yoinka

Executive Director, SOX & SOC Compliance

CVS Health

RemoteVA - Work from homeStaff
Sign in to applyVerified 1h ago
Location
VA - Work from home
Work model
Remote
Level
Staff
Posted
Sep 2, 2026

Skills

Cybersecurity

About this role

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time. Description We're building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you'll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger — helping to simplify health care one person, one family and one community at a time.

Position

Summary The Executive Director, SOX & SOC Compliance owns CVS Health's first-line SOX cybersecurity and IT general controls (ITGC) compliance program and SOC 1/SOC 2 readiness and attestation program, ensuring control scope, requirements, and evidence standards meet enterprise, regulatory, Internal Audit, and external audit expectations. Reporting to the AVP, Governance, Risk & Compliance (GRC), this leader manages the SOX and SOC compliance lifecycle as a first-line owner — including control scoping, requirements definition, evidence standards, deficiency management, and readiness for assurance activities — and serves as the primary compliance partner for Finance, Internal Audit, and external auditors on SOX and SOC matters. Control testing for design and operating effectiveness is performed by the Controls Assurance Testing (CAT) team; this role does not execute independent testing directly but sets requirements, engages closely with CAT throughout the testing cycle, and is accountable for the overall compliance outcome. The Executive Director builds and leads a team focused on scoping, evidence governance, audit coordination, and executive reporting, and drives close partnership with CAT to ensure testing is scoped, resourced, and completed on schedule.

Key Responsibilities

Own the enterprise SOX cybersecurity/ITGC and SOC 1/SOC 2 compliance programs end-to-end from a first-line perspective, including control scope definition, requirements, evidence standards, and readiness activities, in coordination with Finance, control owners, Internal Audit, and external auditors. Partner closely with the Controls Assurance Testing (CAT) team to define the annual testing scope and calendar, ensure testing requirements and evidence standards are clearly understood, and resolve scoping or interpretation questions; engage with CAT throughout the testing cycle to monitor progress, address blockers, and ensure control owners provide evidence and support on schedule. Lead SOC 1 and SOC 2 readiness activities, including control mapping to trust services criteria and coordination with CAT and control owners on evidence collection ahead of attestation testing. Serve as the first-line compliance point of contact for Internal Audit and external auditors on SOX and SOC engagements, coordinating requests, walkthroughs, evidence needs, and issue resolution while channeling testing-related questions to CAT as needed. Own the control deficiency lifecycle from a first-line compliance-program perspective — reviewing CAT's testing results, driving root cause analysis and remediation planning with control owners, and coordinating closure readiness with Internal Audit and external auditors — with clear accountability assigned to control and process owners. Maintain SOX and SOC control requirements, scoping documentation, and evidence standards within GRC platforms (e.g., AuditBoard, Archer), ensuring CAT and control owners are working from current, assurance-ready requirements. Drive continuous improvement of SOX and SOC compliance processes,

Listing verified 1h ago. Applications go through the company's official careers site.

← Back to Yoinka

Executive Director, SOX & SOC Compliance at CVS Health, VA - Work from home | Yoinka