IT SOX Controls Specialist

Stripe · SEA, SF, NYC · 6482 SOX · listed August 7, 2026

The shape of it

Seniority
Senior
Experience asked
10+ years
Where
Not stated
Requirements listed
10
Length
696 words

In the posting’s own words

Finance is the strategic engine that drives rigorous decision making and acts as the financial stewards of Stripe's businesses - and we'd like your help. Stripe is building a world class Controllership team, which is responsible for the corporate SOX program. Stripe is seeking a bar-raising IT SOX Controls Specialist to join its SOX team. This growing team is responsible for the global implementation and operation of Stripe's SOX program. We seek a candidate that is excited by the challenge of working for a hyper-growth company that is focused on expanding the economic infrastructure of the internet.

What it asks for · 10

  • Bachelor's degree; Master's degree a plus in Accounting, Information Systems, Finance, or related field
  • Technical certification required (e.g., CPA, CIA, CISA, PMP)
  • 10+ years of work experience in managing and/or assessing SOX programs
  • Big 4 audit firm or equivalent audit experience
  • Developed expertise and extensive experience with leading and performing SOX business process program design, control implementation, and monitoring of SOX program
  • Hands-on experience evaluating third-party SOC reports (SOC 1 / SOC 2) and assessing CUEC coverage and gaps
  • Familiarity with IT general controls and application-level controls in the context of financial reporting systems
  • Strong knowledge of technical accounting, order to cash, and financial close & reporting controls
  • Strong communication skills, including presenting to and influencing senior business leaders
  • Demonstrated success managing concurrent workstreams/projects independently

Also a plus

  • Experience in implementing internal controls in early-stage public companies is strongly preferred
  • Experience with an online payments company, ecommerce, SaaS, Payments, Fintech, or Financial Services industries is desirable
  • Experience working with JIRA and AuditBoard is a plus
  • Familiarity with third-party risk management (TPRM) frameworks and vendor risk programs is a plus

What the job covers

  • Own the end-to-end SOX assessment lifecycle for third-party applications in scope for financial reporting, including identification, risk tiering, and control mapping
  • Lead the evaluation and review of third-party SOC 1 and SOC 2 reports (SSAE 18 / ISAE 3402), assessing complementary user entity controls (CUECs) and identifying gaps that require compensating controls at Stripe
  • Design and implement controls to address risks arising from third-party systems and integrations that impact the financial reporting supply chain
  • Develop and maintain SOX-ready documentation for third-party control environments, including risk and control matrices (RCMs), narratives, and process flow diagrams
  • Project manage control definition and implementation for new third-party system implementations, migrations, and integrations with financial reporting impact
  • Partner with IT, Procurement, and business stakeholders to embed control requirements into the vendor onboarding and periodic review process
  • Review IPE (Information Produced by the Entity) sourced from third-party systems for completeness and accuracy
  • Assess and track control deficiencies identified through third-party reviews, coordinating root cause analysis and corrective action plans with relevant process owners
  • Support the 302 and 404 sub-certification process as it relates to third-party application risks and controls
  • Monitor the third-party application landscape for emerging financial reporting risks as Stripe scales, and proactively develop control plans to address them
  • Contribute to ongoing SOX program improvements, including automation and optimization of third-party control monitoring

Degree language

  • Bachelor's degree; Master's degree a plus in Accounting, Information Systems, Finance, or related field

Tools and skills named

Security & compliance
  • Audit2×
  • SOC 22×
  • Risk management
Operations & finance
  • Supply chain
  • Vendor management
Ways of working
  • Jira
  • Technical writing
Go to market
  • SaaS

Words the posting leans on

  • controls20×
  • sox13×
  • third-party13×
  • experience7×
  • risk7×
  • financial reporting6×
  • process6×
  • implementation5×
  • requirements5×
  • soc5×
  • sox program5×
  • systems5×
  • business4×
  • review4×
  • accounting3×
  • assessing3×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Stripe

every open role at Stripe

How this page was made

An automated read of a public job posting, fetched August 25, 2026 and last changed by Stripe on August 18, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.