We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.
Description
We're building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you'll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger — helping to simplify health care one person, one family and one community at a time.
Position Summary
The Executive Director, SOX & SOC Compliance owns CVS Health's first-line SOX cybersecurity and IT general controls (ITGC) compliance program and SOC 1/SOC 2 readiness and attestation program, ensuring control scope, requirements, and evidence standards meet enterprise, regulatory, Internal Audit, and external audit expectations. Reporting to the AVP, Governance, Risk & Compliance (GRC), this leader manages the SOX and SOC compliance lifecycle as a first-line owner — including control scoping, requirements definition, evidence standards, deficiency management, and readiness for assurance activities — and serves as the primary compliance partner for Finance, Internal Audit, and external auditors on SOX and SOC matters. Control testing for design and operating effectiveness is performed by the Controls Assurance Testing (CAT) team; this role does not execute independent testing directly but sets requirements, engages closely with CAT throughout the testing cycle, and is accountable for the overall compliance outcome. The Executive Director builds and leads a team focused on scoping, evidence governance, audit coordination, and executive reporting, and drives close partnership with CAT to ensure testing is scoped, resourced, and completed on schedule.
Key Responsibilities:
- Own the enterprise SOX cybersecurity/ITGC and SOC 1/SOC 2 compliance programs end-to-end from a first-line perspective, including control scope definition, requirements, evidence standards, and readiness activities, in coordination with Finance, control owners, Internal Audit, and external auditors.
- Partner closely with the Controls Assurance Testing (CAT) team to define the annual testing scope and calendar, ensure testing requirements and evidence standards are clearly understood, and resolve scoping or interpretation questions; engage with CAT throughout the testing cycle to monitor progress, address blockers, and ensure control owners provide evidence and support on schedule.
- Lead SOC 1 and SOC 2 readiness activities, including control mapping to trust services criteria and coordination with CAT and control owners on evidence collection ahead of attestation testing.
- Serve as the first-line compliance point of contact for Internal Audit and external auditors on SOX and SOC engagements, coordinating requests, walkthroughs, evidence needs, and issue resolution while channeling testing-related questions to CAT as needed.
- Own the control deficiency lifecycle from a first-line compliance-program perspective — reviewing CAT's testing results, driving root cause analysis and remediation planning with control owners, and coordinating closure readiness with Internal Audit and external auditors — with clear accountability assigned to control and process owners.
- Maintain SOX and SOC control requirements, scoping documentation, and evidence standards within GRC platforms (e.g., AuditBoard, Archer), ensuring CAT and control owners are working from current, assurance-ready requirements.
- Drive continuous improvement of SOX and SOC compliance processes, including evidence-reuse and reduction of duplicative requests to control owners, in partnership with CAT and GRC tooling teams.
- Produce and present executive-level reporting on SOX and SOC compliance posture, control readiness, tested control effectiveness (sourced from CAT's testing results), issue trends, and remediation progress to AVP GRC, Deputy CISO, and relevant governance forums.
- Partner with policy and standards owners to ensure SOX and SOC control requirements reflect current regulatory and framework expectations as they evolve.
- Support the security exception and risk acceptance process for SOX- and SOC-relevant control gaps identified through CAT's testing, ensuring appropriate documentation and executive visibility.
- Lead, coach, and develop the SOX & SOC Compliance team, building bench strength and a culture of accountability, precision, and strong cross-team partnership with CAT.
Required Qualifications
- 10+ years of progressive experience leading first-line-of-defense SOX ITGC, SOC 1/SOC 2, technology compliance, or control governance programs, including 3+ years in a leadership role.
- 7+ years of experience managing SOX ITGC and SOC 1/SOC 2 compliance programs from a first-line-of-defense perspective, including control scoping, requirements definition, evidence standards, deficiency remediation, and coordination with Internal Audit and external auditors.
- 7+ years of experience with relevant control and framework requirements, including SOX, SOC 1/SOC 2 trust services criteria, PCAOB/AICPA standards as applicable to management readiness and evidence expectations, NIST CSF, ISO 27001, and HITRUST CSF.
- 3+ years of experience with GRC and compliance management platforms (e.g., Optro, Archer, ServiceNow) for control scoping, evidence management, issue tracking, and executive reporting.
- 3+ years of experience with people leadership, including building, developing, and retaining a high-performing compliance team.
Preferred Qualifications
- Relevant certifications such as CISA, CISSP, CISM, CRISC, or CPA.
- Experience in healthcare, health insurance, pharmacy, or retail industries with large, complex vendor ecosystems and regulated data environments.
- Experience supporting regulatory examinations, cybersecurity compliance reviews, and external audit engagements through first-line readiness, evidence coordination, issue management, and partnership with Internal Audit and independent testing functions.
- Familiarity with SEC cybersecurity disclosure requirements and their intersection with SOX and SOC control environments, and materiality assessment processes.
- Experience operating within a matrixed, multi-business-unit enterprise (e.g., retail, pharmacy, health services, or similarly complex organizational structures).
- Demonstrated ability to build and manage effective cross-functional partnerships across first-line control owners, control testing teams, Internal Audit, Finance, and external auditors to drive aligned compliance outcomes.
- Proven ability to communicate compliance posture, control readiness, issue status, and remediation progress clearly to executive leadership, Internal Audit, and external auditors.
Education
- Bachelor's degree in Information Security, Accounting, Information Systems, Risk Management, or a related field, or equivalent professional experience.
Pay Range
The typical pay range for this role is:
$175,100.00 - $334,750.00
This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company’s equity award program.
Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.
Great benefits for great people
We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.
This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.
Additional details about available benefits are provided during the application process and on Benefits Moments.
We anticipate the application window for this opening will close on: 09/09/2026
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.