- Experience
- 4+ yrs
- Salary
- EUR 56,300 – EUR 93,800 / year
- Openings
- 1
- Posted
- 2 weeks ago
- Work mode
- In office
- Education
- Bachelor's degree
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About McKesson
McKesson is a Fortune 10 company dedicated to improving healthcare by making quality care more accessible and affordable. We emphasize the health, happiness, and well-being of our team and those we serve, fostering a culture of growth, impact, and innovation. Join us as we work together to shape the future of health.
Role Overview
We are seeking a SOX and Compliance Analyst to support governance, risk, and compliance initiatives enterprise-wide, focusing on SAP, Identity Governance, Cybersecurity, and Internal Controls. This role involves managing SAP GRC platforms, supporting SOX compliance, handling user access governance via SailPoint, producing compliance reports, and collaborating with auditors to reinforce control environments.
Key Responsibilities
- Administer and support SAP GRC Access Control and Process Control systems including user provisioning, access requests, emergency access, and Segregation of Duties monitoring.
- Conduct SOX ITGC and automated control testing functions such as gathering evidence, documentation, validation, and issue management.
- Support SailPoint Identity Governance & Administration processes including access reviews, certification campaigns, role management, and provisioning workflows.
- Develop and update cybersecurity compliance dashboards, risk reporting, vulnerability tracking, and executive summaries.
- Collaborate with Information Security teams on remediation of vulnerabilities and control weaknesses.
- Coordinate internal and external audit activities by providing evidence and facilitating walkthroughs and testing as required.
- Monitor control exceptions, drive remediation efforts to closure ensuring compliance with company policies and regulations.
- Identify and implement improvements in governance, compliance, automation, and operational effectiveness within GRC processes.
Qualifications and Experience
- Minimum of 4 years’ experience in IT Governance, Risk & Compliance, IT Audit, SOX Compliance, Cybersecurity Compliance, or Identity & Access Management.
- Bachelor's degree in Information Systems, Information Security, Computer Science, Accounting, Risk Management, Business Administration, or related field; or equivalent experience.
- Proven hands-on administration of SAP GRC Access Control and/or Process Control.
- Experience in SOX controls testing, audit support, evidence gathering, and compliance documentation.
- Familiarity with SailPoint Identity Governance & Administration or similar IAM platforms.
- Knowledge of IT General Controls, access governance, Segregation of Duties, and regulatory compliance standards.
- Experience in cybersecurity compliance reporting, risk metrics, vulnerability management, and security control monitoring.
- Strong analytical, communication, documentation, and stakeholder engagement skills.
Preferred Skills and Certifications
- Experience with SAP S/4HANA and SAP security principles.
- Familiarity with cybersecurity frameworks such as NIST, ISO 27001, COBIT, PCI-DSS, HIPAA.
- Experience with Integrated Risk Management, GRC Automation, or Regulatory Technology solutions.
- Industry certifications like CISA, CRISC, CISSP, CGEIT, SAP GRC, Security+, or SailPoint.
- Skills in developing compliance dashboards and executive reporting.
- Knowledge of vulnerability management systems and remediation tracking.
- Experience handling complex large-scale audit programs.
- Demonstrated success in process improvement and compliance automation.
- Technical expertise with SAP Basis, HANA/Oracle/MSSQL administration, SAP BusinessObjects, Linux and Windows administration.
- Experience with SAP RISE, SAP Business Technology Platform, and other SaaS SAP solutions.
- Competence with cloud platforms like Microsoft Azure and Google Cloud Platform.
- Advanced understanding of Identity and Access Management including SSO/MFA, OpenID, SAML, Kerberos, SPNego, LDAP, Active Directory, Okta, and SAP Identity Provider.
- Privileged Access Management experience in SAP and non-SAP environments including CyberArk.
- Proficiency in Identity Governance and Administration tools such as SAP GRC and SailPoint.
- Experience with SOX/SOC controls at operating system, database, and application levels in diverse environments.
Compensation and Benefits
We offer a comprehensive Total Rewards package to support our employees’ physical, mental, and financial well-being. Our pay range for this role is €56,300 to €93,800, competitive and compliant with applicable regulations. Additional compensation components may include annual bonuses and long-term incentives.
Additional Information
Please be aware of recruiting scams impersonating McKesson. We never request money or credit card information during applications and do not communicate via unofficial email providers or chatrooms. Official job postings are listed on our career site.
Minimum education
Bachelor's Degree
Industry
Hospitals & Health Care