IT SOX Controls Specialist
Stripe
Stripe
SEA, SF, NYC, US
Employment type not specified
Valid through 9/6/2026
Job description
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.
About the team
Finance is the strategic engine that drives rigorous decision making and acts as the financial stewards of Stripe's businesses - and we'd like your help. Stripe is building a world class Controllership team, which is responsible for the corporate SOX program. Stripe is seeking a bar-raising IT SOX Controls Specialist to join its SOX team. This growing team is responsible for the global implementation and operation of Stripe's SOX program. We seek a candidate that is excited by the challenge of working for a hyper-growth company that is focused on expanding the economic infrastructure of the internet.
What you’ll do
The IT SOX Controls Specialist is a key member of Stripe's SOX Compliance function within the Chief Accounting Organization, building confidence for our investor community through a strong and scalable SOX program. In this role, you will own the design, implementation, and monitoring of controls over third-party applications and service providers that impact Stripe's financial reporting. You will work closely with business process owners, IT, Procurement, and Vendor Management teams, reporting to the Head of SOX Compliance.
Responsibilities
Own the end-to-end SOX assessment lifecycle for third-party applications in scope for financial reporting, including identification, risk tiering, and control mapping
Lead the evaluation and review of third-party SOC 1 and SOC 2 reports (SSAE 18 / ISAE 3402), assessing complementary user entity controls (CUECs) and identifying gaps that require compensating controls at Stripe
Design and implement controls to address risks arising from third-party systems and integrations that impact the financial reporting supply chain
Develop and maintain SOX-ready documentation for third-party control environments, including risk and control matrices (RCMs), narratives, and process flow diagrams
Project manage control definition and implementation for new third-party system implementations, migrations, and integrations with financial reporting impact
Partner with IT, Procurement, and business stakeholders to embed control requirements into the vendor onboarding and periodic review process
Review IPE (Information Produced by the Entity) sourced from third-party systems for completeness and accuracy
Assess and track control deficiencies identified through third-party reviews, coordinating root cause analysis and corrective action plans with relevant process owners
Support the 302 and 404 sub-certification process as it relates to third-party application risks and controls
Monitor the third-party application landscape for emerging financial reporting risks as Stripe scales, and proactively develop control plans to address them
Contribute to ongoing SOX program improvements, including automation and optimization of third-party control monitoring
Who you are
We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
Bachelor's degree; Master's degree a plus in Accounting, Information Systems, Finance, or related field
Technical certification required (e.g., CPA, CIA, CISA, PMP)
10+ years of work experience in managing and/or assessing SOX programs
Big 4 audit firm or equivalent audit experience
Developed expertise and extensive experience with leading and performing SOX business process program design, control implementation, and monitoring of SOX program
Hands-on experience evaluating third-party SOC reports (SOC 1 / SOC 2) and assessing CUEC coverage and gaps
Familiarity with IT general controls and application-level controls in the context of financial reporting systems
Strong knowledge of technical accounting, order to cash, and financial close & reporting controls
Strong communication skills, including presenting to and influencing senior business leaders
Demonstrated success managing concurrent workstreams/projects independently
Preferred qualifications
Experience in implementing internal controls in early-stage public companies is strongly preferred
Experience with an online payments company, ecommerce, SaaS, Payments, Fintech, or Financial Services industries is desirable
Experience working with JIRA and AuditBoard is a plus
Familiarity with third-party risk management (TPRM) frameworks and vendor risk programs is a plus