IT SOX Controls Specialist

Stripe

SEA, SF, NYC, US

Stripe

SEA, SF, NYC, US

Employment type not specified

Valid through 9/6/2026

Job description

Who we are

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.

About the team

Finance is the strategic engine that drives rigorous decision making and acts as the financial stewards of Stripe's businesses - and we'd like your help. Stripe is building a world class Controllership team, which is responsible for the corporate SOX program. Stripe is seeking a bar-raising  IT SOX Controls Specialist to join its SOX team. This growing team is responsible for the global implementation and operation of Stripe's SOX program. We seek a candidate that is excited by the challenge of working for a hyper-growth company that is focused on expanding the economic infrastructure of the internet.

What you’ll do

The IT SOX Controls Specialist is a key member of Stripe's SOX Compliance function within the Chief Accounting Organization, building confidence for our investor community through a strong and scalable SOX program. In this role, you will own the design, implementation, and monitoring of controls over third-party applications and service providers that impact Stripe's financial reporting. You will work closely with business process owners, IT, Procurement, and Vendor Management teams, reporting to the Head of SOX Compliance.

Responsibilities

Own the end-to-end SOX assessment lifecycle for third-party applications in scope for financial reporting, including identification, risk tiering, and control mapping

Lead the evaluation and review of third-party SOC 1 and SOC 2 reports (SSAE 18 / ISAE 3402), assessing complementary user entity controls (CUECs) and identifying gaps that require compensating controls at Stripe

Design and implement controls to address risks arising from third-party systems and integrations that impact the financial reporting supply chain

Develop and maintain SOX-ready documentation for third-party control environments, including risk and control matrices (RCMs), narratives, and process flow diagrams

Project manage control definition and implementation for new third-party system implementations, migrations, and integrations with financial reporting impact

Partner with IT, Procurement, and business stakeholders to embed control requirements into the vendor onboarding and periodic review process

Review IPE (Information Produced by the Entity) sourced from third-party systems for completeness and accuracy

Assess and track control deficiencies identified through third-party reviews, coordinating root cause analysis and corrective action plans with relevant process owners

Support the 302 and 404 sub-certification process as it relates to third-party application risks and controls

Monitor the third-party application landscape for emerging financial reporting risks as Stripe scales, and proactively develop control plans to address them

Contribute to ongoing SOX program improvements, including automation and optimization of third-party control monitoring

Who you are

We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum requirements

Bachelor's degree; Master's degree a plus in Accounting, Information Systems, Finance, or related field

Technical certification required (e.g., CPA, CIA, CISA, PMP)

10+ years of work experience in managing and/or assessing SOX programs

Big 4 audit firm or equivalent audit experience

Developed expertise and extensive experience with leading and performing SOX business process program design, control implementation, and monitoring of SOX program

Hands-on experience evaluating third-party SOC reports (SOC 1 / SOC 2) and assessing CUEC coverage and gaps

Familiarity with IT general controls and application-level controls in the context of financial reporting systems

Strong knowledge of technical accounting, order to cash, and financial close & reporting controls

Strong communication skills, including presenting to and influencing senior business leaders

Demonstrated success managing concurrent workstreams/projects independently

Preferred qualifications

Experience in implementing internal controls in early-stage public companies is strongly preferred

Experience with an online payments company, ecommerce, SaaS, Payments, Fintech, or Financial Services industries is desirable

Experience working with JIRA and AuditBoard is a plus

Familiarity with third-party risk management (TPRM) frameworks and vendor risk programs is a plus