthen the overall control environment.
Job Duties and Responsibilities (cont.)
External Audit and Stakeholder Coordination
· Serve as the primary liaison with the external audit IT team, coordinating requests, evidence submissions, walkthroughs, testing status, findings, and supplementary procedures.
· Coordinate with external auditors to increase reliance on management testing, reduce duplication, and improve audit efficiency.
· Partner with local external audit firms and global management teams to support statutory audit and financial reporting requirements where IT controls or system evidence are relevant.
· Prepare clear and concise status reports, issue summaries, and control-related communications for senior management and other stakeholders.
Governance, Risk, and Continuous Improvement
· Monitor emerging IT risks, system changes, technology initiatives, cybersecurity considerations, and regulatory expectations that may affect financial reporting controls.
· Participate as a stakeholder in key IT initiatives to ensure that financial controls are considered during system design, implementation, and change management.
· Promote consistent IT control practices across global locations and support continuous improvement of the Company's governance, risk management, and control processes.
· Provide training, coaching, and guidance to IT and business control owners to strengthen control awareness and accountability.
Leadership and Team Development
· Lead, mentor, and develop IT controls team members and co-source resources.
· Build strong cross-functional relationships with finance, IT, internal audit, external auditors, and business leadership.
· Foster a culture of accountability, collaboration, continuous improvement, and high-quality execution.
Education and Qualifications
Position Requirements:
· 8+ years of experience in IT audit, IT controls, SOX compliance, internal audit, public accounting, or a related finance/internal controls role.
· Strong knowledge of internal control over financial reporting, Sarbanes-Oxley requirements, COSO framework, IT general controls, IT application controls, and IT-dependent business controls.
· Experience evaluating control design, testing operating effectiveness, reviewing audit evidence, and assessing control deficiencies.
· Working knowledge of ERP environments, preferably SAP and Oracle, including security, change management, IT operations, interfaces, and automated controls.
· Experience coordinating with external auditors, internal audit, IT stakeholders, finance process owners, and global control owners.
· Strong project management skills, including the ability to manage competing priorities, deadlines, global resources, and third-party service providers.
· Excellent written and verbal communication skills, including the ability to explain technical control matters to finance, IT, audit, and senior management audiences.
· Demonstrated ability to lead, coach, and develop team members and co-source resources.
Preferred Qualifications:
· Experience in a public company SOX environment, ideally within a global manufacturing organization.
· Public accounting, Big Four, or large public-company internal audit/SOX experience.
· Professional certification such as CISA, CPA, CIA, CISSP, or equivalent.
· Experience with SAP GRC or similar GRC/compliance tools.
· Experience with data analytics, automated evidence collection, continuous controls monitoring, or audit automation.
· Familiarity with third-party service organization controls, including SOC 1/SOC 2 reports, complementary user entity controls, and bridge letters.
· Exposure to cloud, SaaS, cybersecurity, data privacy, disaster recovery, and business continuity controls.
· Knowledge of PCAOB expectations, ICFR documentation standards, and external auditor reliance strategies.
Required Education:
· Bachelor’s degree in accounting, finance, information systems, or a related field.
· Significant exposure to information technology and financial systems controls is required.
· Advanced degree or professional certification is preferred.
Nearest Major Market: Detroit